Search CVE reports


Toggle filters

1 – 10 of 25450 results

Status is adjusted based on your filters.


CVE-2025-5024

Medium priority
Needs evaluation

A flaw was found in gnome-remote-desktop. Once gnome-remote-desktop listens for RDP connections, an unauthenticated attacker can exhaust system resources and repeatedly crash the process. There may be a resource leak after many...

1 affected package

gnome-remote-desktop

Package 24.04 LTS
gnome-remote-desktop Needs evaluation
Show less packages

CVE-2025-47780

Medium priority
Needs evaluation

Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk, trying to disallow shell commands to be...

1 affected package

asterisk

Package 24.04 LTS
asterisk Needs evaluation
Show less packages

CVE-2025-47779

Medium priority
Needs evaluation

Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk, SIP requests of the type MESSAGE...

1 affected package

asterisk

Package 24.04 LTS
asterisk Needs evaluation
Show less packages

CVE-2025-4280

Medium priority
Not affected

MacOS version of Poedit bundles a Python interpreter that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user to the main application bundle. An attacker with local user access can invoke this...

1 affected package

poedit

Package 24.04 LTS
poedit Not affected
Show less packages

CVE-2025-3887

High priority
Needs evaluation

GStreamer H265 Codec Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this...

1 affected package

gst-plugins-bad1.0

Package 24.04 LTS
gst-plugins-bad1.0 Needs evaluation
Show less packages

CVE-2025-32915

Medium priority

Not in release

Packages downloaded by Checkmk's automatic agent updates on Linux and Solaris have incorrect permissions in Checkmk < 2.4.0p1, < 2.3.0p32, < 2.2.0p42 and <= 2.1.0p49 (EOL). This allows a local attacker to read sensitive data.

1 affected package

check-mk

Package 24.04 LTS
check-mk Not in release
Show less packages

CVE-2025-2759

Medium priority
Needs evaluation

GStreamer Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of GStreamer. An attacker must first obtain the ability...

1 affected package

gstreamer1.0

Package 24.04 LTS
gstreamer1.0 Needs evaluation
Show less packages

CVE-2025-2506

Medium priority
Not affected

When pglogical attempts to replicate data, it does not verify it is using a replication connection, which means a user with CONNECT access to a database configured for replication can execute the pglogical command to obtain read...

1 affected package

pglogical

Package 24.04 LTS
pglogical Not affected
Show less packages

CVE-2023-47466

Medium priority
Needs evaluation

TagLib before 2.0 allows a segmentation violation and application crash during tag writing via a crafted WAV file in which an id3 chunk is the only valid chunk.

1 affected package

taglib

Package 24.04 LTS
taglib Needs evaluation
Show less packages

CVE-2025-5020

Medium priority
Ignored

Opening maliciously-crafted URLs in Firefox from other apps such as Safari could have allowed attackers to spoof website addresses if the URLs utilized non-HTTP schemes used internally by the Firefox iOS client This vulnerability...

9 affected packages

firefox, mozjs102, mozjs115, mozjs38, mozjs52...

Package 24.04 LTS
firefox Not affected
mozjs102 Ignored
mozjs115 Ignored
mozjs38 Not in release
mozjs52 Not in release
mozjs68 Not in release
mozjs78 Not in release
mozjs91 Not in release
thunderbird Not affected
Show all 9 packages Show less packages