Bugs with TODO items

Hide "check" TODOs

BugDescriptionNote
CVE-2016-1584In all versions of Unity8 a running but not active application on a la ...check proper tracking update
CVE-2016-20023In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users c ...check
CVE-2020-36968M/Monit 3.7.4 contains an authentication vulnerability that allows aut ...check, unclear upstream status
CVE-2020-36969M/Monit 3.7.4 contains a privilege escalation vulnerability that allow ...check, unclear upstream status
CVE-2020-37011Gnome Fonts Viewer 3.34.0 contains a heap corruption vulnerability tha ...check, unclear upstream status. Doesn't reproduce with the version in trixie
CVE-2020-37038Code Blocks 20.03 contains a denial of service vulnerability that allo ...check, possibly just DoS of application and unimportant
CVE-2020-37040Code Blocks 17.12 contains a local buffer overflow vulnerability that ...check, might be Windows specific issue
CVE-2021-26381Improper system call parameter validation in the Trusted OS may allow ...check
CVE-2021-26410Improper syscall input validation in ASP (AMD Secure Processor) may fo ...check
CVE-2021-47793Telegram Desktop 2.9.2 contains a denial of service vulnerability that ...check
CVE-2022-23538github.com/sylabs/scs-library-client is the Go client for the Singular ...check details, might as well affect golang-github-apptainer-container-library-client
CVE-2022-50942Incinga Web 2.8.2 contains a client-side cross-site scripting vulnerab ...check status upstream
CVE-2023-26044react/http is an event-driven, streaming HTTP client and server implem ...check, is embedded inicinga-php-thirdparty, icingaweb2-module-reactbundle possibly affected
CVE-2023-49316In Math/BinaryField.php in phpseclib 3 before 3.0.34, excessively larg ...check if affecting ldap-account-manager or unused path
CVE-2023-50251php-svg-lib is an SVG file parsing / rendering library. Prior to versi ...check, other packages are embedding the library: civicrm, icinga-php-thirdparty and icingaweb2 to be checked
CVE-2023-50252php-svg-lib is an SVG file parsing / rendering library. Prior to versi ...check, other packages are embedding the library: civicrm, icinga-php-thirdparty and icingaweb2 to be checked
CVE-2023-50262Dompdf is an HTML to PDF converter for PHP. When parsing SVG images Do ...check sources embedding php-dompdf if affected
CVE-2024-4027A flaw was found in Undertow. Servlets using a method that calls HttpS ...check details
CVE-2024-21953Improper input validation in IOMMU could allow a malicious hypervisor ...check
CVE-2024-22420JupyterLab is an extensible environment for interactive and reproducib ...check completeness, src:jupyter-notebook?
CVE-2024-22421JupyterLab is an extensible environment for interactive and reproducib ...check completeness, src:jupyter-notebook?
CVE-2024-36310Improper input validation in the SMM communications buffer could allow ...check
CVE-2024-36311A Time-of-check time-of-use (TOCTOU) race condition in the SMM communi ...check
CVE-2024-36355Improper input validation in the SMM handler could allow an attacker w ...check
CVE-2024-54192An issue inTcpreplay v4.5.1 allows a local attacker to cause a denial ...check
CVE-2025-0012Improper handling of overlap between the segmented reverse map table ( ...check
CVE-2025-0029Improper handling of error condition during host-induced faults can al ...check
CVE-2025-0031A use after free in the SEV firmware could allow a malicous hypervisor ...check
CVE-2025-4382A flaw was found in systems utilizing LUKS-encrypted disks with GRUB c ...double check if vulnerability only considered present after grub_is_cli_disabled is introduced
CVE-2025-6499A vulnerability classified as problematic was found in vstakhov libucl ...check if impacts security wise rspamd, which embeds libucl and uses it a compile time
CVE-2025-8671A mismatch caused by client-triggered server-sent stream resets betwee ...check, some projects will assign own CVEs and should then be covered under that specific CVE instead
CVE-2025-8941A flaw was found in linux-pam. The pam_namespace module may improperly ...check likely RedHat specific incomplete fix for CVE-2025-6020, but asked to pinpoint incomplete fixes
CVE-2025-11010A vulnerability has been found in vstakhov libucl up to 0.9.2. Affecte ...check if impacts security wise rspamd, which embeds libucl and uses it a compile time
CVE-2025-11147Reflected cross-site scripting (XSS) in Apt-Cacher-NG v3.2.1. The vuln ...clarifying with reporter and Eduard Bloch on the issue.
CVE-2025-11242Server-Side Request Forgery (SSRF) vulnerability in Teknolist Computer ...check
CVE-2025-15569A flaw has been found in Artifex MuPDF up to 1.26.1 on Windows. The im ...check
CVE-2025-15570A vulnerability was found in ckolivas lrzip up to 0.651. This impacts ...check
CVE-2025-15571A security vulnerability has been detected in ckolivas lrzip up to 0.6 ...check
CVE-2025-15572A vulnerability has been found in wasm3 up to 0.5.0. The affected elem ...check
CVE-2025-20070Improper conditions check for the Intel(R) Optane(TM) PMem management ...check
CVE-2025-20080Null pointer dereference in the firmware for some Intel(R) AMT and Int ...check
CVE-2025-20106Uncontrolled search path in some software installer for some VTune(TM) ...check
CVE-2025-22453Improper input validation for some Server Firmware Update Utility(SysF ...check
CVE-2025-22849Incorrect default permissions for the Intel(R) Optane(TM) PMem managem ...check
CVE-2025-22885Improper buffer restrictions in the firmware for the TDX Module may al ...check
CVE-2025-24851Uncaught exception in the firmware for some 100GbE Intel(R) Ethernet C ...check
CVE-2025-25058Improper initialization for some ESXi kernel mode driver for the Intel ...check
CVE-2025-25210Improper input validation for some Server Firmware Update Utility(SysF ...check
CVE-2025-27243Out-of-bounds write in the firmware for some Intel(R) Ethernet Control ...check
CVE-2025-27535Exposed ioctl with insufficient access control in the firmware for som ...check
CVE-2025-27560Loop with unreachable exit condition ('infinite loop') for some Intel( ...check
CVE-2025-27572Exposure of sensitive information during transient execution for some ...check
CVE-2025-27708Out-of-bounds read in the firmware for some Intel(R) Converged Securit ...check
CVE-2025-27940Out-of-bounds read for some TDX Module before version tdx1.5 within Ri ...check
CVE-2025-29939Improper access control in secure encrypted virtualization (SEV) could ...check
CVE-2025-29946Insufficient or Incomplete Data Removal in Hardware Component in SEV f ...check
CVE-2025-29948Improper access control in AMD Secure Encrypted Virtualization (SEV) f ...check
CVE-2025-29949Insufficient input parameter sanitization in AMD Secure Processor (ASP ...check
CVE-2025-29950Improper input validation in system management mode (SMM) could allow ...check
CVE-2025-29951A buffer overflow in the AMD Secure Processor (ASP) bootloader could a ...check
CVE-2025-29952Improper Initialization within the AMD Secure Encrypted Virtualization ...check
CVE-2025-30508Improper authorization in the Intel(R) Quick Assist Technology for som ...check
CVE-2025-30513Race condition for some TDX Module within Ring 0: Hypervisor may allow ...check
CVE-2025-31648Improper handling of values in the microcode flow for some Intel(R) Pr ...check
CVE-2025-31655Incorrect default permissions for some Intel(R) Battery Life Diagnosti ...check
CVE-2025-31944Race condition for some TDX Module before version tdx1.5 within Ring 0 ...check
CVE-2025-32003Out-of-bounds read in the firmware for some 100GbE Intel(R) Ethernet N ...check
CVE-2025-32007Out-of-bounds read for some TDX before version tdx module 1.5.24 withi ...check
CVE-2025-32008Out-of-bounds write in the firmware for the Intel(R) AMT and Intel(R) ...check
CVE-2025-32092Insecure inherited permissions for some Intel(R) Graphics Software bef ...check
CVE-2025-32453Incorrect default permissions for some Intel(R) Graphics Driver softwa ...check
CVE-2025-32467Use of uninitialized variable for some TDX Module before version tdx1. ...check
CVE-2025-32735Improper conditions check in some firmware for some Intel(R) NPU Drive ...check
CVE-2025-32739Improper conditions check in some firmware for some Intel(R) Graphics ...check
CVE-2025-33030Improper conditions check in some firmware for some Intel(R) NPU Drive ...check
CVE-2025-35992Improper conditions check in some firmware for some Intel(R) NPU Drive ...check
CVE-2025-35998Missing protection mechanism for alternate hardware interface in the I ...check
CVE-2025-58064CKEditor 5 is a modern JavaScript rich-text editor with an MVC archite ...check
CVE-2025-60796phpPgAdmin 7.13.0 and earlier contains multiple cross-site scripting ( ...check, possibly not reported upstream
CVE-2025-60797phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability i ...check, possibly not reported upstream
CVE-2025-60798phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability i ...check, possibly not reported upstream
CVE-2025-60799phpPgAdmin 7.13.0 and earlier contains an incorrect access control vul ...check, possibly not reported upstream
CVE-2025-61261A reflected cross-site scripting (XSS) vulnerability in CKeditor v46.1 ...check
CVE-2025-65102PJSIP is a free and open source multimedia communication library. Prio ...check, might affect asterisk and ring
CVE-2025-65865An integer overflow in eProsima Fast-DDS v3.3 allows attackers to caus ...check https://gist.github.com/lkloliver/7aa48cb9fc7a1dd74cb595212bb69d33, unclear if reported upstream
CVE-2025-66412Angular is a development platform for building mobile and desktop web ...check, might not impact the 1.x versions of Angular
CVE-2025-66567The ruby-saml library is for implementing the client side of a SAML au ...check
CVE-2025-66568The ruby-saml library implements the client side of an SAML authorizat ...check
CVE-2025-66578xmlseclibs is a library written in PHP for working with XML Encryption ...check
CVE-2025-67108eProsima Fast-DDS v3.3 was discovered to contain improper validation f ...check https://gist.github.com/lkloliver/81b5d5a8328d712dbfd497bf11dbe913, unclear if reported upstream
CVE-2026-0671Improper Neutralization of Input During Web Page Generation (XSS or 'C ...check
CVE-2026-0708check if impacts security wise rspamd, which embeds libucl and uses it a compile time
CVE-2026-1703When pip is installing and extracting a maliciously crafted wheel arch ...check as well pipenv

Search for package or bug name: Reporting problems