Search CVE reports


Toggle filters

451 – 460 of 31781 results

Status is adjusted based on your filters.


CVE-2025-70298

Medium priority
Needs evaluation

GPAC v2.4.0 was discovered to contain an out-of-bounds read in the oggdmx_parse_tags function.

1 affected package

gpac

Package 24.04 LTS
gpac Needs evaluation
Show less packages

CVE-2025-66417

Medium priority

Not in release

GLPI is a free asset and IT management software package. From 11.0.0, < 11.0.3, an unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 11.0.3.

1 affected package

glpi

Package 24.04 LTS
glpi Not in release
Show less packages

CVE-2025-64516

Medium priority

Not in release

GLPI is a free asset and IT management software package. Prior to 10.0.21 and 11.0.3, an unauthorized user can access GLPI documents attached to any item (ticket, asset, ...). If the public FAQ is enabled, this unauthorized access...

1 affected package

glpi

Package 24.04 LTS
glpi Not in release
Show less packages

CVE-2026-0992

Medium priority
Fixed

A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated <nextCatalog> elements pointing to the same downstream catalog. A remote...

1 affected package

libxml2

Package 24.04 LTS
libxml2 Fixed
Show less packages

CVE-2026-0990

Medium priority
Fixed

A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote...

1 affected package

libxml2

Package 24.04 LTS
libxml2 Fixed
Show less packages

CVE-2026-0989

Medium priority
Fixed

A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially crafted or...

1 affected package

libxml2

Package 24.04 LTS
libxml2 Fixed
Show less packages

CVE-2026-0897

Medium priority

Not in release

Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through 3.13.0 on all platforms allows a remote attacker to cause a Denial of Service (DoS) through memory exhaustion...

1 affected package

keras

Package 24.04 LTS
keras Not in release
Show less packages

CVE-2026-0962

Medium priority
Needs evaluation

SOME/IP-SD protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service

1 affected package

wireshark

Package 24.04 LTS
wireshark Needs evaluation
Show less packages

CVE-2026-0961

Medium priority
Needs evaluation

BLF file parser crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service

1 affected package

wireshark

Package 24.04 LTS
wireshark Needs evaluation
Show less packages

CVE-2026-0960

Medium priority
Needs evaluation

HTTP3 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.2 allows denial of service

1 affected package

wireshark

Package 24.04 LTS
wireshark Needs evaluation
Show less packages