Search CVE reports
41 – 50 of 24406 results
CVE-2024-58036
Medium priorityNet::Dropbox::API 1.9 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions. Specifically Net::Dropbox::API uses the Data::Random library...
1 affected package
libnet-dropbox-api-perl
Package | 24.04 LTS |
---|---|
libnet-dropbox-api-perl | Needs evaluation |
CVE-2024-57868
Medium priorityWeb::API 2.8 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions. Specifically Web::API uses the Data::Random library which...
1 affected package
libweb-api-perl
Package | 24.04 LTS |
---|---|
libweb-api-perl | Needs evaluation |
CVE-2025-29476
Medium priorityBuffer Overflow vulnerability in compress_chunk_fuzzer with oss-fuzz on commit 16450518afddcb3139de627157208e49bfef6987 in c-blosc2 v.2.17.0 and before.
1 affected package
c-blosc2
Package | 24.04 LTS |
---|---|
c-blosc2 | Needs evaluation |
CVE-2025-31130
Medium prioritygitoxide is an implementation of git written in Rust. Before 0.42.0, gitoxide uses SHA-1 hash implementations without any collision detection, leaving it vulnerable to hash collision attacks. gitoxide uses the sha1_smol or sha1...
1 affected package
rust-gix-features
Package | 24.04 LTS |
---|---|
rust-gix-features | Needs evaluation |
CVE-2025-3198
Medium priorityA vulnerability has been found in GNU Binutils 2.43/2.44 and classified as problematic. Affected by this vulnerability is the function display_info of the file binutils/bucomm.c of the component objdump. The manipulation leads to...
1 affected package
binutils
Package | 24.04 LTS |
---|---|
binutils | Needs evaluation |
CVE-2025-3196
Medium priorityA vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. Affected is the function Assimp::MD2Importer::InternReadFile in the library code/AssetLib/MD2/MD2Loader.cpp of the component...
1 affected package
assimp
Package | 24.04 LTS |
---|---|
assimp | Needs evaluation |
CVE-2025-31483
Medium priorityMiniflux is a feed reader. Due to a weak Content Security Policy on the /proxy/* route, an attacker can bypass the CSP of the media proxy and execute cross-site scripting when opening external images in a new tab/window. To...
1 affected package
miniflux
Package | 24.04 LTS |
---|---|
miniflux | Needs evaluation |
CVE-2024-4877
Medium priorityOpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe which the OpenVPN GUI component would connect to allowing it to escalate its privileges
1 affected package
openvpn
Package | 24.04 LTS |
---|---|
openvpn | Not affected |
CVE-2025-3160
Medium priorityA vulnerability has been found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This vulnerability affects the function Assimp::SceneCombiner::AddNodeHashes of the file code/Common/SceneCombiner.cpp of the...
1 affected package
assimp
Package | 24.04 LTS |
---|---|
assimp | Needs evaluation |
CVE-2025-31115
Medium priorityXZ Utils provide a general-purpose data-compression library plus command-line tools. In XZ Utils 5.3.3alpha to 5.8.0, the multithreaded .xz decoder in liblzma has a bug where invalid input can at least result in a crash. The...
1 affected package
xz-utils
Package | 24.04 LTS |
---|---|
xz-utils | Fixed |