Search CVE reports


Toggle filters

1 – 10 of 34705 results

Status is adjusted based on your filters.


CVE-2025-46421

Medium priority
Needs evaluation

A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to...

2 affected packages

libsoup2.4, libsoup3

Package 18.04 LTS
libsoup2.4 Needs evaluation
libsoup3
Show less packages

CVE-2025-46420

Medium priority
Needs evaluation

A flaw was found in libsoup. It is vulnerable to memory leaks in the soup_header_parse_quality_list() function when parsing a quality list that contains elements with all zeroes.

2 affected packages

libsoup2.4, libsoup3

Package 18.04 LTS
libsoup2.4 Needs evaluation
libsoup3
Show less packages

CVE-2025-27820

Medium priority
Needs evaluation

A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release

1 affected package

httpcomponents-client

Package 18.04 LTS
httpcomponents-client Needs evaluation
Show less packages

CVE-2025-46400

Medium priority
Needs evaluation

Segmentation fault in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via read_arcobject function.

1 affected package

fig2dev

Package 18.04 LTS
fig2dev Needs evaluation
Show less packages

CVE-2025-46399

Medium priority
Needs evaluation

Segmentation fault in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via genge_itp_spline function.

1 affected package

fig2dev

Package 18.04 LTS
fig2dev Needs evaluation
Show less packages

CVE-2025-46398

Medium priority
Needs evaluation

Stack-overflow in fig2dev in version 3.2.9a allows an attacker possible code execution via local input manipulation via read_objects function.

1 affected package

fig2dev

Package 18.04 LTS
fig2dev Needs evaluation
Show less packages

CVE-2025-46397

Medium priority
Needs evaluation

Stack-overflow in fig2dev in version 3.2.9a allows an attacker possible code execution via local input manipulation via bezier_spline function.

1 affected package

fig2dev

Package 18.04 LTS
fig2dev Needs evaluation
Show less packages

CVE-2025-46394

Medium priority
Vulnerable

In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences.

1 affected package

busybox

Package 18.04 LTS
busybox Vulnerable
Show less packages

CVE-2025-46393

Medium priority
Needs evaluation

In multispectral MIFF image processing in ImageMagick before 7.1.1-44, packet_size is mishandled (related to the rendering of all channels in an arbitrary order).

1 affected package

imagemagick

Package 18.04 LTS
imagemagick Needs evaluation
Show less packages

CVE-2025-43965

Medium priority
Needs evaluation

In MIFF image processing in ImageMagick before 7.1.1-44, image depth is mishandled after SetQuantumFormat is used.

1 affected package

imagemagick

Package 18.04 LTS
imagemagick Needs evaluation
Show less packages