Search CVE reports


Toggle filters

211 – 220 of 29314 results

Status is adjusted based on your filters.


CVE-2025-11678

Medium priority
Needs evaluation

Stack-based Buffer Overflow in lws_adns_parse_label in warmcat libwebsockets allows, when the LWS_WITH_SYS_ASYNC_DNS flag is enabled during compilation, to overflow the label_stack, when the attacker is able to sniff a DNS request...

1 affected package

libwebsockets

Package 24.04 LTS
libwebsockets Needs evaluation
Show less packages

CVE-2025-11677

Medium priority
Needs evaluation

Use After Free in WebSocket server implementation in lws_handshake_server in warmcat libwebsockets may allow an attacker, in specific configurations where the user provides a callback function...

1 affected package

libwebsockets

Package 24.04 LTS
libwebsockets Needs evaluation
Show less packages

CVE-2024-31573

Medium priority
Needs evaluation

XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (used for an XSLT transformation), because XSLT extension functions are enabled.

1 affected package

xmlunit

Package 24.04 LTS
xmlunit Needs evaluation
Show less packages

CVE-2014-6439

Medium priority

Not in release

(Cross-site scripting (XSS) vulnerability in the CORS functionality in ...)

1 affected package

elasticsearch

Package 24.04 LTS
elasticsearch Not in release
Show less packages

CVE-2025-6338

Medium priority
Not affected

There is an incomplete cleanup vulnerability in Qt Network's Schannel support on Windows which can lead to a Denial of Service over a long period.This issue affects Qt from 5.15.0 through 6.8.3, from 6.9.0 before 6.9.2.

1 affected package

qt6-base

Package 24.04 LTS
qt6-base Not affected
Show less packages

CVE-2025-62496

Medium priority
Needs evaluation

A vulnerability exists in the QuickJS engine's BigInt string parsing logic (js_bigint_from_string) when attempting to create a BigInt from a string with an excessively large number of digits. The function calculates the necessary...

1 affected package

quickjs

Package 24.04 LTS
quickjs Needs evaluation
Show less packages

CVE-2025-62495

Medium priority
Needs evaluation

An integer overflow vulnerability exists in the QuickJS regular expression engine (libregexp) due to an inconsistent representation of the bytecode buffer size. * The regular expression bytecode is stored in a DynBuf structure,...

1 affected package

quickjs

Package 24.04 LTS
quickjs Needs evaluation
Show less packages

CVE-2025-62494

Medium priority
Needs evaluation

A type confusion vulnerability exists in the handling of the string addition (+) operation within the QuickJS engine. * The code first checks if the left-hand operand is a string. * It then attempts to convert the right-hand...

1 affected package

quickjs

Package 24.04 LTS
quickjs Needs evaluation
Show less packages

CVE-2025-62493

Medium priority
Needs evaluation

A vulnerability exists in the QuickJS engine's BigInt string conversion logic (js_bigint_to_string1) due to an incorrect calculation of the required number of digits, which in turn leads to reading memory past the allocated BigInt...

1 affected package

quickjs

Package 24.04 LTS
quickjs Needs evaluation
Show less packages

CVE-2025-62492

Medium priority
Needs evaluation

A vulnerability stemming from floating-point arithmetic precision errors exists in the QuickJS engine's implementation of TypedArray.prototype.indexOf() when a negative fromIndex argument is supplied. * The fromIndex argument...

1 affected package

quickjs

Package 24.04 LTS
quickjs Needs evaluation
Show less packages