Search CVE reports
1 – 10 of 30164 results
CVE-2025-46421
Medium priorityA flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to...
2 affected packages
libsoup2.4, libsoup3
Package | 20.04 LTS |
---|---|
libsoup2.4 | Needs evaluation |
libsoup3 | Not in release |
CVE-2025-46420
Medium priorityA flaw was found in libsoup. It is vulnerable to memory leaks in the soup_header_parse_quality_list() function when parsing a quality list that contains elements with all zeroes.
2 affected packages
libsoup2.4, libsoup3
Package | 20.04 LTS |
---|---|
libsoup2.4 | Needs evaluation |
libsoup3 | Not in release |
CVE-2025-43859
Medium priorityh11 is a Python implementation of HTTP/1.1. Prior to version 0.16.0, a leniency in h11's parsing of line terminators in chunked-coding message bodies can lead to request smuggling vulnerabilities under certain conditions. This...
1 affected package
python-h11
Package | 20.04 LTS |
---|---|
python-h11 | Needs evaluation |
CVE-2025-27820
Medium priorityA bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release
1 affected package
httpcomponents-client
Package | 20.04 LTS |
---|---|
httpcomponents-client | Needs evaluation |
CVE-2025-46400
Medium prioritySegmentation fault in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via read_arcobject function.
1 affected package
fig2dev
Package | 20.04 LTS |
---|---|
fig2dev | Needs evaluation |
CVE-2025-46399
Medium prioritySegmentation fault in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via genge_itp_spline function.
1 affected package
fig2dev
Package | 20.04 LTS |
---|---|
fig2dev | Needs evaluation |
CVE-2025-46398
Medium priorityStack-overflow in fig2dev in version 3.2.9a allows an attacker possible code execution via local input manipulation via read_objects function.
1 affected package
fig2dev
Package | 20.04 LTS |
---|---|
fig2dev | Needs evaluation |
CVE-2025-46397
Medium priorityStack-overflow in fig2dev in version 3.2.9a allows an attacker possible code execution via local input manipulation via bezier_spline function.
1 affected package
fig2dev
Package | 20.04 LTS |
---|---|
fig2dev | Needs evaluation |
CVE-2025-46394
Medium priorityIn tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences.
1 affected package
busybox
Package | 20.04 LTS |
---|---|
busybox | Vulnerable |
CVE-2025-46393
Medium priorityIn multispectral MIFF image processing in ImageMagick before 7.1.1-44, packet_size is mishandled (related to the rendering of all channels in an arbitrary order).
1 affected package
imagemagick
Package | 20.04 LTS |
---|---|
imagemagick | Needs evaluation |