Search CVE reports


Toggle filters

3441 – 3450 of 60258 results


CVE-2025-46687

Medium priority
Needs evaluation

quickjs-ng through 0.9.0 has a missing length check in JS_ReadString for a string, leading to a heap-based buffer overflow. QuickJS before 2025-04-26 is also affected.

1 affected package

quickjs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
quickjs Needs evaluation Not in release Not in release
Show less packages

CVE-2025-2866

Medium priority
Fixed

Improper Verification of Cryptographic Signature vulnerability in LibreOffice allows PDF Signature Spoofing by Improper Validation. In the affected versions of LibreOffice a flaw in the verification code for adbe.pkcs7.sha1...

1 affected package

libreoffice

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice Fixed Fixed Fixed
Show less packages

CVE-2025-46653

Medium priority
Needs evaluation

Formidable (aka node-formidable) 2.1.0 through 3.x before 3.5.3 relies on hexoid to prevent guessing of filenames for untrusted executable content; however, hexoid is documented as not "cryptographically secure." (Also, there is a...

1 affected package

node-formidable

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-formidable Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-46646

Medium priority
Fixed

In Artifex Ghostscript before 10.05.0, decode_utf8 in base/gp_utf8.c mishandles overlong UTF-8 encoding. NOTE: this issue exists because of an incomplete fix for CVE-2024-46954.

1 affected package

ghostscript

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ghostscript Fixed Not affected Not affected Not affected
Show less packages

CVE-2025-3647

Medium priority
Needs evaluation

A flaw was discovered in Moodle. Additional checks were required to ensure that users can only access cohort data they are authorized to retrieve.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2025-3645

Medium priority
Needs evaluation

A flaw was found in Moodle. Insufficient capability checks in a messaging web service allowed users to view other users' names and online statuses.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2025-3644

Medium priority
Needs evaluation

A flaw was found in Moodle. Additional checks were required to prevent users from deleting course sections they did not have permission to modify.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2025-3643

Medium priority
Needs evaluation

A flaw was found in Moodle. The return URL in the policy tool required additional sanitizing to prevent a reflected Cross-site scripting (XSS) risk.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2025-3642

Medium priority
Needs evaluation

A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS EQUELLA repository. By default, this was only available to teachers and managers on sites with the EQUELLA repository enabled.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2025-3641

Medium priority
Needs evaluation

A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS Dropbox repository. By default, this was only available to teachers and managers on sites with the Dropbox repository enabled.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Needs evaluation
Show less packages