Search CVE reports
31 – 40 of 25323 results
CVE-2025-4664
High priorityInsufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
1 affected package
chromium-browser
Package | 24.04 LTS |
---|---|
chromium-browser | Not affected |
CVE-2025-4640
Medium priorityOut-of-bounds Write vulnerability in PointCloudLibrary pcl allows Overflow Buffers. Since version 1.14.0, PCL by default uses a zlib installation from the system, unless the user sets WITH_SYSTEM_ZLIB=FALSE. So this...
1 affected package
pcl
Package | 24.04 LTS |
---|---|
pcl | Needs evaluation |
CVE-2025-4638
Medium priorityA vulnerability exists in the inftrees.c component of the zlib library, which is bundled within the PointCloudLibrary (PCL). This issue may allow context-dependent attackers to cause undefined behavior by exploiting improper...
1 affected package
pcl
Package | 24.04 LTS |
---|---|
pcl | Needs evaluation |
CVE-2025-4609
Medium priority[Unknown description]
1 affected package
chromium-browser
Package | 24.04 LTS |
---|---|
chromium-browser | Not affected |
CVE-2025-4478
Medium priorityA segmentation fault can be trigger through a unauthenticated attacker leaving the service in a defunct state possibly causing a denial of service.
1 affected package
gnome-remote-desktop
Package | 24.04 LTS |
---|---|
gnome-remote-desktop | Needs evaluation |
CVE-2025-3932
Medium priorityIt was possible to craft an email that showed a tracking link as an attachment. If the user attempted to open the attachment, Thunderbird automatically accessed the link. The configuration to block remote content did not prevent...
1 affected package
thunderbird
Package | 24.04 LTS |
---|---|
thunderbird | Needs evaluation |
CVE-2025-3909
Medium priorityThunderbird's handling of the X-Mozilla-External-Attachment-URL header can be exploited to execute JavaScript in the file:/// context. By crafting a nested email attachment (message/rfc822) and setting its content type...
1 affected package
thunderbird
Package | 24.04 LTS |
---|---|
thunderbird | Needs evaluation |
CVE-2025-3877
Medium priorityA crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's desktop or home directory without prompting, even if auto-saving is disabled. This behavior can be abused to...
1 affected package
thunderbird
Package | 24.04 LTS |
---|---|
thunderbird | Needs evaluation |
CVE-2025-3875
Medium priorityThunderbird parses addresses in a way that can allow sender spoofing in case the server allows an invalid From address to be used. For example, if the From header contains an (invalid) value "Spoofed Name ", Thunderbird treats...
1 affected package
thunderbird
Package | 24.04 LTS |
---|---|
thunderbird | Needs evaluation |
CVE-2025-23166
Medium priority[Improper error handling in async cryptographic operations crashes process]
1 affected package
nodejs
Package | 24.04 LTS |
---|---|
nodejs | Needs evaluation |