← Back

Flightcrew Project

flightcrew_project

3 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Flightcrew
flightcrew

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Canonical
Flightcrew ProjectSigil Ebook
3Flightcrew
SigilUbuntu Linux
Jun 17, 2026
Jul 31, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Sigil before 0.9.16 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in a ZIP archive entry that is mishandled during extraction.
2Canonical
Flightcrew Project
2Flightcrew
Ubuntu Linux
Jun 17, 2026
Jul 4, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
FlightCrew v0.9.2 and older are vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in a ZIP archive entry that is mishandled during extraction.
1Flightcrew Project
1Flightcrew
Jun 17, 2026
Jun 28, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in FlightCrew v0.9.2 and earlier. A NULL pointer dereference occurs in GetRelativePathToNcx() or GetRelativePathsToXhtmlDocuments() when a NULL pointer is passed to xc::XMLUri::isValidURI(). This...Show more
An issue was discovered in FlightCrew v0.9.2 and earlier. A NULL pointer dereference occurs in GetRelativePathToNcx() or GetRelativePathsToXhtmlDocuments() when a NULL pointer is passed to xc::XMLUri::isValidURI(). This affects third-party software (not Sigil) that uses FlightCrew as a library.Show less