Search CVE reports
1751 – 1760 of 45973 results
Not in release
joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to version 1.7.3, JWTClaimsRegistry applies membership matching to list-valued iss and sub claims,...
1 affected package
joserfc
| Package | 24.04 LTS |
|---|---|
| joserfc | Not in release |
Aria2 version 1.37.0 and below is affected by a Divide By Zero issue in src/bittorrent_helper.cc, which allows a remote malicious user to cause a Denial of Service
1 affected package
aria2
| Package | 24.04 LTS |
|---|---|
| aria2 | Needs evaluation |
A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array (VLA) on the stack without proper bounds checking, causing an unbounded stack...
1 affected package
gimp
| Package | 24.04 LTS |
|---|---|
| gimp | Needs evaluation |
A flaw was found in the file-pcx plugin in GIMP, affecting 32-bit builds only. When processing a PCX image file, the plugin calculates memory allocation sizes based on the image dimensions and the number of color planes. If a...
1 affected package
gimp
| Package | 24.04 LTS |
|---|---|
| gimp | Needs evaluation |
NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private...
1 affected package
network-manager
| Package | 24.04 LTS |
|---|---|
| network-manager | Needs evaluation |
Not in release
Horde IMP's AppleDouble MIME viewer writes an attacker-controlled attachment name into an HTML status block without escaping it. In lib/Mime/Viewer/Appledouble.php, _IMPrender() obtains the name of the data part with...
1 affected package
php-horde-imp
| Package | 24.04 LTS |
|---|---|
| php-horde-imp | Not in release |
A flaw was found in WebKitGTK. Processing malicious web content can cause a use-after-free issue due to improper memory handling and result in memory corruption.
5 affected packages
webkitgtk, webkit2gtk, qtwebkit-source, qtwebkit-opensource-src, wpewebkit
| Package | 24.04 LTS |
|---|---|
| webkitgtk | Not in release |
| webkit2gtk | Vulnerable |
| qtwebkit-source | Not in release |
| qtwebkit-opensource-src | Ignored |
| wpewebkit | Not in release |
A vulnerability was found in RPM's rpmbuild tarball processing. When processing a crafted source archive, the getTarSpec() function in tools/rpmbuild.cc passes an attacker-controlled tar archive member name to rpmExpand() as part...
1 affected package
rpm
| Package | 24.04 LTS |
|---|---|
| rpm | Needs evaluation |
A flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trust flags when validating CA certificates, allowing certificates present in the NSS database without TRUSTED_CA flags to be accepted...
1 affected package
jss
| Package | 24.04 LTS |
|---|---|
| jss | Needs evaluation |
fast-uri is a URI parser for Node.js. During parsing it runs a legacy decoding pass over the scheme component and never re-escapes the result, and serialization writes the scheme back out verbatim, unlike the host component which...
1 affected package
node-ajv
| Package | 24.04 LTS |
|---|---|
| node-ajv | Needs evaluation |