Search CVE reports


Toggle filters

1 – 10 of 27011 results

Status is adjusted based on your filters.


CVE-2025-8454

Medium priority
Needs evaluation

It was discovered that uscan, a tool to scan/watch upstream sources for new releases of software, included in devscripts (a collection of scripts to make the life of a Debian Package maintainer easier), skips OpenPGP verification...

1 affected package

devscripts

Package 24.04 LTS
devscripts Needs evaluation
Show less packages

CVE-2025-8292

Medium priority
Not affected

Use after free in Media Stream in Google Chrome prior to 138.0.7204.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

1 affected package

chromium-browser

Package 24.04 LTS
chromium-browser Not affected
Show less packages

CVE-2025-8283

Medium priority
Needs evaluation

A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as...

1 affected package

netavark

Package 24.04 LTS
netavark Needs evaluation
Show less packages

CVE-2025-8264

Medium priority

Not in release

Versions of the package z-push/z-push-dev before 2.7.6 are vulnerable to SQL Injection due to unparameterized queries in the IMAP backend. An attacker can inject malicious commands by manipulating the username field in basic...

1 affected package

z-push

Package 24.04 LTS
z-push Not in release
Show less packages

CVE-2025-8262

Medium priority
Needs evaluation

A vulnerability was found in yarnpkg Yarn up to 1.22.22. It has been classified as problematic. Affected is the function explodeHostedGitFragment of the file src/resolvers/exotics/hosted-git-resolver.js. The manipulation leads...

1 affected package

node-yarnpkg

Package 24.04 LTS
node-yarnpkg Needs evaluation
Show less packages

CVE-2025-8225

Medium priority
Needs evaluation

A vulnerability was found in GNU Binutils 2.44 and classified as problematic. This issue affects the function process_debug_info of the file binutils/dwarf.c of the component DWARF Section Handler. The manipulation leads to memory...

1 affected package

binutils

Package 24.04 LTS
binutils Needs evaluation
Show less packages

CVE-2025-8224

Medium priority
Needs evaluation

A vulnerability has been found in GNU Binutils 2.44 and classified as problematic. This vulnerability affects the function bfd_elf_get_str_section of the file bfd/elf.c of the component BFD Library. The manipulation leads to null...

1 affected package

binutils

Package 24.04 LTS
binutils Needs evaluation
Show less packages

CVE-2025-8197

Medium priority
Vulnerable

A global buffer overflow vulnerability was found in the soup_header_name_to_string function in Libsoup. The `soup_header_name_to_string` function does not validate the `name` parameter passed in, and directly...

2 affected packages

libsoup2.4, libsoup3

Package 24.04 LTS
libsoup2.4 Vulnerable
libsoup3 Vulnerable
Show less packages

CVE-2025-8194

Medium priority
Needs evaluation

There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop...

12 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7...

Package 24.04 LTS
python2.7 Not in release
python3.4 Not in release
python3.5 Not in release
python3.6 Not in release
python3.7 Not in release
python3.8 Not in release
python3.9 Not in release
python3.10 Not in release
python3.11 Not in release
python3.12 Needs evaluation
python3.13 Not in release
python3.14 Not in release
Show all 12 packages Show less packages

CVE-2025-8177

Low priority
Not affected

A vulnerability was found in LibTIFF up to 4.7.0. It has been rated as critical. This issue affects the function setrow of the file tools/thumbnail.c. The manipulation leads to buffer overflow. An attack has to be approached...

1 affected package

tiff

Package 24.04 LTS
tiff Not affected
Show less packages