Search CVE reports


Toggle filters

291 – 300 of 35777 results

Status is adjusted based on your filters.


CVE-2025-70310

Medium priority
Needs evaluation

A heap overflow in the vorbis_to_intern() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted .ogg file.

1 affected package

gpac

Package 22.04 LTS
gpac Needs evaluation
Show less packages

CVE-2025-70309

Medium priority
Needs evaluation

A stack overflow in the pcmreframe_flush_packet function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted WAV file.

1 affected package

gpac

Package 22.04 LTS
gpac Needs evaluation
Show less packages

CVE-2025-70308

Medium priority
Needs evaluation

An out-of-bounds read in the GSF demuxer filter component of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted .gsf file.

1 affected package

gpac

Package 22.04 LTS
gpac Needs evaluation
Show less packages

CVE-2025-70305

Medium priority
Needs evaluation

A stack overflow in the dmx_saf function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted .saf file.

1 affected package

gpac

Package 22.04 LTS
gpac Needs evaluation
Show less packages

CVE-2025-70304

Medium priority
Needs evaluation

A buffer overflow in the vobsub_get_subpic_duration() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted packet.

1 affected package

gpac

Package 22.04 LTS
gpac Needs evaluation
Show less packages

CVE-2025-70298

Medium priority
Needs evaluation

GPAC v2.4.0 was discovered to contain an out-of-bounds read in the oggdmx_parse_tags function.

1 affected package

gpac

Package 22.04 LTS
gpac Needs evaluation
Show less packages

CVE-2025-66417

Medium priority

Not in release

GLPI is a free asset and IT management software package. From 11.0.0, < 11.0.3, an unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 11.0.3.

1 affected package

glpi

Package 22.04 LTS
glpi Not in release
Show less packages

CVE-2025-64516

Medium priority

Not in release

GLPI is a free asset and IT management software package. Prior to 10.0.21 and 11.0.3, an unauthorized user can access GLPI documents attached to any item (ticket, asset, ...). If the public FAQ is enabled, this unauthorized access...

1 affected package

glpi

Package 22.04 LTS
glpi Not in release
Show less packages

CVE-2026-0992

Medium priority
Fixed

A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated <nextCatalog> elements pointing to the same downstream catalog. A remote...

1 affected package

libxml2

Package 22.04 LTS
libxml2 Fixed
Show less packages

CVE-2026-0990

Medium priority
Fixed

A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote...

1 affected package

libxml2

Package 22.04 LTS
libxml2 Fixed
Show less packages