Search CVE reports


Toggle filters

341 – 350 of 41351 results

Status is adjusted based on your filters.


CVE-2025-59465

Medium priority
Needs evaluation

A malformed `HTTP/2 HEADERS` frame with oversized, invalid `HPACK` data can cause Node.js to crash by triggering an unhandled `TLSSocket` error `ECONNRESET`. Instead of safely closing the connection, the process crashes, enabling...

1 affected package

nodejs

Package 18.04 LTS
nodejs Needs evaluation
Show less packages

CVE-2025-59464

Medium priority
Needs evaluation

A memory leak in Node.js’s OpenSSL integration occurs when converting `X.509` certificate fields to UTF-8 without freeing the allocated buffer. When applications call `socket.getPeerCertificate(true)`, each certificate field leaks...

1 affected package

nodejs

Package 18.04 LTS
nodejs Needs evaluation
Show less packages

CVE-2025-55132

Medium priority
Needs evaluation

A flaw in Node.js's permission model allows a file's access and modification timestamps to be changed via `futimes()` even when the process has only read permissions. Unlike `utimes()`, `futimes()` does not apply the expected...

1 affected package

nodejs

Package 18.04 LTS
nodejs Needs evaluation
Show less packages

CVE-2025-55131

Medium priority
Needs evaluation

A flaw in Node.js's buffer allocation logic can expose uninitialized memory when allocations are interrupted, when using the `vm` module with the timeout option. Under specific timing conditions, buffers allocated...

1 affected package

nodejs

Package 18.04 LTS
nodejs Needs evaluation
Show less packages

CVE-2025-55130

Medium priority
Needs evaluation

A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the...

1 affected package

nodejs

Package 18.04 LTS
nodejs Needs evaluation
Show less packages

CVE-2025-56005

Medium priority
Vulnerable

An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the `picklefile` parameter in the `yacc()` function. This parameter accepts a `.pkl` file that is deserialized...

1 affected package

ply

Package 18.04 LTS
ply Vulnerable
Show less packages

CVE-2025-33231

Medium priority
Needs evaluation

NVIDIA Nsight Systems for Windows contains a vulnerability in the application’s DLL loading mechanism where an attacker could cause an uncontrolled search path element by exploiting insecure DLL search paths. A successful exploit...

1 affected package

nvidia-cuda-toolkit

Package 18.04 LTS
nvidia-cuda-toolkit Needs evaluation
Show less packages

CVE-2025-33230

Medium priority
Needs evaluation

NVIDIA Nsight Systems for Linux contains a vulnerability in the .run installer, where an attacker could cause an OS command injection by supplying a malicious string to the installation path. A successful exploit of this...

1 affected package

nvidia-cuda-toolkit

Package 18.04 LTS
nvidia-cuda-toolkit Needs evaluation
Show less packages

CVE-2025-33229

Medium priority
Needs evaluation

NVIDIA Nsight Visual Studio for Windows contains a vulnerability in Nsight Monitor where an attacker can execute arbitrary code with the same privileges as the NVIDIA Nsight Visual Studio Edition Monitor application. A successful...

1 affected package

nvidia-cuda-toolkit

Package 18.04 LTS
nvidia-cuda-toolkit Needs evaluation
Show less packages

CVE-2025-33228

Medium priority
Needs evaluation

NVIDIA Nsight Systems contains a vulnerability in the gfx_hotspot recipe, where an attacker could cause an OS command injection by supplying a malicious string to the process_nsys_rep_cli.py script if the script is invoked...

1 affected package

nvidia-cuda-toolkit

Package 18.04 LTS
nvidia-cuda-toolkit Needs evaluation
Show less packages