Search CVE reports


Toggle filters

41 – 50 of 24406 results

Status is adjusted based on your filters.


CVE-2024-58036

Medium priority
Needs evaluation

Net::Dropbox::API 1.9 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions. Specifically Net::Dropbox::API uses the Data::Random library...

1 affected package

libnet-dropbox-api-perl

Package 24.04 LTS
libnet-dropbox-api-perl Needs evaluation
Show less packages

CVE-2024-57868

Medium priority
Needs evaluation

Web::API 2.8 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions. Specifically Web::API uses the Data::Random library which...

1 affected package

libweb-api-perl

Package 24.04 LTS
libweb-api-perl Needs evaluation
Show less packages

CVE-2025-29476

Medium priority
Needs evaluation

Buffer Overflow vulnerability in compress_chunk_fuzzer with oss-fuzz on commit 16450518afddcb3139de627157208e49bfef6987 in c-blosc2 v.2.17.0 and before.

1 affected package

c-blosc2

Package 24.04 LTS
c-blosc2 Needs evaluation
Show less packages

CVE-2025-31130

Medium priority
Needs evaluation

gitoxide is an implementation of git written in Rust. Before 0.42.0, gitoxide uses SHA-1 hash implementations without any collision detection, leaving it vulnerable to hash collision attacks. gitoxide uses the sha1_smol or sha1...

1 affected package

rust-gix-features

Package 24.04 LTS
rust-gix-features Needs evaluation
Show less packages

CVE-2025-3198

Medium priority
Needs evaluation

A vulnerability has been found in GNU Binutils 2.43/2.44 and classified as problematic. Affected by this vulnerability is the function display_info of the file binutils/bucomm.c of the component objdump. The manipulation leads to...

1 affected package

binutils

Package 24.04 LTS
binutils Needs evaluation
Show less packages

CVE-2025-3196

Medium priority
Needs evaluation

A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. Affected is the function Assimp::MD2Importer::InternReadFile in the library code/AssetLib/MD2/MD2Loader.cpp of the component...

1 affected package

assimp

Package 24.04 LTS
assimp Needs evaluation
Show less packages

CVE-2025-31483

Medium priority
Needs evaluation

Miniflux is a feed reader. Due to a weak Content Security Policy on the /proxy/* route, an attacker can bypass the CSP of the media proxy and execute cross-site scripting when opening external images in a new tab/window. To...

1 affected package

miniflux

Package 24.04 LTS
miniflux Needs evaluation
Show less packages

CVE-2024-4877

Medium priority
Not affected

OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe which the OpenVPN GUI component would connect to allowing it to escalate its privileges

1 affected package

openvpn

Package 24.04 LTS
openvpn Not affected
Show less packages

CVE-2025-3160

Medium priority
Needs evaluation

A vulnerability has been found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This vulnerability affects the function Assimp::SceneCombiner::AddNodeHashes of the file code/Common/SceneCombiner.cpp of the...

1 affected package

assimp

Package 24.04 LTS
assimp Needs evaluation
Show less packages

CVE-2025-31115

Medium priority
Fixed

XZ Utils provide a general-purpose data-compression library plus command-line tools. In XZ Utils 5.3.3alpha to 5.8.0, the multithreaded .xz decoder in liblzma has a bug where invalid input can at least result in a crash. The...

1 affected package

xz-utils

Package 24.04 LTS
xz-utils Fixed
Show less packages