Search CVE reports


Toggle filters

1 – 10 of 112 results


CVE-2024-52284

Medium priority
Needs evaluation

Unauthorized disclosure of sensitive data: Any user with `GET` or `LIST` permissions on `BundleDeployment` resources could retrieve Helm values containing credentials or other secrets.

1 affected package

fleet

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fleet Not in release Not in release
Show less packages

CVE-2025-27363

Medium priority
Fixed

An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable...

1 affected package

freetype

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freetype Not affected Fixed Fixed Fixed
Show less packages

CVE-2025-23022

Medium priority
Needs evaluation

FreeType 2.8.1 has a signed integer overflow in cf2_doFlex in cff/cf2intrp.c.

1 affected package

freetype

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freetype Not affected Not affected Not affected Needs evaluation
Show less packages

CVE-2024-23081

Medium priority
Ignored

ThreeTen Backport v1.6.8 was discovered to contain a NullPointerException via the component org.threeten.bp.LocalDate::compareTo(ChronoLocalDate). NOTE: this is disputed by multiple third parties who believe there was...

1 affected package

threeten-extra

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
threeten-extra Not affected Not affected Not affected
Show less packages

CVE-2024-23082

Medium priority
Ignored

ThreeTen Backport v1.6.8 was discovered to contain an integer overflow via the component org.threeten.bp.format.DateTimeFormatter::parse(CharSequence, ParsePosition). NOTE: this is disputed by multiple third parties who believe...

1 affected package

threeten-extra

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
threeten-extra Not affected Not affected Not affected
Show less packages

CVE-2024-23525

Medium priority

Some fixes available 3 of 4

The Spreadsheet::ParseXLSX package before 0.30 for Perl allows XXE attacks because it neglects to use the no_xxe option of XML::Twig.

1 affected package

libspreadsheet-parsexlsx-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libspreadsheet-parsexlsx-perl Not affected Fixed Fixed Ignored
Show less packages

CVE-2024-22368

Medium priority

Some fixes available 3 of 4

The Spreadsheet::ParseXLSX package before 0.28 for Perl can encounter an out-of-memory condition during parsing of a crafted XLSX document. This occurs because the memoize implementation does not have appropriate constraints on...

1 affected package

libspreadsheet-parsexlsx-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libspreadsheet-parsexlsx-perl Not affected Fixed Fixed Ignored
Show less packages

CVE-2023-7101

Medium priority

Some fixes available 5 of 7

Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a...

1 affected package

libspreadsheet-parseexcel-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libspreadsheet-parseexcel-perl Not affected Fixed Fixed Fixed
Show less packages

CVE-2023-2004

Medium priority
Fixed

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

1 affected package

freetype

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freetype Fixed Fixed Not affected
Show less packages

CVE-2022-31782

Medium priority

Some fixes available 3 of 4

ftbench.c in FreeType Demo Programs through 2.12.1 has a heap-based buffer overflow.

1 affected package

freetype

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freetype Fixed Fixed Fixed
Show less packages