Search CVE reports
1 – 10 of 23 results
Unidata netcdf-c through 4.10.1 contains an out-of-bounds write vulnerability in NC4_HDF5_inq_attname() that copies HDF5 attribute names into a fixed 256-byte buffer without length validation. Attackers can craft HDF5 files with...
2 affected packages
netcdf, netcdf-parallel
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| netcdf | Vulnerable | Vulnerable | Vulnerable | Vulnerable | Vulnerable |
| netcdf-parallel | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | — |
NSF Unidata NetCDF-C Attribute Name Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NSF Unidata NetCDF-C. User...
2 affected packages
netcdf, netcdf-parallel
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| netcdf | Vulnerable | Vulnerable | Vulnerable | Vulnerable | Vulnerable |
| netcdf-parallel | Vulnerable | Vulnerable | Vulnerable | Vulnerable | — |
NSF Unidata NetCDF-C Dimension Name Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NSF Unidata NetCDF-C. User...
2 affected packages
netcdf, netcdf-parallel
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| netcdf | Vulnerable | Vulnerable | Vulnerable | Vulnerable | Vulnerable |
| netcdf-parallel | Vulnerable | Vulnerable | Vulnerable | Vulnerable | — |
NSF Unidata NetCDF-C Variable Name Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NSF Unidata NetCDF-C. User...
2 affected packages
netcdf, netcdf-parallel
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| netcdf | Vulnerable | Vulnerable | Vulnerable | Vulnerable | Vulnerable |
| netcdf-parallel | Vulnerable | Vulnerable | Vulnerable | Vulnerable | — |
NSF Unidata NetCDF-C NC Variable Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NSF Unidata NetCDF-C. User interaction is...
2 affected packages
netcdf, netcdf-parallel
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| netcdf | Vulnerable | Vulnerable | Vulnerable | Vulnerable | Vulnerable |
| netcdf-parallel | Vulnerable | Vulnerable | Vulnerable | Vulnerable | — |
NSF Unidata NetCDF-C Time Unit Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NSF Unidata NetCDF-C. User...
2 affected packages
netcdf, netcdf-parallel
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| netcdf | Vulnerable | Vulnerable | Vulnerable | Vulnerable | Vulnerable |
| netcdf-parallel | Vulnerable | Vulnerable | Vulnerable | Vulnerable | — |
An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_decode() performs incorrect memory handling while parsing crafted XML files, leading to a heap out-of-bounds read.
4 affected packages
netcdf, scilab, mapcache, netcdf-parallel
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| netcdf | Not affected | Not affected | Ignored | Ignored | Not affected |
| scilab | Vulnerable | Vulnerable | Vulnerable | Vulnerable | Vulnerable |
| mapcache | Ignored | Ignored | Ignored | Ignored | Ignored |
| netcdf-parallel | Not affected | Not affected | Ignored | Ignored | — |
Some fixes available 1 of 49
An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_decode() performs incorrect memory handling while parsing crafted XML files, leading to a heap-based buffer overflow.
4 affected packages
mapcache, scilab, netcdf-parallel, netcdf
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| mapcache | Vulnerable | Vulnerable | Vulnerable | Vulnerable | Vulnerable |
| scilab | Vulnerable | Vulnerable | Vulnerable | Vulnerable | Vulnerable |
| netcdf-parallel | Vulnerable | Vulnerable | Vulnerable | Vulnerable | Not in release |
| netcdf | Not affected | Not affected | Ignored | Ignored | Not affected |
An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_parse_str() performs incorrect memory handling while parsing crafted XML files (out-of-bounds read after a certain strcspn failure).
4 affected packages
mapcache, scilab, netcdf-parallel, netcdf
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| mapcache | Vulnerable | Vulnerable | Vulnerable | Vulnerable | Vulnerable |
| scilab | Vulnerable | Vulnerable | Vulnerable | Vulnerable | Vulnerable |
| netcdf-parallel | Vulnerable | Vulnerable | Vulnerable | Vulnerable | Not in release |
| netcdf | Not affected | Not affected | Ignored | Ignored | Not affected |
Some fixes available 1 of 57
An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_parse_str() performs incorrect memory handling while parsing crafted XML files (writing outside a memory region created by mmap).
5 affected packages
mapcache, scilab, netcdf-parallel, navit, netcdf
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| mapcache | Ignored | Ignored | Ignored | Ignored | Ignored |
| scilab | Vulnerable | Vulnerable | Vulnerable | Vulnerable | Vulnerable |
| netcdf-parallel | Not affected | Not affected | Ignored | Ignored | Not in release |
| navit | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| netcdf | Not affected | Not affected | Ignored | Ignored | Not affected |