Search CVE reports


Toggle filters

1 – 8 of 8 results


CVE-2025-52937

Medium priority
Needs evaluation

Vulnerability in PointCloudLibrary PCL (surface/src/3rdparty/opennurbs modules). This vulnerability is associated with program files crc32.C. This vulnerability is only relevant if the PCL version is older than 1.14.0 or the user...

1 affected package

pcl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pcl Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-4640

Medium priority
Needs evaluation

Out-of-bounds Write vulnerability in PointCloudLibrary pcl allows Overflow Buffers. Since version 1.14.0, PCL by default uses a zlib installation from the system, unless the user sets WITH_SYSTEM_ZLIB=FALSE. So this...

1 affected package

pcl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pcl Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-4638

Medium priority
Needs evaluation

A vulnerability exists in the inftrees.c component of the zlib library, which is bundled within the PointCloudLibrary (PCL). This issue may allow context-dependent attackers to cause undefined behavior by exploiting improper...

1 affected package

pcl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pcl Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-53432

Medium priority

Some fixes available 6 of 7

While parsing certain malformed PLY files, PCL version 1.14.1 crashes due to an uncaught std::out_of_range exception in PCLPointCloud2::at. This issue could potentially be exploited to cause a denial-of-service (DoS) attack when...

1 affected package

pcl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pcl Fixed Fixed Fixed Fixed
Show less packages

CVE-2015-5262

Medium priority

Some fixes available 18 of 19

http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClient before 4.3.6 ignores the http.socket.timeout configuration setting during an SSL handshake, which allows remote attackers to cause a denial of...

2 affected packages

commons-httpclient, httpcomponents-client

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
commons-httpclient Fixed Fixed Fixed
httpcomponents-client Not affected Not affected Not affected
Show less packages

CVE-2014-3577

Medium priority

Some fixes available 4 of 6

org.apache.http.conn.ssl.AbstractVerifier in Apache HttpComponents HttpClient before 4.3.5 and HttpAsyncClient before 4.0.2 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN)...

2 affected packages

commons-httpclient, httpcomponents-client

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
commons-httpclient Not affected
httpcomponents-client Not affected
Show less packages

CVE-2012-6153

Low priority

Some fixes available 1 of 3

http/conn/ssl/AbstractVerifier.java in Apache Commons HttpClient before 4.2.3 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the...

2 affected packages

commons-httpclient, httpcomponents-client

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
commons-httpclient
httpcomponents-client
Show less packages

CVE-2012-5783

Low priority

Some fixes available 1 of 5

Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN)...

2 affected packages

commons-httpclient, httpcomponents-client

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
commons-httpclient
httpcomponents-client
Show less packages