Search CVE reports


Toggle filters

31 – 40 of 25323 results

Status is adjusted based on your filters.


CVE-2025-4664

High priority
Not affected

Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

1 affected package

chromium-browser

Package 24.04 LTS
chromium-browser Not affected
Show less packages

CVE-2025-4640

Medium priority
Needs evaluation

Out-of-bounds Write vulnerability in PointCloudLibrary pcl allows Overflow Buffers. Since version 1.14.0, PCL by default uses a zlib installation from the system, unless the user sets WITH_SYSTEM_ZLIB=FALSE. So this...

1 affected package

pcl

Package 24.04 LTS
pcl Needs evaluation
Show less packages

CVE-2025-4638

Medium priority
Needs evaluation

A vulnerability exists in the inftrees.c component of the zlib library, which is bundled within the PointCloudLibrary (PCL). This issue may allow context-dependent attackers to cause undefined behavior by exploiting improper...

1 affected package

pcl

Package 24.04 LTS
pcl Needs evaluation
Show less packages

CVE-2025-4609

Medium priority
Not affected

[Unknown description]

1 affected package

chromium-browser

Package 24.04 LTS
chromium-browser Not affected
Show less packages

CVE-2025-4478

Medium priority
Needs evaluation

A segmentation fault can be trigger through a unauthenticated attacker leaving the service in a defunct state possibly causing a denial of service.

1 affected package

gnome-remote-desktop

Package 24.04 LTS
gnome-remote-desktop Needs evaluation
Show less packages

CVE-2025-3932

Medium priority
Needs evaluation

It was possible to craft an email that showed a tracking link as an attachment. If the user attempted to open the attachment, Thunderbird automatically accessed the link. The configuration to block remote content did not prevent...

1 affected package

thunderbird

Package 24.04 LTS
thunderbird Needs evaluation
Show less packages

CVE-2025-3909

Medium priority
Needs evaluation

Thunderbird's handling of the X-Mozilla-External-Attachment-URL header can be exploited to execute JavaScript in the file:/// context. By crafting a nested email attachment (message/rfc822) and setting its content type...

1 affected package

thunderbird

Package 24.04 LTS
thunderbird Needs evaluation
Show less packages

CVE-2025-3877

Medium priority
Needs evaluation

A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's desktop or home directory without prompting, even if auto-saving is disabled. This behavior can be abused to...

1 affected package

thunderbird

Package 24.04 LTS
thunderbird Needs evaluation
Show less packages

CVE-2025-3875

Medium priority
Needs evaluation

Thunderbird parses addresses in a way that can allow sender spoofing in case the server allows an invalid From address to be used. For example, if the From header contains an (invalid) value "Spoofed Name ", Thunderbird treats...

1 affected package

thunderbird

Package 24.04 LTS
thunderbird Needs evaluation
Show less packages

CVE-2025-23166

Medium priority
Needs evaluation

[Improper error handling in async cryptographic operations crashes process]

1 affected package

nodejs

Package 24.04 LTS
nodejs Needs evaluation
Show less packages