Search CVE reports


Toggle filters

31 – 40 of 25562 results

Status is adjusted based on your filters.


CVE-2024-7803

Medium priority

Not in release

An issue has been discovered in GitLab CE/EE affecting all versions from 11.6 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A Discord webhook integration may cause DoS.

1 affected package

gitlab

Package 24.04 LTS
gitlab Not in release
Show less packages

CVE-2024-22654

Medium priority
Needs evaluation

tcpreplay v4.4.4 was discovered to contain an infinite loop via the tcprewrite function at get.c.

1 affected package

tcpreplay

Package 24.04 LTS
tcpreplay Needs evaluation
Show less packages

CVE-2024-22653

Medium priority
Needs evaluation

yasm commit 9defefae was discovered to contain a NULL pointer dereference via the yasm_section_bcs_append function at section.c.

1 affected package

yasm

Package 24.04 LTS
yasm Needs evaluation
Show less packages

CVE-2020-36846

Medium priority
Needs evaluation

A buffer overflow, as described in CVE-2020-8927, exists in the embedded Brotli library.  Versions of IO::Compress::Brotli prior to 0.007 included a version of the brotli library prior to version 1.0.8, where an...

1 affected package

libio-compress-brotli-perl

Package 24.04 LTS
libio-compress-brotli-perl Needs evaluation
Show less packages

CVE-2025-27151

Medium priority
Needs evaluation

Redis is an open source, in-memory database that persists on disk. In versions starting from 7.0.0 to before 8.0.2, a stack-based buffer overflow exists in redis-check-aof due to the use of memcpy with strlen(filepath) when...

1 affected package

redis

Package 24.04 LTS
redis Needs evaluation
Show less packages

CVE-2025-5283

Medium priority
Vulnerable

Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

11 affected packages

chromium-browser, firefox, libvpx, mozjs102, mozjs115...

Package 24.04 LTS
chromium-browser Not affected
firefox Not affected
libvpx Vulnerable
mozjs102 Ignored
mozjs115 Ignored
mozjs38 Not in release
mozjs52 Not in release
mozjs68 Not in release
mozjs78 Not in release
mozjs91 Not in release
thunderbird Not affected
Show all 11 packages Show less packages

CVE-2025-5054

Medium priority
Fixed

Race condition can result in confidential information leakage

1 affected package

apport

Package 24.04 LTS
apport Fixed
Show less packages

CVE-2025-40909

Medium priority
Needs evaluation

[Thread creation while a directory handle is open does a fchdir, affecting other threads (race condition)]

1 affected package

perl

Package 24.04 LTS
perl Needs evaluation
Show less packages

CVE-2025-31501

Medium priority
Needs evaluation

Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an RT permalink.

1 affected package

request-tracker5

Package 24.04 LTS
request-tracker5 Needs evaluation
Show less packages

CVE-2025-31500

Medium priority
Needs evaluation

Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an Asset name.

1 affected package

request-tracker5

Package 24.04 LTS
request-tracker5 Needs evaluation
Show less packages