Search CVE reports


Toggle filters

831 – 840 of 32432 results

Status is adjusted based on your filters.


CVE-2025-58066

Medium priority

Not in release

nptd-rs is a tool for synchronizing your computer's clock, implementing the NTP and NTS protocols. In versions between 1.2.0 and 1.6.1 inclusive servers which allow non-NTS traffic are affected by a denial of...

1 affected package

rust-ntpd

Package 22.04 LTS
rust-ntpd Not in release
Show less packages

CVE-2025-9670

Medium priority
Needs evaluation

A security flaw has been discovered in mixmark-io turndown up to 7.2.1. This affects an unknown function of the file src/commonmark-rules.js. Performing manipulation results in inefficient regular expression complexity. It is...

1 affected package

node-turndown

Package 22.04 LTS
node-turndown Needs evaluation
Show less packages

CVE-2025-55763

Medium priority
Needs evaluation

Buffer Overflow in the URI parser of CivetWeb 1.14 through 1.16 (latest) allows a remote attacker to achieve remote code execution via a crafted HTTP request. This vulnerability is triggered during request processing and may allow...

1 affected package

civetweb

Package 22.04 LTS
civetweb Needs evaluation
Show less packages

CVE-2025-47909

Medium priority
Needs evaluation

Hosts listed in TrustedOrigins implicitly allow requests from the corresponding HTTP origins, allowing network MitMs to perform CSRF attacks. After the CVE-2025-24358 fix, a network attacker that places a form...

1 affected package

golang-github-gorilla-csrf

Package 22.04 LTS
golang-github-gorilla-csrf Needs evaluation
Show less packages

CVE-2025-9649

Medium priority
Needs evaluation

A security vulnerability has been detected in appneta tcpreplay 4.5.1. Impacted is the function calc_sleep_time of the file send_packets.c. Such manipulation leads to divide by zero. An attack has to be approached locally. The...

1 affected package

tcpreplay

Package 22.04 LTS
tcpreplay Needs evaluation
Show less packages

CVE-2025-55304

Low priority
Needs evaluation

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. A denial-of-service was found in Exiv2 version 0.28.5: a quadratic algorithm in the ICC profile parsing...

1 affected package

exiv2

Package 22.04 LTS
exiv2 Needs evaluation
Show less packages

CVE-2025-54080

Low priority
Needs evaluation

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds read was found in Exiv2 versions 0.28.5 and earlier. The out-of-bounds read is triggered...

1 affected package

exiv2

Package 22.04 LTS
exiv2 Needs evaluation
Show less packages

CVE-2025-40927

Medium priority
Needs evaluation

CGI::Simple versions before 1.282 for Perl has a HTTP response splitting flaw This vulnerability is a confirmed HTTP response splitting flaw in CGI::Simple that allows HTTP response header injection, which can be used for...

1 affected package

libcgi-simple-perl

Package 22.04 LTS
libcgi-simple-perl Needs evaluation
Show less packages

CVE-2025-58058

Medium priority
Needs evaluation

xz is a pure golang package for reading and writing xz-compressed files. Prior to version 0.5.14, it is possible to put data in front of an LZMA-encoded byte stream without detecting the situation while reading the header. This...

1 affected package

golang-github-ulikunitz-xz

Package 22.04 LTS
golang-github-ulikunitz-xz Needs evaluation
Show less packages

CVE-2025-57767

Medium priority
Needs evaluation

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.15.2, 21.10.2, and 22.5.2, if a SIP request is received with an Authorization header that contains a realm that wasn't in a previous...

1 affected package

asterisk

Package 22.04 LTS
asterisk Needs evaluation
Show less packages