Search CVE reports


Toggle filters

1241 – 1250 of 1342 results


CVE-2014-3424

Medium priority
Ignored

lisp/net/tramp-sh.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a /tmp/tramp.##### temporary file.

7 affected packages

emacs-snapshot, emacs22, emacs23, emacs24, emacs25...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
emacs-snapshot Not in release
emacs22 Not in release
emacs23 Not in release
emacs24 Not in release
emacs25 Not affected
xemacs21 Not affected
xemacs21-packages Not affected
Show all 7 packages Show less packages

CVE-2014-3423

Negligible priority
Ignored

lisp/net/browse-url.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a /tmp/Mosaic.##### temporary file.

7 affected packages

emacs-snapshot, emacs22, emacs23, emacs24, emacs25...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
emacs-snapshot Not in release
emacs22 Not in release
emacs23 Not in release
emacs24 Not in release
emacs25 Not affected
xemacs21 Not affected
xemacs21-packages Not affected
Show all 7 packages Show less packages

CVE-2014-3422

Medium priority
Ignored

lisp/emacs-lisp/find-gc.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file under /tmp/esrc/.

7 affected packages

emacs-snapshot, emacs22, emacs23, emacs24, emacs25...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
emacs-snapshot Not in release
emacs22 Not in release
emacs23 Not in release
emacs24 Not in release
emacs25 Not affected
xemacs21 Not affected
xemacs21-packages Not affected
Show all 7 packages Show less packages

CVE-2014-3421

Medium priority
Vulnerable

lisp/gnus/gnus-fun.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on the /tmp/gnus.face.ppm temporary file.

7 affected packages

xemacs21-packages, emacs-snapshot, emacs22, emacs23, emacs24...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xemacs21-packages Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
emacs-snapshot Not in release Not in release Not in release Not in release Not in release
emacs22 Not in release Not in release Not in release Not in release Not in release
emacs23 Not in release Not in release Not in release Not in release Not in release
emacs24 Not in release Not in release Not in release Not in release Not in release
emacs25 Not in release Not in release Not in release Not in release Not affected
xemacs21 Not affected Not affected Not affected Not affected Not affected
Show all 7 packages Show less packages

CVE-2013-1764

Medium priority
Not affected

The Zypper (aka zypp) backend in PackageKit before 0.8.8 allows local users to downgrade packages via the "install updates" method.

1 affected package

packagekit

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
packagekit
Show less packages

CVE-2014-2030

Medium priority

Some fixes available 3 of 4

Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick, possibly 6.8.8-5, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PSD image,...

1 affected package

imagemagick

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
imagemagick
Show less packages

CVE-2014-1958

Medium priority

Some fixes available 3 of 4

Buffer overflow in the DecodePSDPixels function in coders/psd.c in ImageMagick before 6.8.8-5 might allow remote attackers to execute arbitrary code via a crafted PSD image, involving the L%06ld string, a different vulnerability...

1 affected package

imagemagick

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
imagemagick
Show less packages

CVE-2013-4453

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in templates/login.php in LDAP Account Manager (LAM) 4.3 and 4.2.1 allows remote attackers to inject arbitrary web script or HTML via the language parameter.

1 affected package

ldap-account-manager

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ldap-account-manager Not affected Not affected Not affected
Show less packages

CVE-2013-1066

Medium priority
Fixed

language-selector 0.110.x before 0.110.1, 0.90.x before 0.90.1, and 0.79.x before 0.79.4 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by...

1 affected package

language-selector

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
language-selector
Show less packages

CVE-2013-1441

Medium priority
Ignored

econvert in ExactImage 0.8.9 and earlier does not properly initialize the setjmp variable, which allows context-dependent users to cause a denial of service (crash) via a crafted image file.

1 affected package

exactimage

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
exactimage
Show less packages