Search CVE reports


Toggle filters

471 – 480 of 37102 results

Status is adjusted based on your filters.


CVE-2025-15468

Low priority
Not affected

Issue summary: If an application using the SSL_CIPHER_find() function in a QUIC protocol client or server receives an unknown cipher suite from the peer, a NULL dereference occurs. Impact summary: A NULL pointer dereference leads...

4 affected packages

openssl, openssl1.0, nodejs, edk2

Package 20.04 LTS
openssl Not affected
openssl1.0
nodejs Not affected
edk2 Not affected
Show less packages

CVE-2025-15467

Medium priority
Not affected

Issue summary: Parsing CMS AuthEnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or...

4 affected packages

openssl, openssl1.0, nodejs, edk2

Package 20.04 LTS
openssl Not affected
openssl1.0
nodejs Not affected
edk2 Not affected
Show less packages

CVE-2025-11187

Medium priority
Not affected

Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow, invalid pointer or NULL pointer dereference during MAC verification. Impact summary: The stack buffer...

4 affected packages

openssl, openssl1.0, nodejs, edk2

Package 20.04 LTS
openssl Not affected
openssl1.0
nodejs Not affected
edk2 Not affected
Show less packages

CVE-2026-24400

Medium priority
Needs evaluation

AssertJ provides Fluent testing assertions for Java and the Java Virtual Machine (JVM). Starting in version 1.4.0 and prior to version 3.27.7, an XML External Entity (XXE) vulnerability exists...

1 affected package

assertj-core

Package 20.04 LTS
assertj-core Needs evaluation
Show less packages

CVE-2025-9820

Low priority
Needs evaluation

A flaw was found in the GnuTLS library, specifically in the gnutls_pkcs11_token_init() function that handles PKCS#11 token initialization. When a token label longer than expected is processed, the function writes past the end of a...

1 affected package

gnutls28

Package 20.04 LTS
gnutls28 Needs evaluation
Show less packages

CVE-2025-9615

Medium priority
Vulnerable

A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and...

1 affected package

network-manager

Package 20.04 LTS
network-manager Vulnerable
Show less packages

CVE-2025-50537

Medium priority
Needs evaluation

Stack overflow vulnerability in eslint before 9.26.0 when serializing objects with circular references in eslint/lib/shared/serialization.js. The exploit is triggered via the RuleTester.run() method, which validates test cases and...

1 affected package

eslint

Package 20.04 LTS
eslint Needs evaluation
Show less packages

CVE-2026-1418

Medium priority
Needs evaluation

A security vulnerability has been detected in GPAC up to 2.4.0. This affects the function gf_text_import_srt_bifs of the file src/scene_manager/text_to_bifs.c of the component SRT Subtitle Import. Such manipulation leads to...

1 affected package

gpac

Package 20.04 LTS
gpac Needs evaluation
Show less packages

CVE-2026-1417

Medium priority
Needs evaluation

A weakness has been identified in GPAC up to 2.4.0. Affected by this issue is the function dump_isom_rtp of the file applications/mp4box/filedump.c. This manipulation causes null pointer dereference. The attack needs to...

1 affected package

gpac

Package 20.04 LTS
gpac Needs evaluation
Show less packages

CVE-2026-1416

Medium priority
Needs evaluation

A security flaw has been discovered in GPAC up to 2.4.0. Affected by this vulnerability is the function DumpMovieInfo of the file applications/mp4box/filedump.c. The manipulation results in null pointer dereference. The attack...

1 affected package

gpac

Package 20.04 LTS
gpac Needs evaluation
Show less packages