Search CVE reports


Toggle filters

1751 – 1760 of 60355 results


CVE-2025-45582

Medium priority
Vulnerable

GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the victim must extract an archive that contains a ../ symlink to a critical directory. Second,...

1 affected package

tar

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tar Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2025-48924

Medium priority
Needs evaluation

Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0. The methods...

2 affected packages

libcommons-lang-java, libcommons-lang3-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libcommons-lang-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libcommons-lang3-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-51591

Medium priority
Needs evaluation

A Server-Side Request Forgery (SSRF) in JGM Pandoc v3.6.4 allows attackers to gain access to and compromise the whole infrastructure via injecting a crafted iframe.

1 affected package

pandoc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pandoc Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-5992

Medium priority
Needs evaluation

When passing values outside of the expected range to QColorTransferGenericFunction it can cause a denial of service, for example, this can happen when passing a specifically crafted ICC profile to QColorSpace::fromICCProfile.This...

1 affected package

qt6-base

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qt6-base Needs evaluation Needs evaluation
Show less packages

CVE-2025-53864

Medium priority
Needs evaluation

Connect2id Nimbus JOSE + JWT 10.0.x before 10.0.2 and 9.37.x before 9.37.4 allows a remote attacker to cause a denial of service via a deeply nested JSON object supplied in a JWT claim set, because of uncontrolled recursion. NOTE:...

1 affected package

libgoogle-gson-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgoogle-gson-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-53630

Medium priority

Not in release

llama.cpp is an inference of several LLM models in C/C++. Integer Overflow in the gguf_init_from_file_impl function in ggml/src/gguf.cpp can lead to Heap Out-of-Bounds Read/Write. This vulnerability is fixed in...

1 affected package

llama.cpp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
llama.cpp Not in release Not in release
Show less packages

CVE-2025-53629

Medium priority
Needs evaluation

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.23.0, incoming requests using Transfer-Encoding: chunked in the header can allocate memory arbitrarily in the server, potentially leading...

1 affected package

cpp-httplib

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cpp-httplib Needs evaluation Needs evaluation
Show less packages

CVE-2025-53628

Medium priority
Needs evaluation

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.20.1, cpp-httplib does not have a limit for a unique line, permitting an attacker to explore this to allocate memory arbitrarily. This...

1 affected package

cpp-httplib

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cpp-httplib Needs evaluation Needs evaluation
Show less packages

CVE-2025-53506

Medium priority
Vulnerable

Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial settings frame that reduces the maximum permitted concurrent streams. This issue affects Apache Tomcat: from...

3 affected packages

tomcat10, tomcat11, tomcat9

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat10 Vulnerable Not in release
tomcat11 Not in release Not in release
tomcat9 Not affected Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2025-52520

Medium priority
Vulnerable

For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache Tomcat could lead to a DoS via bypassing of size limits. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8,...

3 affected packages

tomcat10, tomcat11, tomcat9

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat10 Vulnerable Not in release
tomcat11 Not in release Not in release
tomcat9 Not affected Vulnerable Vulnerable Vulnerable
Show less packages