Search CVE reports


Toggle filters

1 – 10 of 30002 results

Status is adjusted based on your filters.


CVE-2025-62408

Medium priority
Needs evaluation

c-ares is an asynchronous resolver library. Versions 1.32.3 through 1.34.5 terminate a query after maximum attempts when using read_answer() and process_answer(), which can cause a Denial of Service. This issue is fixed in version 1.34.6.

1 affected package

c-ares

Package 24.04 LTS
c-ares Needs evaluation
Show less packages

CVE-2025-59391

Medium priority
Needs evaluation

A memory disclosure vulnerability exists in libcoap's OSCORE configuration parser in libcoap before release-4.3.5-patches. An out-of-bounds read may occur when parsing certain configuration values, allowing an attacker to infer or...

3 affected packages

libcoap, libcoap2, libcoap3

Package 24.04 LTS
libcoap Not in release
libcoap2 Not in release
libcoap3 Needs evaluation
Show less packages

CVE-2025-59030

Medium priority
Needs evaluation

[Insufficient validation of incoming notifies over TCP can lead to a denial of service in Recursor]

1 affected package

pdns-recursor

Package 24.04 LTS
pdns-recursor Needs evaluation
Show less packages

CVE-2025-59029

Medium priority
Needs evaluation

[Internal logic flaw in cache management can lead to a denial of service in Recursor]

1 affected package

pdns-recursor

Package 24.04 LTS
pdns-recursor Needs evaluation
Show less packages

CVE-2025-66577

Medium priority
Needs evaluation

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.27.0, a vulnerability allows attacker-controlled HTTP headers to influence server-visible metadata, logging, and authorization decisions....

1 affected package

cpp-httplib

Package 24.04 LTS
cpp-httplib Needs evaluation
Show less packages

CVE-2025-66570

High priority
Needs evaluation

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.27.0, a vulnerability allows attacker-controlled HTTP headers to influence server-visible metadata, logging, and authorization decisions....

1 affected package

cpp-httplib

Package 24.04 LTS
cpp-httplib Needs evaluation
Show less packages

CVE-2025-66566

Medium priority
Needs evaluation

yawkat LZ4 Java provides LZ4 compression for Java. Insufficient clearing of the output buffer in Java-based decompressor implementations in lz4-java 1.10.0 and earlier allows remote attackers to read previous buffer contents via...

1 affected package

lz4-java

Package 24.04 LTS
lz4-java Needs evaluation
Show less packages

CVE-2025-66549

Medium priority
Needs evaluation

Nextcloud Desktop is the desktop sync client for Nextcloud. Prior to 3.16.5, when trying to manually lock a file inside an end-to-end encrypted directory, the path of the file was sent to the server unencrypted, making it possible...

1 affected package

nextcloud-desktop

Package 24.04 LTS
nextcloud-desktop Needs evaluation
Show less packages

CVE-2025-66471

Medium priority
Needs evaluation

urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handling of...

2 affected packages

python-urllib3, python-pip

Package 24.04 LTS
python-urllib3 Needs evaluation
python-pip Needs evaluation
Show less packages

CVE-2025-66418

Medium priority
Needs evaluation

urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited...

2 affected packages

python-urllib3, python-pip

Package 24.04 LTS
python-urllib3 Needs evaluation
python-pip Needs evaluation
Show less packages