Search CVE reports


Toggle filters

121 – 130 of 31282 results

Status is adjusted based on your filters.


CVE-2025-43212

Medium priority
Needs evaluation

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, macOS Sequoia 15.6, iOS 18.6 and iPadOS 18.6, tvOS 18.6, watchOS 11.6, visionOS 2.6. Processing maliciously crafted web content may lead to...

5 affected packages

webkitgtk, webkit2gtk, qtwebkit-source, qtwebkit-opensource-src, wpewebkit

Package 22.04 LTS
webkitgtk Not in release
webkit2gtk Needs evaluation
qtwebkit-source Not in release
qtwebkit-opensource-src Ignored
wpewebkit Ignored
Show less packages

CVE-2025-43211

Medium priority
Needs evaluation

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, macOS Sequoia 15.6, iPadOS 17.7.9, iOS 18.6 and iPadOS 18.6, tvOS 18.6, watchOS 11.6, visionOS 2.6. Processing web content may lead to a...

5 affected packages

webkitgtk, webkit2gtk, qtwebkit-source, qtwebkit-opensource-src, wpewebkit

Package 22.04 LTS
webkitgtk Not in release
webkit2gtk Needs evaluation
qtwebkit-source Not in release
qtwebkit-opensource-src Ignored
wpewebkit Ignored
Show less packages

CVE-2025-31278

Medium priority
Needs evaluation

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iPadOS 17.7.9, watchOS 11.6, visionOS 2.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6. Processing maliciously crafted web...

5 affected packages

webkitgtk, webkit2gtk, qtwebkit-source, qtwebkit-opensource-src, wpewebkit

Package 22.04 LTS
webkitgtk Not in release
webkit2gtk Needs evaluation
qtwebkit-source Not in release
qtwebkit-opensource-src Ignored
wpewebkit Ignored
Show less packages

CVE-2025-31273

Medium priority
Needs evaluation

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, macOS Sequoia 15.6, iOS 18.6 and iPadOS 18.6, tvOS 18.6, watchOS 11.6, visionOS 2.6. Processing maliciously crafted web content may lead to...

5 affected packages

webkitgtk, webkit2gtk, qtwebkit-source, qtwebkit-opensource-src, wpewebkit

Package 22.04 LTS
webkitgtk Not in release
webkit2gtk Needs evaluation
qtwebkit-source Not in release
qtwebkit-opensource-src Ignored
wpewebkit Ignored
Show less packages

CVE-2025-4674

Medium priority
Needs evaluation

The go command may execute unexpected commands when operating in untrusted VCS repositories. This occurs when possibly dangerous VCS configuration is present in repositories. This can happen when a repository was fetched via one...

15 affected packages

golang, golang-1.6, golang-1.8, golang-1.9, golang-1.10...

Package 22.04 LTS
golang Not in release
golang-1.6 Not in release
golang-1.8 Not in release
golang-1.9 Not in release
golang-1.10 Not in release
golang-1.13 Needs evaluation
golang-1.14 Not in release
golang-1.16 Not in release
golang-1.17 Needs evaluation
golang-1.18 Needs evaluation
golang-1.20 Needs evaluation
golang-1.21 Needs evaluation
golang-1.22 Needs evaluation
golang-1.23 Needs evaluation
golang-1.24 Not in release
Show all 15 packages Show less packages

CVE-2025-27514

Medium priority

Not in release

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In versions 9.5.0 through 10.0.18, a technician can use a malicious payload to trigger a...

1 affected package

glpi

Package 22.04 LTS
glpi Not in release
Show less packages

CVE-2025-7458

Medium priority
Needs evaluation

An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of service or disclose sensitive...

2 affected packages

sqlite, sqlite3

Package 22.04 LTS
sqlite Needs evaluation
sqlite3 Not affected
Show less packages

CVE-2025-8264

Medium priority
Needs evaluation

Versions of the package z-push/z-push-dev before 2.7.6 are vulnerable to SQL Injection due to unparameterized queries in the IMAP backend. An attacker can inject malicious commands by manipulating the username field in basic...

1 affected package

z-push

Package 22.04 LTS
z-push Needs evaluation
Show less packages

CVE-2025-8283

Medium priority

Not in release

A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as...

1 affected package

netavark

Package 22.04 LTS
netavark Not in release
Show less packages

CVE-2025-8194

Medium priority
Needs evaluation

There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop...

12 affected packages

python3.13, python2.7, python3.4, python3.5, python3.6...

Package 22.04 LTS
python3.13 Not in release
python2.7 Needs evaluation
python3.4 Not in release
python3.5 Not in release
python3.6 Not in release
python3.7 Not in release
python3.8 Not in release
python3.9 Not in release
python3.10 Needs evaluation
python3.11 Needs evaluation
python3.12 Not in release
python3.14 Not in release
Show all 12 packages Show less packages