Search CVE reports


Toggle filters

1 – 10 of 40375 results

Status is adjusted based on your filters.


CVE-2025-32807

Medium priority
Needs evaluation

A path traversal vulnerability in FusionDirectory before 1.5 allows remote attackers to read arbitrary files on the host that end with .png (and .svg or .xpm for some configurations) via the icon parameter of a GET request to geticon.php.

1 affected package

fusiondirectory

Package 16.04 LTS
fusiondirectory Needs evaluation
Show less packages

CVE-2025-32743

Medium priority
Needs evaluation

In ConnMan through 1.44, the lookup string in ns_resolv in dnsproxy.c can be NULL or an empty string when the TC (Truncated) bit is set in a DNS response. This allows attackers to cause a denial of service (application crash) or...

1 affected package

connman

Package 16.04 LTS
connman Needs evaluation
Show less packages

CVE-2025-32728

Medium priority
Not affected

In sshd in OpenSSH before 10.0, the DisableForwarding directive does not adhere to the documentation stating that it disables X11 and agent forwarding.

2 affected packages

openssh, openssh-ssh1

Package 16.04 LTS
openssh Not affected
openssh-ssh1
Show less packages

CVE-2025-29088

Medium priority
Needs evaluation

An issue in sqlite v.3.49.0 allows an attacker to cause a denial of service via the SQLITE_DBCONFIG_LOOKASIDE component

2 affected packages

sqlite, sqlite3

Package 16.04 LTS
sqlite Needs evaluation
sqlite3 Needs evaluation
Show less packages

CVE-2025-2761

Medium priority
Needs evaluation

[GIMP FLI File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability]

1 affected package

gimp

Package 16.04 LTS
gimp Needs evaluation
Show less packages

CVE-2025-2760

Medium priority
Needs evaluation

[GIMP XWD File Parsing Integer Overflow Remote Code Execution Vulnerability]

1 affected package

gimp

Package 16.04 LTS
gimp Needs evaluation
Show less packages

CVE-2024-38865

Medium priority
Needs evaluation

Improper neutralization of livestatus command delimiters in a specific endpoint within RestAPI of Checkmk prior to 2.2.0p39, 2.3.0p25, and 2.1.0p51 (EOL) allows arbitrary livestatus command execution. Exploitation requires the...

1 affected package

check-mk

Package 16.04 LTS
check-mk Needs evaluation
Show less packages

CVE-2025-32387

Medium priority
Needs evaluation

Helm is a package manager for Charts for Kubernetes. A JSON Schema file within a chart can be crafted with a deeply nested chain of references, leading to parser recursion that can exceed the stack size limit and trigger a stack...

1 affected package

helm

Package 16.04 LTS
helm Needs evaluation
Show less packages

CVE-2025-32386

Medium priority
Needs evaluation

Helm is a tool for managing Charts. A chart archive file can be crafted in a manner where it expands to be significantly larger uncompressed than compressed (e.g., >800x difference). When Helm loads this specially crafted chart,...

1 affected package

helm

Package 16.04 LTS
helm Needs evaluation
Show less packages

CVE-2025-32464

Medium priority
Not affected

HAProxy 2.2 through 3.1.6, in certain uncommon configurations, has a sample_conv_regsub heap-based buffer overflow because of mishandling of the replacement of multiple short patterns with a longer one.

1 affected package

haproxy

Package 16.04 LTS
haproxy Not affected
Show less packages