Search CVE reports


Toggle filters

51 – 60 of 39259 results

Status is adjusted based on your filters.


CVE-2025-58189

Medium priority
Needs evaluation

When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.

16 affected packages

golang, golang-1.6, golang-1.8, golang-1.9, golang-1.10...

Package 18.04 LTS
golang
golang-1.6
golang-1.8 Needs evaluation
golang-1.9 Needs evaluation
golang-1.10 Needs evaluation
golang-1.13 Needs evaluation
golang-1.14
golang-1.16 Needs evaluation
golang-1.17
golang-1.18 Needs evaluation
golang-1.20
golang-1.21
golang-1.22
golang-1.23
golang-1.24
golang-1.25
Show all 16 packages Show less packages

CVE-2025-58188

Medium priority
Needs evaluation

Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal method. This affects programs which validate arbitrary certificate chains.

16 affected packages

golang, golang-1.6, golang-1.8, golang-1.9, golang-1.10...

Package 18.04 LTS
golang
golang-1.6
golang-1.8 Needs evaluation
golang-1.9 Needs evaluation
golang-1.10 Needs evaluation
golang-1.13 Needs evaluation
golang-1.14
golang-1.16 Needs evaluation
golang-1.17
golang-1.18 Needs evaluation
golang-1.20
golang-1.21
golang-1.22
golang-1.23
golang-1.24
golang-1.25
Show all 16 packages Show less packages

CVE-2025-58187

Medium priority
Needs evaluation

Due to the design of the name constraint checking algorithm, the processing time of some inputs scals non-linearly with respect to the size of the certificate. This affects programs which validate arbitrary certificate chains.

16 affected packages

golang, golang-1.6, golang-1.8, golang-1.9, golang-1.10...

Package 18.04 LTS
golang
golang-1.6
golang-1.8 Needs evaluation
golang-1.9 Needs evaluation
golang-1.10 Needs evaluation
golang-1.13 Needs evaluation
golang-1.14
golang-1.16 Needs evaluation
golang-1.17
golang-1.18 Needs evaluation
golang-1.20
golang-1.21
golang-1.22
golang-1.23
golang-1.24
golang-1.25
Show all 16 packages Show less packages

CVE-2025-58186

Medium priority
Needs evaluation

Despite HTTP headers having a default limit of 1MB, the number of cookies that can be parsed does not have a limit. By sending a lot of very small cookies such as "a=;", an attacker can make an HTTP server allocate a large amount...

16 affected packages

golang, golang-1.6, golang-1.8, golang-1.9, golang-1.10...

Package 18.04 LTS
golang
golang-1.6
golang-1.8 Needs evaluation
golang-1.9 Needs evaluation
golang-1.10 Needs evaluation
golang-1.13 Needs evaluation
golang-1.14
golang-1.16 Needs evaluation
golang-1.17
golang-1.18 Needs evaluation
golang-1.20
golang-1.21
golang-1.22
golang-1.23
golang-1.24
golang-1.25
Show all 16 packages Show less packages

CVE-2025-58185

Medium priority
Needs evaluation

Parsing a maliciously crafted DER payload could allocate large amounts of memory, causing memory exhaustion.

16 affected packages

golang, golang-1.6, golang-1.8, golang-1.9, golang-1.10...

Package 18.04 LTS
golang
golang-1.6
golang-1.8 Needs evaluation
golang-1.9 Needs evaluation
golang-1.10 Needs evaluation
golang-1.13 Needs evaluation
golang-1.14
golang-1.16 Needs evaluation
golang-1.17
golang-1.18 Needs evaluation
golang-1.20
golang-1.21
golang-1.22
golang-1.23
golang-1.24
golang-1.25
Show all 16 packages Show less packages

CVE-2025-58183

Medium priority
Needs evaluation

tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a large number of sparse regions can cause a Reader to read an unbounded...

16 affected packages

golang, golang-1.6, golang-1.8, golang-1.9, golang-1.10...

Package 18.04 LTS
golang
golang-1.6
golang-1.8 Needs evaluation
golang-1.9 Needs evaluation
golang-1.10 Needs evaluation
golang-1.13 Needs evaluation
golang-1.14
golang-1.16 Needs evaluation
golang-1.17
golang-1.18 Needs evaluation
golang-1.20
golang-1.21
golang-1.22
golang-1.23
golang-1.24
golang-1.25
Show all 16 packages Show less packages

CVE-2025-47912

Medium priority
Needs evaluation

The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL. RFC 3986 permits IPv6 addresses to be included within the host component, enclosed within square...

16 affected packages

golang, golang-1.6, golang-1.8, golang-1.9, golang-1.10...

Package 18.04 LTS
golang
golang-1.6
golang-1.8 Needs evaluation
golang-1.9 Needs evaluation
golang-1.10 Needs evaluation
golang-1.13 Needs evaluation
golang-1.14
golang-1.16 Needs evaluation
golang-1.17
golang-1.18 Needs evaluation
golang-1.20
golang-1.21
golang-1.22
golang-1.23
golang-1.24
golang-1.25
Show all 16 packages Show less packages

CVE-2025-10934

Medium priority
Needs evaluation

GIMP XWD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit...

1 affected package

gimp

Package 18.04 LTS
gimp Needs evaluation
Show less packages

CVE-2025-10925

Medium priority
Needs evaluation

GIMP ILBM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to...

1 affected package

gimp

Package 18.04 LTS
gimp Needs evaluation
Show less packages

CVE-2025-10924

Medium priority
Needs evaluation

GIMP FF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this...

1 affected package

gimp

Package 18.04 LTS
gimp Needs evaluation
Show less packages