Search CVE reports


Toggle filters

61 – 70 of 29681 results

Status is adjusted based on your filters.


CVE-2024-7021

Medium priority
Not affected

Inappropriate implementation in Autofill in Google Chrome on Windows prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

1 affected package

chromium-browser

Package 24.04 LTS
chromium-browser Not affected
Show less packages

CVE-2024-7017

Medium priority
Not affected

Inappropriate implementation in DevTools in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

1 affected package

chromium-browser

Package 24.04 LTS
chromium-browser Not affected
Show less packages

CVE-2024-13983

Medium priority
Not affected

Inappropriate implementation in Lens in Google Chrome on iOS prior to 136.0.7103.59 allowed a remote attacker to perform UI spoofing via a crafted QR code. (Chromium security severity: Low)

1 affected package

chromium-browser

Package 24.04 LTS
chromium-browser Not affected
Show less packages

CVE-2024-13178

Medium priority
Not affected

Inappropriate implementation in Fullscreen in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

1 affected package

chromium-browser

Package 24.04 LTS
chromium-browser Not affected
Show less packages

CVE-2024-11920

Medium priority
Not affected

Inappropriate implementation in Dawn in Google Chrome on Mac prior to 130.0.6723.92 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

1 affected package

chromium-browser

Package 24.04 LTS
chromium-browser Not affected
Show less packages

CVE-2024-11919

Medium priority
Not affected

Inappropriate implementation in Intents in Google Chrome on Android prior to 129.0.6668.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

1 affected package

chromium-browser

Package 24.04 LTS
chromium-browser Not affected
Show less packages

CVE-2025-47913

Medium priority
Vulnerable

SSH clients receiving SSH_AGENT_SUCCESS when expecting a typed response will panic and cause early termination of the client process.

4 affected packages

golang-go.crypto, snapd, lxd, google-guest-agent

Package 24.04 LTS
golang-go.crypto Needs evaluation
snapd Needs evaluation
lxd Not in release
google-guest-agent Vulnerable
Show less packages

CVE-2025-64718

Medium priority
Needs evaluation

js-yaml is a JavaScript YAML parser and dumper. In js-yaml 4.1.0 and below, it's possible for an attacker to modify the prototype of the result of a parsed yaml document via prototype pollution (`__proto__`). All users who parse...

1 affected package

node-js-yaml

Package 24.04 LTS
node-js-yaml Needs evaluation
Show less packages

CVE-2025-13120

Medium priority
Needs evaluation

A vulnerability has been found in mruby up to 3.4.0. This vulnerability affects the function sort_cmp of the file src/array.c. Such manipulation leads to use after free. An attack has to be approached locally. The exploit has been...

1 affected package

mruby

Package 24.04 LTS
mruby Needs evaluation
Show less packages

CVE-2025-12818

Medium priority
Needs evaluation

Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes. This results...

8 affected packages

postgresql-18, postgresql-17, postgresql-16, postgresql-14, postgresql-12...

Package 24.04 LTS
postgresql-18 Not in release
postgresql-17 Not in release
postgresql-16 Needs evaluation
postgresql-14 Not in release
postgresql-12 Not in release
postgresql-10 Not in release
postgresql-9.5 Not in release
postgresql-9.3 Not in release
Show all 8 packages Show less packages