Search CVE reports
151 – 160 of 53321 results
A heap use-after-free flaw was found in Gnumeric. When a user opens a crafted Gnumeric workbook containing a malformed SheetObjectComponent element, the XML parser can dereference a freed sheet-object component, causing Gnumeric to crash.
1 affected package
gnumeric
| Package | 22.04 LTS |
|---|---|
| gnumeric | Needs evaluation |
Flatpak's process ID namespace separation does not prevent a sandboxed app's kill(0, signal) or killpg(0, signal) calls from reaching processes outside the sandbox that share the same process group. A malicious or compromised...
1 affected package
flatpak
| Package | 22.04 LTS |
|---|---|
| flatpak | Needs evaluation |
Flatpak passes through arbitrary vendor-extension keys unmodified when exporting an application's Desktop Entry (.desktop) and D-Bus Service (.service) files, instead of validating against an allowlist. A malicious Flatpak app can...
1 affected package
flatpak
| Package | 22.04 LTS |
|---|---|
| flatpak | Needs evaluation |
Flatpak creates temporary child repository directories under the user cache with world-writable permissions (0777). On multi-user systems with a permissive umask, other local users could read or modify the temporary directory used...
1 affected package
flatpak
| Package | 22.04 LTS |
|---|---|
| flatpak | Needs evaluation |
Flatpak writes the OCI repository authentication token with world-readable permissions (0644) in the system-helper's cache directory, allowing other local users on a multi-user system to read the token and impersonate...
1 affected package
flatpak
| Package | 22.04 LTS |
|---|---|
| flatpak | Needs evaluation |
A path traversal vulnerability in Flatpak's handling of the files/etc directory during app deployment allows a malicious Flatpak app to cause certain host system files (such as passwd, group, machine-id, or resolv.conf) to be...
1 affected package
flatpak
| Package | 22.04 LTS |
|---|---|
| flatpak | Needs evaluation |
A path traversal vulnerability in Flatpak's handling of the export/bin directory during app deployment allows a malicious Flatpak app to cause deletion of attacker-chosen files outside the deployment directory when the app is...
1 affected package
flatpak
| Package | 22.04 LTS |
|---|---|
| flatpak | Needs evaluation |
Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability. The JsonWebSignature.deserialize_json() method accepts a JSON Serialization JWS object and returns the payload as successfully verified without...
1 affected package
python-authlib
| Package | 22.04 LTS |
|---|---|
| python-authlib | Needs evaluation |
[Unknown description]
1 affected package
gimp
| Package | 22.04 LTS |
|---|---|
| gimp | Needs evaluation |
[Unknown description]
1 affected package
gimp
| Package | 22.04 LTS |
|---|---|
| gimp | Needs evaluation |