Search CVE reports


Toggle filters

551 – 560 of 32109 results

Status is adjusted based on your filters.


CVE-2026-24686

Medium priority
Needs evaluation

go-tuf is a Go implementation of The Update Framework (TUF). go-tuf's TAP 4 Multirepo Client uses the map file repository name string (`repoName`) as a filesystem path component when selecting the local metadata cache directory....

1 affected package

golang-github-theupdateframework-go-tuf

Package 24.04 LTS
golang-github-theupdateframework-go-tuf Needs evaluation
Show less packages

CVE-2026-24486

Medium priority
Fixed

Python-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Traversal vulnerability exists when using non-default configuration options `UPLOAD_DIR` and `UPLOAD_KEEP_FILENAME=True`. An attacker can...

1 affected package

python-multipart

Package 24.04 LTS
python-multipart Fixed
Show less packages

CVE-2026-24480

Medium priority
Needs evaluation

QGIS is a free, open source, cross platform geographical information system (GIS) The repository contains a GitHub Actions workflow called "pre-commit checks" that, before commit 76a693cd91650f9b4e83edac525e5e4f90d954e9,...

1 affected package

qgis

Package 24.04 LTS
qgis Needs evaluation
Show less packages

CVE-2026-22796

Low priority

Some fixes available 1 of 2

Issue summary: A type confusion vulnerability exists in the signature verification of signed PKCS#7 data where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference...

4 affected packages

openssl, openssl1.0, nodejs, edk2

Package 24.04 LTS
openssl Fixed
openssl1.0 Not in release
nodejs Not affected
edk2 Needs evaluation
Show less packages

CVE-2026-22795

Low priority
Fixed

Issue summary: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file. Impact summary: An application processing a malformed PKCS#12 file can be caused to dereference an invalid or...

4 affected packages

openssl, openssl1.0, nodejs, edk2

Package 24.04 LTS
openssl Fixed
openssl1.0 Not in release
nodejs Not affected
edk2 Not affected
Show less packages

CVE-2025-69421

Low priority
Fixed

Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function. Impact summary: A NULL pointer dereference can trigger a crash which leads to Denial of...

4 affected packages

openssl, openssl1.0, nodejs, edk2

Package 24.04 LTS
openssl Fixed
openssl1.0 Not in release
nodejs Not affected
edk2 Not affected
Show less packages

CVE-2025-69420

Low priority
Fixed

Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference...

4 affected packages

openssl, openssl1.0, nodejs, edk2

Package 24.04 LTS
openssl Fixed
openssl1.0 Not in release
nodejs Not affected
edk2 Not affected
Show less packages

CVE-2025-69419

Low priority

Some fixes available 1 of 2

Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII BMP code point can trigger a one byte write before the...

4 affected packages

openssl, openssl1.0, nodejs, edk2

Package 24.04 LTS
openssl Fixed
openssl1.0 Not in release
nodejs Not affected
edk2 Needs evaluation
Show less packages

CVE-2025-69418

Low priority

Some fixes available 1 of 2

Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs whose length is not a multiple<br>of 16 bytes can leave the final partial block unencrypted...

4 affected packages

openssl, openssl1.0, nodejs, edk2

Package 24.04 LTS
openssl Fixed
openssl1.0 Not in release
nodejs Not affected
edk2 Needs evaluation
Show less packages

CVE-2025-68160

Low priority

Some fixes available 1 of 2

Issue summary: Writing large, newline-free data into a BIO chain using the line-buffering filter where the next BIO performs short writes can trigger a heap-based out-of-bounds write. Impact summary: This out-of-bounds write can...

4 affected packages

openssl, openssl1.0, nodejs, edk2

Package 24.04 LTS
openssl Fixed
openssl1.0 Not in release
nodejs Not affected
edk2 Needs evaluation
Show less packages