Search CVE reports
1 – 10 of 11 results
Some fixes available 5 of 8
An integer underflow vulnerability exists in the OLE Document DIFAT Parser functionality of catdoc 0.95. A specially crafted malformed file can lead to heap-based memory corruption. An attacker can provide a malicious file to...
1 affected package
catdoc
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| catdoc | Not affected | Fixed | Fixed | Fixed | Fixed |
Some fixes available 5 of 8
An integer overflow vulnerability exists in the OLE Document File Allocation Table Parser functionality of catdoc 0.95. A specially crafted malformed file can lead to heap-based memory corruption. An attacker can provide a...
1 affected package
catdoc
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| catdoc | Not affected | Fixed | Fixed | Fixed | Fixed |
Some fixes available 5 of 8
A memory corruption vulnerability exists in the Shared String Table Record Parser implementation in xls2csv utility version 0.95. A specially crafted malformed file can lead to a heap buffer overflow. An attacker can provide a...
1 affected package
catdoc
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| catdoc | Not affected | Fixed | Fixed | Fixed | Fixed |
Catdoc v0.95 was discovered to contain a NULL pointer dereference via the component xls2csv at src/xlsparse.c.
1 affected package
catdoc
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| catdoc | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
Catdoc v0.95 was discovered to contain a NULL pointer dereference via the component xls2csv at src/fileutil.c.
1 affected package
catdoc
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| catdoc | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
Catdoc v0.95 was discovered to contain a global buffer overflow via the function process_file at /src/reader.c.
1 affected package
catdoc
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| catdoc | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
In libdoc through 2019-01-28, doc2text in catdoc.c has a NULL pointer dereference.
1 affected package
catdoc
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| catdoc | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
In libdoc through 2019-01-28, calcFileBlockOffset in ole.c allows division by zero.
1 affected package
catdoc
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| catdoc | Vulnerable | Vulnerable | Vulnerable | Vulnerable | Vulnerable |
The getlong function in numutils.c in libdoc through 2017-10-23 has a heap-based buffer over-read that allows attackers to cause a denial of service (application crash) via a crafted file.
1 affected package
catdoc
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| catdoc | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
The process_file function in reader.c in libdoc through 2017-10-23 has a heap-based buffer over-read that allows attackers to cause a denial of service (application crash) via a crafted file.
1 affected package
catdoc
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| catdoc | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |