Search CVE reports


Toggle filters

491 – 500 of 62102 results


CVE-2025-12816

Medium priority
Needs evaluation

An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1 structures to desynchronize schema validations, yielding a semantic divergence that may...

1 affected package

node-node-forge

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-node-forge Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2025-13502

Medium priority

Some fixes available 4 of 18

A flaw was found in WebKitGTK and WPE WebKit. This vulnerability allows an out-of-bounds read and integer underflow, leading to a UIProcess crash (DoS) via a crafted payload to the GLib remote inspector server.

5 affected packages

webkitgtk, webkit2gtk, qtwebkit-source, qtwebkit-opensource-src, wpewebkit

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
webkitgtk Not in release Not in release Ignored
webkit2gtk Fixed Fixed Ignored Ignored
qtwebkit-source Not in release Not in release Ignored
qtwebkit-opensource-src Ignored Ignored Ignored Ignored
wpewebkit Not in release Ignored Ignored
Show less packages

CVE-2025-13644

Medium priority
Needs evaluation

MongoDB Server may experience an invariant failure during batched delete operations when handling documents. The issue arises when the server mistakenly assumes the presence of multiple documents in a batch based solely on...

1 affected package

mongodb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2025-13643

Medium priority
Needs evaluation

A user with access to the cluster with a limited set of privilege actions may be able to terminate queries that are being executed by other users. This may cause a denial of service by preventing a fraction of queries...

1 affected package

mongodb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2025-13507

Medium priority
Needs evaluation

Inconsistent object size validation in time series processing logic may result in later processing of oversized BSON documents leading to an assert failing and process termination. This issue impacts MongoDB Server v7.0 versions...

1 affected package

mongodb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2025-12893

Medium priority
Needs evaluation

Clients may successfully perform a TLS handshake with a MongoDB server despite presenting a client certificate not aligning with the documented Extended Key Usage (EKU) requirements. A certificate that specifies extendedKeyUsage...

1 affected package

mongodb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2025-65018

Medium priority

Some fixes available 7 of 13

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From version 1.6.0 to before 1.6.51, there is a heap buffer overflow vulnerability in the...

5 affected packages

libpng, libpng1.6, firefox, thunderbird, chromium-browser

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpng Not in release Not in release
libpng1.6 Fixed Fixed Fixed Fixed
firefox Not affected Not affected
thunderbird Needs evaluation Needs evaluation
chromium-browser Not affected Not affected
Show less packages

CVE-2025-64720

Medium priority

Some fixes available 7 of 13

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From version 1.6.0 to before 1.6.51, an out-of-bounds read vulnerability exists in...

5 affected packages

libpng, libpng1.6, firefox, thunderbird, chromium-browser

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpng Not in release Not in release
libpng1.6 Fixed Fixed Fixed Fixed
firefox Not affected Not affected
thunderbird Needs evaluation Needs evaluation
chromium-browser Not affected Not affected
Show less packages

CVE-2025-64506

Medium priority

Some fixes available 7 of 13

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From version 1.6.0 to before 1.6.51, a heap buffer over-read vulnerability exists in...

5 affected packages

libpng, libpng1.6, firefox, thunderbird, chromium-browser

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpng Not in release Not in release
libpng1.6 Fixed Fixed Fixed Fixed
firefox Not affected Not affected
thunderbird Needs evaluation Needs evaluation
chromium-browser Not affected Not affected
Show less packages

CVE-2025-64505

Medium priority

Some fixes available 7 of 13

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to version 1.6.51, a heap buffer over-read vulnerability exists in...

5 affected packages

libpng, libpng1.6, firefox, thunderbird, chromium-browser

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpng Not in release Not in release
libpng1.6 Fixed Fixed Fixed Fixed
firefox Not affected Not affected
thunderbird Needs evaluation Needs evaluation
chromium-browser Not affected Not affected
Show less packages