Search CVE reports


Toggle filters

3811 – 3820 of 60314 results


CVE-2024-38865

Medium priority
Needs evaluation

Improper neutralization of livestatus command delimiters in a specific endpoint within RestAPI of Checkmk prior to 2.2.0p39, 2.3.0p25, and 2.1.0p51 (EOL) allows arbitrary livestatus command execution. Exploitation requires the...

1 affected package

check-mk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
check-mk Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2025-32728

Medium priority

Some fixes available 5 of 12

In sshd in OpenSSH before 10.0, the DisableForwarding directive does not adhere to the documentation stating that it disables X11 and agent forwarding.

2 affected packages

openssh, openssh-ssh1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssh Fixed Fixed Fixed Vulnerable
openssh-ssh1 Ignored Ignored Needs evaluation Needs evaluation
Show less packages

CVE-2025-32387

Medium priority
Needs evaluation

Helm is a package manager for Charts for Kubernetes. A JSON Schema file within a chart can be crafted with a deeply nested chain of references, leading to parser recursion that can exceed the stack size limit and trigger a stack...

1 affected package

helm

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
helm Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-32386

Medium priority
Needs evaluation

Helm is a tool for managing Charts. A chart archive file can be crafted in a manner where it expands to be significantly larger uncompressed than compressed (e.g., >800x difference). When Helm loads this specially crafted chart,...

1 affected package

helm

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
helm Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-32464

Medium priority
Fixed

HAProxy 2.2 through 3.1.6, in certain uncommon configurations, has a sample_conv_regsub heap-based buffer overflow because of mishandling of the replacement of multiple short patterns with a longer one.

1 affected package

haproxy

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
haproxy Fixed Fixed Not affected Not affected
Show less packages

CVE-2025-32460

Medium priority
Needs evaluation

GraphicsMagick before 8e56520 has a heap-based buffer over-read in ReadJXLImage in coders/jxl.c, related to an ImportViewPixelArea call.

1 affected package

graphicsmagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
graphicsmagick Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-31672

Medium priority
Needs evaluation

Improper Input Validation vulnerability in Apache POI. The issue affects the parsing of OOXML format files like xlsx, docx and pptx. These file formats are basically zip files and it is possible for malicious users to add zip...

1 affected package

libapache-poi-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libapache-poi-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-22871

Medium priority
Needs evaluation

The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare...

2 affected packages

golang-1.23, golang-1.24

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-1.23 Needs evaluation Needs evaluation Not in release
golang-1.24 Not in release Not in release Not in release
Show less packages

CVE-2025-3416

Medium priority
Needs evaluation

A flaw was found in OpenSSL's handling of the properties argument in certain functions. This vulnerability can allow use-after-free exploitation, which may result in undefined behavior or incorrect property parsing, leading to...

1 affected package

rust-openssl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rust-openssl Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-26675

Medium priority
Needs evaluation

Out-of-bounds read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.

1 affected package

wsl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wsl Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages