Search CVE reports


Toggle filters

71 – 80 of 31675 results

Status is adjusted based on your filters.


CVE-2025-15468

Low priority
Not affected

Issue summary: If an application using the SSL_CIPHER_find() function in a QUIC protocol client or server receives an unknown cipher suite from the peer, a NULL dereference occurs. Impact summary: A NULL pointer dereference leads...

4 affected packages

openssl, openssl1.0, nodejs, edk2

Package 24.04 LTS
openssl Not affected
openssl1.0 Not in release
nodejs Not affected
edk2 Not affected
Show less packages

CVE-2025-15467

Medium priority

Some fixes available 1 of 2

Issue summary: Parsing CMS AuthEnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or...

4 affected packages

openssl, openssl1.0, nodejs, edk2

Package 24.04 LTS
openssl Fixed
openssl1.0 Not in release
nodejs Not affected
edk2 Needs evaluation
Show less packages

CVE-2025-11187

Medium priority
Not affected

Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow, invalid pointer or NULL pointer dereference during MAC verification. Impact summary: The stack buffer...

4 affected packages

openssl, openssl1.0, nodejs, edk2

Package 24.04 LTS
openssl Not affected
openssl1.0 Not in release
nodejs Not affected
edk2 Not affected
Show less packages

CVE-2026-24476

Medium priority

Not in release

Shaarli is a personal bookmarking service. Prior to version 0.16.0, crafting a malicious tag which starting with `"` prematurely ends the `<input>` tag on the start page and allows an attacker to add arbitrary html leading to a...

1 affected package

shaarli

Package 24.04 LTS
shaarli Not in release
Show less packages

CVE-2026-24400

Medium priority
Needs evaluation

AssertJ provides Fluent testing assertions for Java and the Java Virtual Machine (JVM). Starting in version 1.4.0 and prior to version 3.27.7, an XML External Entity (XXE) vulnerability exists...

1 affected package

assertj-core

Package 24.04 LTS
assertj-core Needs evaluation
Show less packages

CVE-2026-0810

Medium priority
Needs evaluation

A flaw was found in gix-date. The `gix_date::parse::TimeBuf::as_str` function can generate strings containing invalid non-UTF8 characters. This issue violates the internal safety invariants of the `TimeBuf` component, leading to...

1 affected package

rust-gix-date

Package 24.04 LTS
rust-gix-date Needs evaluation
Show less packages

CVE-2025-9820

Low priority
Needs evaluation

A flaw was found in the GnuTLS library, specifically in the gnutls_pkcs11_token_init() function that handles PKCS#11 token initialization. When a token label longer than expected is processed, the function writes past the end of a...

1 affected package

gnutls28

Package 24.04 LTS
gnutls28 Needs evaluation
Show less packages

CVE-2025-9615

Medium priority
Vulnerable

A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and...

1 affected package

network-manager

Package 24.04 LTS
network-manager Vulnerable
Show less packages

CVE-2025-11687

Medium priority
Needs evaluation

A flaw was found in the gi-docgen. This vulnerability allows arbitrary JavaScript execution in the context of the page — enabling DOM access, session cookie theft and other client-side attacks — via a crafted URL that supplies a...

1 affected package

gi-docgen

Package 24.04 LTS
gi-docgen Needs evaluation
Show less packages

CVE-2025-11065

Medium priority

Not in release

A flaw was found in github.com/go-viper/mapstructure/v2, in the field processing component using mapstructure.WeakDecode. This vulnerability allows information disclosure through detailed error messages that may leak sensitive...

1 affected package

golang-github-go-viper-mapstructure

Package 24.04 LTS
golang-github-go-viper-mapstructure Not in release
Show less packages