Show filters
172 Total Results
Displaying 21-30 of 172
Sort by:
Attacker Value
Unknown

CVE-2022-38784

Disclosure Date: August 24, 2022 (last updated February 24, 2025)
Poppler prior to and including 22.08.0 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIGStream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code. This is similar to the vulnerability described by CVE-2022-38171 in Xpdf.
Attacker Value
Unknown

CVE-2022-27438

Disclosure Date: June 06, 2022 (last updated February 23, 2025)
Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected installation to trigger the update check.
Attacker Value
Unknown

CVE-2022-31782

Disclosure Date: June 02, 2022 (last updated February 23, 2025)
ftbench.c in FreeType Demo Programs through 2.12.1 has a heap-based buffer overflow.
Attacker Value
Unknown

CVE-2022-1215

Disclosure Date: June 02, 2022 (last updated February 23, 2025)
A format string vulnerability was found in libinput
Attacker Value
Unknown

CVE-2022-27337

Disclosure Date: May 05, 2022 (last updated February 23, 2025)
A logic error in the Hints::Hints function of Poppler v22.03.0 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.
Attacker Value
Unknown

CVE-2022-38171

Disclosure Date: April 19, 2022 (last updated February 24, 2025)
Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIG2Stream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code. This is similar to the vulnerability described by CVE-2021-30860 (Apple CoreGraphics).
Attacker Value
Unknown

CVE-2021-30860

Disclosure Date: August 24, 2021 (last updated February 23, 2025)
An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PDF may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Attacker Value
Unknown

CVE-2015-1877

Disclosure Date: June 02, 2021 (last updated February 22, 2025)
The open_generic_xdg_mime function in xdg-open in xdg-utils 1.1.0 rc1 in Debian, when using dash, does not properly handle local variables, which allows remote attackers to execute arbitrary commands via a crafted file.
Attacker Value
Unknown

CVE-2020-27748

Disclosure Date: June 01, 2021 (last updated February 22, 2025)
A flaw was found in the xdg-email component of xdg-utils-1.1.0-rc1 and newer. When handling mailto: URIs, xdg-email allows attachments to be discreetly added via the URI when being passed to Thunderbird. An attacker could potentially send a victim a URI that automatically attaches a sensitive file to a new email. If a victim user does not notice that an attachment was added and sends the email, this could result in sensitive information disclosure. It has been confirmed that the code behind this issue is in xdg-email and not in Thunderbird.
Attacker Value
Unknown

CVE-2020-35512

Disclosure Date: February 15, 2021 (last updated February 22, 2025)
A use-after-free flaw was found in D-Bus Development branch <= 1.13.16, dbus-1.12.x stable branch <= 1.12.18, and dbus-1.10.x and older branches <= 1.10.30 when a system has multiple usernames sharing the same UID. When a set of policy rules references these usernames, D-Bus may free some memory in the heap, which is still used by data structures necessary for the other usernames sharing the UID, possibly leading to a crash or other undefined behaviors