Search CVE reports


Toggle filters

11 – 20 of 494 results


CVE-2025-66382

Medium priority
Vulnerable

In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.

23 affected packages

expat, apache2, apr-util, cmake, ghostscript...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
expat Vulnerable Vulnerable Vulnerable Vulnerable
apache2 Not affected Not affected Not affected Not affected
apr-util Not affected Not affected Not affected Not affected
cmake Not affected Not affected Not affected Not affected
ghostscript Not affected Not affected Not affected Not affected
texlive-bin Not affected Not affected Not affected Not affected
xmlrpc-c Needs evaluation Needs evaluation Needs evaluation Needs evaluation
vnc4 Not in release Not in release Needs evaluation
wbxml2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
swish-e Needs evaluation Needs evaluation Needs evaluation Needs evaluation
insighttoolkit4 Not in release Needs evaluation Needs evaluation Needs evaluation
cadaver Needs evaluation Needs evaluation Needs evaluation Needs evaluation
gdcm Not affected Not affected Not affected Needs evaluation
ayttm Not in release Not in release
cableswig Not in release Not in release
coin3 Not affected Not affected Not affected Needs evaluation
matanza Ignored Ignored Ignored Needs evaluation
tdom Needs evaluation Needs evaluation Needs evaluation Needs evaluation
vtk Not in release Not in release
smart Not in release Not in release Needs evaluation
firefox Not affected Not affected
thunderbird Not affected Not affected
libxmltok Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show all 23 packages Show less packages

CVE-2025-12642

Medium priority
Needs evaluation

lighttpd1.4.80 incorrectly merged trailer fields into headers after http request parsing. This behavior can be exploited to conduct HTTP Header Smuggling attacks. Successful exploitation may allow an attacker to: * Bypass...

1 affected package

lighttpd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lighttpd Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-59801

Medium priority
Not affected

In Artifex GhostXPS before 10.06.0, there is a stack-based buffer overflow in xps_unpredict_tiff in xpstiff.c because the samplesperpixel value is not checked.

1 affected package

ghostscript

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ghostscript Not affected Not affected Not affected Not affected
Show less packages

CVE-2025-59800

Medium priority
Fixed

In Artifex Ghostscript through 10.05.1, ocr_begin_page in devices/gdevpdfocr.c has an integer overflow that leads to a heap-based buffer overflow in ocr_line8.

1 affected package

ghostscript

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ghostscript Fixed Fixed Not affected Not affected
Show less packages

CVE-2025-59799

Medium priority
Fixed

Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdfmark_coerce_dest in devices/vector/gdevpdfm.c via a large size value.

1 affected package

ghostscript

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ghostscript Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-59798

Medium priority
Fixed

Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdf_write_cmap in devices/vector/gdevpdtw.c.

1 affected package

ghostscript

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ghostscript Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-8671

Medium priority

Some fixes available 2 of 23

A mismatch caused by client-triggered server-sent stream resets between HTTP/2 specifications and the internal architectures of some HTTP/2 implementations may result in excessive server resource consumption leading to...

5 affected packages

h2o, haproxy, lighttpd, varnish, dnsdist

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
h2o Needs evaluation Needs evaluation Needs evaluation Needs evaluation
haproxy Not affected Not affected Not affected Not affected
lighttpd Needs evaluation Needs evaluation Needs evaluation Needs evaluation
varnish Needs evaluation Needs evaluation Needs evaluation Needs evaluation
dnsdist Fixed Not affected Not affected Not affected
Show less packages

CVE-2025-50952

Medium priority

Some fixes available 4 of 32

openjpeg v 2.5.0 was discovered to contain a NULL pointer dereference via the component /openjp2/dwt.c.

7 affected packages

insighttoolkit4, qtwebengine-opensource-src, blender, texmaker, ghostscript...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
insighttoolkit4 Not in release Needs evaluation Needs evaluation Needs evaluation
qtwebengine-opensource-src Needs evaluation Needs evaluation Needs evaluation Needs evaluation
blender Needs evaluation Needs evaluation Needs evaluation Needs evaluation
texmaker Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ghostscript Not affected Not affected Not affected Needs evaluation
openjpeg Not in release Not in release
openjpeg2 Fixed Fixed Fixed Fixed
Show all 7 packages Show less packages

CVE-2025-54874

Medium priority

Some fixes available 2 of 26

OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG from 2.5.1 through 2.5.3, a call to opj_jp2_read_header may lead to OOB heap memory write when the data stream p_stream is too short and p_image is not initialized.

7 affected packages

insighttoolkit4, qtwebengine-opensource-src, blender, texmaker, ghostscript...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
insighttoolkit4 Not in release Needs evaluation Needs evaluation Needs evaluation
qtwebengine-opensource-src Needs evaluation Needs evaluation Needs evaluation Needs evaluation
blender Needs evaluation Needs evaluation Needs evaluation Needs evaluation
texmaker Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ghostscript Not affected Not affected Not affected Not affected
openjpeg Not in release Not in release
openjpeg2 Not affected Not affected Not affected Not affected
Show all 7 packages Show less packages

CVE-2025-54956

Medium priority
Needs evaluation

The gh package before 1.5.0 for R delivers an HTTP response in a data structure that includes the Authorization header from the corresponding HTTP request.

1 affected package

r-cran-gh

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
r-cran-gh Needs evaluation Needs evaluation Needs evaluation
Show less packages