Search CVE reports


Toggle filters

1 – 10 of 56037 results


CVE-2025-32387

Medium priority
Needs evaluation

Helm is a package manager for Charts for Kubernetes. A JSON Schema file within a chart can be crafted with a deeply nested chain of references, leading to parser recursion that can exceed the stack size limit and trigger a stack...

1 affected package

helm

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
helm Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-32386

Medium priority
Needs evaluation

Helm is a tool for managing Charts. A chart archive file can be crafted in a manner where it expands to be significantly larger uncompressed than compressed (e.g., >800x difference). When Helm loads this specially crafted chart,...

1 affected package

helm

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
helm Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-30215

Medium priority
Needs evaluation

[Unknown description]

1 affected package

nats-server

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
nats-server Needs evaluation Not in release Not in release
Show less packages

CVE-2025-32464

Medium priority
Vulnerable

HAProxy 2.2 through 3.1.6, in certain uncommon configurations, has a sample_conv_regsub heap-based buffer overflow because of mishandling of the replacement of multiple short patterns with a longer one.

1 affected package

haproxy

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
haproxy Vulnerable Vulnerable Not affected Not affected Not affected
Show less packages

CVE-2025-32460

Medium priority
Needs evaluation

GraphicsMagick before 8e56520 has a heap-based buffer over-read in ReadJXLImage in coders/jxl.c, related to an ImportViewPixelArea call.

1 affected package

graphicsmagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
graphicsmagick Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-31672

Medium priority
Needs evaluation

[Unknown description]

1 affected package

libapache-poi-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libapache-poi-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-31344

Medium priority
Needs evaluation

[Unknown description]

1 affected package

giflib

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
giflib Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-22871

Medium priority
Needs evaluation

The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare...

2 affected packages

golang-1.23, golang-1.24

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
golang-1.23 Needs evaluation Needs evaluation Not in release
golang-1.24 Not in release Not in release Not in release
Show less packages

CVE-2025-3416

Medium priority
Needs evaluation

A flaw was found in OpenSSL’s handling of the properties argument in certain functions. This vulnerability can allow use-after-free exploitation, which may result in undefined behavior or incorrect property parsing, leading to...

1 affected package

rust-openssl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
rust-openssl Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-26675

Medium priority
Needs evaluation

Out-of-bounds read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.

1 affected package

wsl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
wsl Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages