Search CVE reports


Toggle filters

1 – 10 of 38405 results

Status is adjusted based on your filters.


CVE-2026-8286

Low priority
Vulnerable

A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.

1 affected package

curl

Package 24.04 LTS
curl Vulnerable
Show less packages

CVE-2026-13311

Medium priority
Needs evaluation

shell-quote prior to 1.8.5 finalizes parsed tokens in parse() using Array.prototype.concat as a reduce accumulator, which reallocates and copies the entire growing array on every iteration. As a result parse() runs in O(n^2) time...

1 affected package

node-shell-quote

Package 24.04 LTS
node-shell-quote Needs evaluation
Show less packages

CVE-2026-12844

Medium priority
Needs evaluation

(List::SomeUtils::XS versions before 0.59 for Perl have a heap buffer o ...)

1 affected package

liblist-someutils-xs-perl

Package 24.04 LTS
liblist-someutils-xs-perl Needs evaluation
Show less packages

CVE-2026-11999

Medium priority
Needs evaluation

(X.509 trust-chain bypass (path-depth exhaustion) in the OpenSSL compat ...)

5 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2

Package 24.04 LTS
openssl Needs evaluation
openssl-fips Not in release
openssl1.0 Not in release
nodejs Not affected
edk2 Needs evaluation
Show less packages

CVE-2026-11998

Medium priority
Needs evaluation

A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and can lead to arbitrary JavaScript execution within the context of the victim's browser session. SCE's purpose...

1 affected package

angular.js

Package 24.04 LTS
angular.js Needs evaluation
Show less packages

CVE-2025-60474

Medium priority
Needs evaluation

A buffer overflow in the gf_media_import function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.

1 affected package

gpac

Package 24.04 LTS
gpac Needs evaluation
Show less packages

CVE-2025-60473

Medium priority
Needs evaluation

A NULL pointer dereference in the gf_filter_in_parent_chain function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted file.

1 affected package

gpac

Package 24.04 LTS
gpac Needs evaluation
Show less packages

CVE-2025-60471

Medium priority
Needs evaluation

A use-after-free in the gf_filter_pid_reconfigure_task_discard function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted media file.

1 affected package

gpac

Package 24.04 LTS
gpac Needs evaluation
Show less packages

CVE-2025-60468

Medium priority
Needs evaluation

GPAC Multimedia Open Source Project GPAC Project/MP4Box 2.5-DEV-rev1593-gfe88c3545-master is affected by: Buffer Overflow. The impact is: cause a denial of service (local). The component is: filter_core/filter_pid.c (L:574-580):...

1 affected package

gpac

Package 24.04 LTS
gpac Needs evaluation
Show less packages

CVE-2025-60467

Medium priority
Needs evaluation

A use-after-free in the gf_filter_pid_inst_swap_delete_task function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted media file.

1 affected package

gpac

Package 24.04 LTS
gpac Needs evaluation
Show less packages