Bugs with TODO items

Hide "check" TODOs

BugDescriptionNote
CVE-2021-4472The mistral-dashboard plugin for openstack has a local file inclusion ...check
CVE-2022-23538github.com/sylabs/scs-library-client is the Go client for the Singular ...check details, might as well affect golang-github-apptainer-container-library-client
CVE-2023-26044react/http is an event-driven, streaming HTTP client and server implem ...check, is embedded inicinga-php-thirdparty, icingaweb2-module-reactbundle possibly affected
CVE-2023-49316In Math/BinaryField.php in phpseclib 3 before 3.0.34, excessively larg ...check if affecting ldap-account-manager or unused path
CVE-2023-50251php-svg-lib is an SVG file parsing / rendering library. Prior to versi ...check, other packages are embedding the library: civicrm, icinga-php-thirdparty and icingaweb2 to be checked
CVE-2023-50252php-svg-lib is an SVG file parsing / rendering library. Prior to versi ...check, other packages are embedding the library: civicrm, icinga-php-thirdparty and icingaweb2 to be checked
CVE-2023-50262Dompdf is an HTML to PDF converter for PHP. When parsing SVG images Do ...check sources embedding php-dompdf if affected
CVE-2024-21922A DLL hijacking vulnerability in AMD StoreMI\u2122 could allow an atta ...check
CVE-2024-21923Incorrect default permissions in AMD StoreMI\u2122 could allow an atta ...check
CVE-2024-22420JupyterLab is an extensible environment for interactive and reproducib ...check completeness, src:jupyter-notebook?
CVE-2024-22421JupyterLab is an extensible environment for interactive and reproducib ...check completeness, src:jupyter-notebook?
CVE-2025-0003Inadequate lock protection within Xilinx Run time may allow a local at ...check
CVE-2025-0005Improper input validation within the XOCL driver may allow a local att ...check
CVE-2025-0007Insufficient validation within Xilinx Run Time framework could allow a ...check
CVE-2025-2486The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI S ...check
CVE-2025-4382A flaw was found in systems utilizing LUKS-encrypted disks with GRUB c ...double check if vulnerability only considered present after grub_is_cli_disabled is introduced
CVE-2025-4690A regular expression used by AngularJS' linky https://docs.angularjs.o ...check
CVE-2025-4953A flaw was found in Podman. In a Containerfile or Podman, data written ...check details
CVE-2025-6499A vulnerability classified as problematic was found in vstakhov libucl ...check if impacts security wise rspamd, which embeds libucl and uses it a compile time
CVE-2025-8671A mismatch caused by client-triggered server-sent stream resets betwee ...check, some projects will assign own CVEs and should then be covered under that specific CVE instead
CVE-2025-8941A flaw was found in linux-pam. The pam_namespace module may improperly ...check if RedHat specific incomplete fix for CVE-2025-6020
CVE-2025-11010A vulnerability has been found in vstakhov libucl up to 0.9.2. Affecte ...check if impacts security wise rspamd, which embeds libucl and uses it a compile time
CVE-2025-11147Reflected cross-site scripting (XSS) in Apt-Cacher-NG v3.2.1. The vuln ...clarifying with reporter and Eduard Bloch on the issue.
CVE-2025-12383In Eclipse Jersey versions 2.45, 3.0.16, 3.1.9 a race condition can ca ...check
CVE-2025-13502A flaw was found in WebKitGTK and WPE WebKit. This vulnerability allow ...check
CVE-2025-13601A heap-based buffer overflow problem was found in glib through an inco ...check
CVE-2025-45311Insecure permissions in fail2ban-client v0.11.2 allows attackers with ...check
CVE-2025-48507The security state of the calling processor into Arm\xae Trusted Firmw ...check
CVE-2025-52538Improper input validation within the XOCL driver may allow a local att ...check
CVE-2025-52539A buffer overflow with Xilinx Run Time Environment may allow a local a ...check
CVE-2025-54515The Secure Flag passed to Versal\u2122 Adaptive SoC\u2019s Arm\xae Tru ...check
CVE-2025-58064CKEditor 5 is a modern JavaScript rich-text editor with an MVC archite ...check
CVE-2025-59390Apache Druid\u2019s Kerberos authenticator uses a weak fallback secret ...check
CVE-2025-60796phpPgAdmin 7.13.0 and earlier contains multiple cross-site scripting ( ...check, possibly not reported upstream
CVE-2025-60797phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability i ...check, possibly not reported upstream
CVE-2025-60798phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability i ...check, possibly not reported upstream
CVE-2025-60799phpPgAdmin 7.13.0 and earlier contains an incorrect access control vul ...check, possibly not reported upstream
CVE-2025-61261A reflected cross-site scripting (XSS) vulnerability in CKeditor v46.1 ...check
CVE-2025-62728SQL injection vulnerability in Hive Metastore Server (HMS) when proces ...check
CVE-2025-65102PJSIP is a free and open source multimedia communication library. Prio ...check, might affect asterisk and ring
CVE-2025-65502Null pointer dereference in add_ca_certs() in Cesanta Mongoose before ...check

Search for package or bug name: Reporting problems