Search CVE reports


Toggle filters

851 – 860 of 37112 results

Status is adjusted based on your filters.


CVE-2025-68468

Medium priority
Fixed

Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource...

1 affected package

avahi

Package 20.04 LTS
avahi Fixed
Show less packages

CVE-2025-68276

Medium priority
Fixed

Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, an unprivileged local users can crash avahi-daemon (with wide-area disabled) by creating record...

1 affected package

avahi

Package 20.04 LTS
avahi Fixed
Show less packages

CVE-2025-15506

Medium priority
Needs evaluation

A vulnerability was found in AcademySoftwareFoundation OpenColorIO up to 2.5.0. This issue affects the function ConvertToRegularExpression of the file src/OpenColorIO/FileRules.cpp. Performing a manipulation results...

1 affected package

opencolorio

Package 20.04 LTS
opencolorio Needs evaluation
Show less packages

CVE-2026-22702

Medium priority
Needs evaluation

virtualenv is a tool for creating isolated virtual python environments. Prior to version 20.36.1, TOCTOU (Time-of-Check-Time-of-Use) vulnerabilities in virtualenv allow local attackers to perform symlink-based attacks on directory...

1 affected package

python-virtualenv

Package 20.04 LTS
python-virtualenv Needs evaluation
Show less packages

CVE-2026-22701

Medium priority
Fixed

filelock is a platform-independent file lock for Python. Prior to version 3.20.3, a TOCTOU race condition vulnerability exists in the SoftFileLock implementation of the filelock package. An attacker with local filesystem access...

1 affected package

python-filelock

Package 20.04 LTS
python-filelock Fixed
Show less packages

CVE-2026-22693

Low priority
Not affected

HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer dereference vulnerability exists in the SubtableUnicodesCache::create function located in src/hb-ot-cmap-table.hh. The function fails to check if hb_malloc...

1 affected package

harfbuzz

Package 20.04 LTS
harfbuzz Not affected
Show less packages

CVE-2026-22691

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to version 6.6.0, pypdf has possible long runtimes for malformed startxref. An attacker who uses this vulnerability can craft a PDF which leads to possibly long...

2 affected packages

pypdf, pypdf2

Package 20.04 LTS
pypdf
pypdf2 Needs evaluation
Show less packages

CVE-2026-22690

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to version 6.6.0, pypdf has possible long runtimes for missing /Root object with large /Size values. An attacker who uses this vulnerability can craft a PDF...

2 affected packages

pypdf, pypdf2

Package 20.04 LTS
pypdf
pypdf2 Needs evaluation
Show less packages

CVE-2026-22610

Medium priority
Needs evaluation

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.18, 20.3.16, 21.0.7, and 21.1.0-rc.0, a cross-site scripting (XSS)...

1 affected package

angular.js

Package 20.04 LTS
angular.js Needs evaluation
Show less packages

CVE-2025-56225

Medium priority
Needs evaluation

fluidsynth-2.4.6 and earlier versions is vulnerable to Null pointer dereference in fluid_synth_monopoly.c, that can be triggered when loading an invalid midi file.

1 affected package

fluidsynth

Package 20.04 LTS
fluidsynth Needs evaluation
Show less packages