Search CVE reports


Toggle filters

1 – 10 of 30798 results

Status is adjusted based on your filters.


CVE-2025-4919

Medium priority
Vulnerable

An attacker was able to perform an out-of-bounds read or write on a JavaScript object by confusing array index sizes. This vulnerability affects Firefox < 138.0.4, Firefox ESR < 128.10.1, and Firefox ESR < 115.23.1.

9 affected packages

firefox, mozjs102, mozjs115, mozjs38, mozjs52...

Package 20.04 LTS
firefox Vulnerable
mozjs102 Not in release
mozjs115 Not in release
mozjs38 Not in release
mozjs52 Ignored
mozjs68 Ignored
mozjs78 Not in release
mozjs91 Not in release
thunderbird Vulnerable
Show all 9 packages Show less packages

CVE-2025-4918

Medium priority
Vulnerable

An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object. This vulnerability affects Firefox < 138.0.4, Firefox ESR < 128.10.1, and Firefox ESR < 115.23.1.

9 affected packages

firefox, mozjs102, mozjs115, mozjs38, mozjs52...

Package 20.04 LTS
firefox Vulnerable
mozjs102 Not in release
mozjs115 Not in release
mozjs38 Not in release
mozjs52 Ignored
mozjs68 Ignored
mozjs78 Not in release
mozjs91 Not in release
thunderbird Vulnerable
Show all 9 packages Show less packages

CVE-2025-48188

Medium priority

Not in release

libpspp-core.a in GNU PSPP through 2.0.1 has an incorrect call from fill_buffer (in data/encrypted-file.c) to the Gnulib rijndaelDecrypt function, leading to a heap-based buffer over-read.

1 affected package

pspp

Package 20.04 LTS
pspp Not in release
Show less packages

CVE-2025-4802

Medium priority
Needs evaluation

Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen...

2 affected packages

eglibc, glibc

Package 20.04 LTS
eglibc Not in release
glibc Needs evaluation
Show less packages

CVE-2025-47792

Medium priority
Needs evaluation

Nextcloud Desktop is the desktop sync client for Nextcloud. In versions of Nextcloud Desktop prior to 3.15, 3rdparty applications already installed on a user machine can create link shares for almost all data via the socket API....

1 affected package

nextcloud-desktop

Package 20.04 LTS
nextcloud-desktop Needs evaluation
Show less packages

CVE-2025-47273

Medium priority
Needs evaluation

setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be...

3 affected packages

python-pip, python-setuptools, setuptools

Package 20.04 LTS
python-pip Needs evaluation
python-setuptools Needs evaluation
setuptools Needs evaluation
Show less packages

CVE-2025-4476

Medium priority

Not in release

A denial-of-service vulnerability has been identified in the libsoup HTTP client library. This flaw can be triggered when a libsoup client receives a 401 (Unauthorized) HTTP response containing a specifically crafted...

1 affected package

libsoup3

Package 20.04 LTS
libsoup3 Not in release
Show less packages

CVE-2025-4211

Medium priority
Needs evaluation

Improper Link Resolution Before File Access ('Link Following') vulnerability in QFileSystemEngine in the Qt corelib module on Windows which potentially allows Symlink Attacks and the use of Malicious Files. Issue originates from...

3 affected packages

qt6-base, qtbase-opensource-src, qtbase-opensource-src-gles

Package 20.04 LTS
qt6-base Not in release
qtbase-opensource-src Needs evaluation
qtbase-opensource-src-gles Needs evaluation
Show less packages

CVE-2025-40907

Medium priority
Needs evaluation

FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library. The included FastCGI library is affected by CVE-2025-23016, causing an integer overflow (and resultant heap-based...

1 affected package

libfcgi-perl

Package 20.04 LTS
libfcgi-perl Needs evaluation
Show less packages

CVE-2025-40906

Medium priority
Needs evaluation

BSON::XS versions 0.8.4 and earlier for Perl includes a bundled libbson 1.1.7, which has several vulnerabilities. Those include CVE-2017-14227, CVE-2018-16790, CVE-2023-0437, CVE-2024-6381, CVE-2024-6383, and...

1 affected package

libbson-xs-perl

Package 20.04 LTS
libbson-xs-perl Needs evaluation
Show less packages