Search CVE reports


Toggle filters

3751 – 3760 of 33827 results

Status is adjusted based on your filters.


CVE-2025-30673

Medium priority

Not in release

Sub::HandlesVia for Perl before 0.050002 allows untrusted code from the current working directory ('.') to be loaded similar to CVE-2016-1238. If an attacker can place a malicious file in current working directory, it may...

1 affected package

libsub-handlesvia-perl

Package 20.04 LTS
libsub-handlesvia-perl Not in release
Show less packages

CVE-2025-3035

Medium priority
Needs evaluation

By first using the AI chatbot in one tab and later activating it in another tab, the document title of the previous tab would leak into the chat prompt. This vulnerability affects Firefox < 137.

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 20.04 LTS
firefox Not in release
thunderbird Not in release
mozjs38 Not in release
mozjs52 Needs evaluation
mozjs68 Ignored
mozjs78 Not in release
mozjs91 Not in release
mozjs102 Not in release
mozjs115 Not in release
Show all 9 packages Show less packages

CVE-2025-3034

Medium priority
Needs evaluation

Memory safety bugs present in Firefox 136 and Thunderbird 136. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This...

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 20.04 LTS
firefox Not in release
thunderbird Not in release
mozjs38 Not in release
mozjs52 Needs evaluation
mozjs68 Ignored
mozjs78 Not in release
mozjs91 Not in release
mozjs102 Not in release
mozjs115 Not in release
Show all 9 packages Show less packages

CVE-2025-3033

Medium priority

Not in release

After selecting a malicious Windows `.url` shortcut from the local filesystem, an unexpected file could be uploaded. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects...

2 affected packages

firefox, thunderbird

Package 20.04 LTS
firefox Not in release
thunderbird Not in release
Show less packages

CVE-2025-3032

Medium priority
Needs evaluation

Leaking of file descriptors from the fork server to web content processes could allow for privilege escalation attacks. This vulnerability affects Firefox < 137 and Thunderbird < 137.

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 20.04 LTS
firefox Not in release
thunderbird Not in release
mozjs38 Not in release
mozjs52 Needs evaluation
mozjs68 Ignored
mozjs78 Not in release
mozjs91 Not in release
mozjs102 Not in release
mozjs115 Not in release
Show all 9 packages Show less packages

CVE-2025-3031

Medium priority
Needs evaluation

An attacker could read 32 bits of values spilled onto the stack in a JIT compiled function. This vulnerability affects Firefox < 137 and Thunderbird < 137.

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 20.04 LTS
firefox Not in release
thunderbird Not in release
mozjs38 Not in release
mozjs52 Needs evaluation
mozjs68 Ignored
mozjs78 Not in release
mozjs91 Not in release
mozjs102 Not in release
mozjs115 Not in release
Show all 9 packages Show less packages

CVE-2025-3030

Medium priority
Needs evaluation

Memory safety bugs present in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been...

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 20.04 LTS
firefox Not in release
thunderbird Not in release
mozjs38 Not in release
mozjs52 Needs evaluation
mozjs68 Ignored
mozjs78 Not in release
mozjs91 Not in release
mozjs102 Not in release
mozjs115 Not in release
Show all 9 packages Show less packages

CVE-2025-3029

Medium priority
Needs evaluation

A crafted URL containing specific Unicode characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability affects Firefox < 137, Firefox ESR < 128.9, Thunderbird < 137, and...

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 20.04 LTS
firefox Not in release
thunderbird Not in release
mozjs38 Not in release
mozjs52 Needs evaluation
mozjs68 Ignored
mozjs78 Not in release
mozjs91 Not in release
mozjs102 Not in release
mozjs115 Not in release
Show all 9 packages Show less packages

CVE-2025-3028

Medium priority
Needs evaluation

JavaScript code running while transforming a document with the XSLTProcessor could lead to a use-after-free. This vulnerability affects Firefox < 137, Firefox ESR < 115.22, Firefox ESR < 128.9, Thunderbird < 137, and Thunderbird < 128.9.

9 affected packages

mozjs78, firefox, thunderbird, mozjs38, mozjs52...

Package 20.04 LTS
mozjs78 Not in release
firefox Not in release
thunderbird Not in release
mozjs38 Not in release
mozjs52 Needs evaluation
mozjs68 Ignored
mozjs91 Not in release
mozjs102 Not in release
mozjs115 Not in release
Show all 9 packages Show less packages

CVE-2025-30224

Medium priority
Needs evaluation

MyDumper is a MySQL Logical Backup Tool. The MySQL C client library (libmysqlclient) allows authenticated remote actors to read arbitrary files from client systems via a crafted server response to LOAD LOCAL INFILE query, leading...

1 affected package

mydumper

Package 20.04 LTS
mydumper Needs evaluation
Show less packages