Search CVE reports


Toggle filters

41 – 50 of 31371 results

Status is adjusted based on your filters.


CVE-2025-8578

Medium priority
Not affected

Use after free in Cast in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

1 affected package

chromium-browser

Package 22.04 LTS
chromium-browser Not affected
Show less packages

CVE-2025-8577

Medium priority
Not affected

Inappropriate implementation in Picture In Picture in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium...

1 affected package

chromium-browser

Package 22.04 LTS
chromium-browser Not affected
Show less packages

CVE-2025-8576

Medium priority
Not affected

Use after free in Extensions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Medium)

1 affected package

chromium-browser

Package 22.04 LTS
chromium-browser Not affected
Show less packages

CVE-2025-8556

Medium priority
Needs evaluation

A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to compromise session security via low-order point injection and incorrect point validation during Diffie-Hellman key exchange.

1 affected package

golang-github-cloudflare-circl

Package 22.04 LTS
golang-github-cloudflare-circl Needs evaluation
Show less packages

CVE-2025-8534

Medium priority
Needs evaluation

A vulnerability classified as problematic was found in libtiff 4.6.0. This vulnerability affects the function PS_Lvl2page of the file tools/tiff2ps.c of the component tiff2ps. The manipulation leads to null pointer dereference. It...

5 affected packages

tiff, qtwebengine-opensource-src, texmaker, gdal, neuron

Package 22.04 LTS
tiff Needs evaluation
qtwebengine-opensource-src Needs evaluation
texmaker Needs evaluation
gdal Not affected
neuron Needs evaluation
Show less packages

CVE-2025-8454

Medium priority
Needs evaluation

It was discovered that uscan, a tool to scan/watch upstream sources for new releases of software, included in devscripts (a collection of scripts to make the life of a Debian Package maintainer easier), skips OpenPGP verification...

1 affected package

devscripts

Package 22.04 LTS
devscripts Needs evaluation
Show less packages

CVE-2025-8292

Medium priority
Not affected

Use after free in Media Stream in Google Chrome prior to 138.0.7204.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

1 affected package

chromium-browser

Package 22.04 LTS
chromium-browser Not affected
Show less packages

CVE-2025-8283

Medium priority

Not in release

A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as...

1 affected package

netavark

Package 22.04 LTS
netavark Not in release
Show less packages

CVE-2025-8264

Medium priority
Needs evaluation

Versions of the package z-push/z-push-dev before 2.7.6 are vulnerable to SQL Injection due to unparameterized queries in the IMAP backend. An attacker can inject malicious commands by manipulating the username field in basic...

1 affected package

z-push

Package 22.04 LTS
z-push Needs evaluation
Show less packages

CVE-2025-8262

Medium priority
Needs evaluation

A vulnerability was found in yarnpkg Yarn up to 1.22.22. It has been classified as problematic. Affected is the function explodeHostedGitFragment of the file src/resolvers/exotics/hosted-git-resolver.js. The manipulation leads...

1 affected package

node-yarnpkg

Package 22.04 LTS
node-yarnpkg Needs evaluation
Show less packages