Search CVE reports


Toggle filters

491 – 500 of 32653 results

Status is adjusted based on your filters.


CVE-2025-8860

Medium priority
Not affected

A flaw was found in QEMU in the uefi-vars virtual device. When the guest writes to register UEFI_VARS_REG_BUFFER_SIZE, the .write callback `uefi_vars_write` is invoked. The function allocates a heap buffer without zeroing the...

1 affected package

qemu

Package 24.04 LTS
qemu Not affected
Show less packages

CVE-2025-14876

Medium priority
Fixed

A flaw was found in the virtio-crypto device of QEMU. A malicious guest operating system can exploit a missing length limit in the AKCIPHER path, leading to uncontrolled memory allocation. This can result in a denial of service...

1 affected package

qemu

Package 24.04 LTS
qemu Fixed
Show less packages

CVE-2025-1272

Medium priority
Needs evaluation

The Linux Kernel lockdown mode for kernel versions starting on 6.12 and above for Fedora Linux has the lockdown mode disabled without any warning. This may allow an attacker to gain access to sensitive information such kernel...

157 affected packages

linux, linux-hwe, linux-hwe-5.4, linux-hwe-5.8, linux-hwe-5.11...

Package 24.04 LTS
linux Needs evaluation
linux-hwe Not in release
linux-hwe-5.4 Not in release
linux-hwe-5.8 Not in release
linux-hwe-5.11 Not in release
linux-hwe-5.13 Not in release
linux-hwe-5.15 Not in release
linux-hwe-5.19 Not in release
linux-hwe-6.2 Not in release
linux-hwe-6.5 Not in release
linux-hwe-6.8 Not in release
linux-hwe-edge Not in release
linux-lts-xenial Not in release
linux-kvm Not in release
linux-allwinner-5.19 Not in release
linux-aws-5.0 Not in release
linux-aws-5.3 Not in release
linux-aws-5.4 Not in release
linux-aws Needs evaluation
linux-aws-5.8 Not in release
linux-aws-5.11 Not in release
linux-aws-5.13 Not in release
linux-aws-5.15 Not in release
linux-aws-5.19 Not in release
linux-aws-6.2 Not in release
linux-aws-6.5 Not in release
linux-aws-6.8 Not in release
linux-aws-hwe Not in release
linux-azure Needs evaluation
linux-azure-4.15 Not in release
linux-azure-5.3 Not in release
linux-azure-5.4 Not in release
linux-azure-5.8 Not in release
linux-azure-5.11 Not in release
linux-azure-5.13 Not in release
linux-azure-5.15 Not in release
linux-azure-5.19 Not in release
linux-azure-6.2 Not in release
linux-azure-6.5 Not in release
linux-azure-6.8 Not in release
linux-azure-fde Needs evaluation
linux-azure-fde-5.15 Not in release
linux-azure-fde-5.19 Not in release
linux-azure-fde-6.2 Not in release
linux-bluefield Not in release
linux-azure-edge Not in release
linux-fips Not in release
linux-aws-fips Not in release
linux-azure-fips Not in release
linux-gcp-fips Not in release
linux-gcp Needs evaluation
linux-gcp-4.15 Not in release
linux-gcp-5.3 Not in release
linux-gcp-5.4 Not in release
linux-gcp-5.8 Not in release
linux-gcp-5.11 Not in release
linux-gcp-5.13 Not in release
linux-gcp-5.15 Not in release
linux-gcp-5.19 Not in release
linux-gcp-6.2 Not in release
linux-gcp-6.5 Not in release
linux-gcp-6.8 Not in release
linux-gke Needs evaluation
linux-gke-4.15 Not in release
linux-gke-5.4 Not in release
linux-gke-5.15 Not in release
linux-gkeop Needs evaluation
linux-gkeop-5.4 Not in release
linux-gkeop-5.15 Not in release
linux-ibm Needs evaluation
linux-ibm-5.4 Not in release
linux-ibm-5.15 Not in release
linux-intel-5.13 Not in release
linux-intel-iotg Not in release
linux-intel-iotg-5.15 Not in release
linux-iot Not in release
linux-intel-iot-realtime Not in release
linux-lowlatency Needs evaluation
linux-lowlatency-hwe-5.15 Not in release
linux-lowlatency-hwe-5.19 Not in release
linux-lowlatency-hwe-6.2 Not in release
linux-lowlatency-hwe-6.5 Not in release
linux-lowlatency-hwe-6.8 Not in release
linux-nvidia Needs evaluation
linux-nvidia-6.2 Not in release
linux-nvidia-6.5 Not in release
linux-nvidia-6.8 Not in release
linux-nvidia-lowlatency Needs evaluation
linux-oracle Needs evaluation
linux-oracle-5.0 Not in release
linux-oracle-5.3 Not in release
linux-oracle-5.4 Not in release
linux-oracle-5.8 Not in release
linux-oracle-5.11 Not in release
linux-oracle-5.13 Not in release
linux-oracle-5.15 Not in release
linux-oracle-6.5 Not in release
linux-oracle-6.8 Not in release
linux-oem Not in release
linux-oem-5.6 Not in release
linux-oem-5.10 Not in release
linux-oem-5.13 Not in release
linux-oem-5.14 Not in release
linux-oem-5.17 Not in release
linux-oem-6.0 Not in release
linux-oem-6.1 Not in release
linux-oem-6.5 Not in release
linux-oem-6.8 Ignored
linux-oem-6.11 Ignored
linux-raspi Needs evaluation
linux-raspi2 Not in release
linux-raspi-5.4 Not in release
linux-raspi-realtime Ignored
linux-realtime Ignored
linux-riscv Ignored
linux-riscv-5.8 Not in release
linux-riscv-5.11 Not in release
linux-riscv-5.15 Not in release
linux-riscv-5.19 Not in release
linux-riscv-6.5 Not in release
linux-riscv-6.8 Not in release
linux-starfive-5.19 Not in release
linux-starfive-6.2 Not in release
linux-starfive-6.5 Not in release
linux-xilinx-zynqmp Not in release
linux-intel Ignored
linux-hwe-6.11 Ignored
linux-lowlatency-hwe-6.11 Ignored
linux-nvidia-tegra Needs evaluation
linux-nvidia-tegra-igx Not in release
linux-azure-nvidia Needs evaluation
linux-azure-6.11 Ignored
linux-gcp-6.11 Ignored
linux-nvidia-tegra-5.15 Not in release
linux-oem-6.14 Ignored
linux-riscv-6.14 Ignored
linux-ibm-6.8 Not in release
linux-aws-6.14 Needs evaluation
linux-gcp-6.14 Needs evaluation
linux-hwe-6.14 Needs evaluation
linux-oracle-6.14 Ignored
linux-nvidia-6.11 Ignored
linux-realtime-6.14 Ignored
linux-realtime-6.8 Not in release
linux-azure-6.14 Needs evaluation
linux-azure-fde-6.14 Needs evaluation
linux-azure-nvidia-6.14 Needs evaluation
linux-xilinx Needs evaluation
linux-oem-6.17 Needs evaluation
linux-azure-fde-6.8 Not in release
linux-aws-6.17 Needs evaluation
linux-gcp-6.17 Needs evaluation
linux-hwe-6.17 Needs evaluation
linux-oracle-6.17 Needs evaluation
linux-riscv-6.17 Needs evaluation
linux-azure-6.17 Needs evaluation
linux-azure-fde-6.17 Needs evaluation
Show all 157 packages Show less packages

CVE-2025-12343

Negligible priority
Needs evaluation

A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf.c source file. The issue occurs in the dnn_execute_model_tf() function, where a task object is freed multiple times in certain error-handling...

2 affected packages

ffmpeg, libav

Package 24.04 LTS
ffmpeg Needs evaluation
libav Not in release
Show less packages

CVE-2025-0577

Medium priority
Not affected

An insufficient entropy vulnerability was found in glibc. The getrandom and arc4random family of functions may return predictable randomness if these functions are called again after the fork, which happens concurrently with a...

2 affected packages

eglibc, glibc

Package 24.04 LTS
eglibc Not in release
glibc Not affected
Show less packages

CVE-2026-2661

Medium priority

Not in release

A security flaw has been discovered in Squirrel up to 3.2. This affects the function SQObjectPtr::operator in the library squirrel/sqobject.h. The manipulation results in heap-based buffer overflow. The attack needs to...

1 affected package

squirrel3

Package 24.04 LTS
squirrel3 Not in release
Show less packages

CVE-2026-25500

Medium priority
Fixed

Rack is a modular Ruby web server interface. Prior to versions 2.2.22, 3.1.20, and 3.2.5, `Rack::Directory` generates an HTML directory index where each file entry is rendered as a clickable link. If a file exists on disk whose...

1 affected package

ruby-rack

Package 24.04 LTS
ruby-rack Fixed
Show less packages

CVE-2026-22860

Medium priority
Fixed

Rack is a modular Ruby web server interface. Prior to versions 2.2.22, 3.1.20, and 3.2.5, `Rack::Directory`’s path check used a string prefix match on the expanded path. A request like `/../root_example/` can escape the configured...

1 affected package

ruby-rack

Package 24.04 LTS
ruby-rack Fixed
Show less packages

CVE-2026-2659

Medium priority

Not in release

A vulnerability was determined in Squirrel up to 3.2. Affected by this vulnerability is the function SQFuncState::PopTarget of the file src/squirrel/squirrel/sqfuncstate.cpp. Executing a manipulation of the argument _target_stack...

1 affected package

squirrel3

Package 24.04 LTS
squirrel3 Not in release
Show less packages

CVE-2025-14009

High priority
Needs evaluation

A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions. The _unzip_iter function in nltk/downloader.py uses zipfile.extractall() without performing path validation or security checks....

1 affected package

nltk

Package 24.04 LTS
nltk Needs evaluation
Show less packages