Bugs with TODO items

Hide "check" TODOs

BugDescriptionNote
CVE-2016-20023In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users c ...check
CVE-2022-23538github.com/sylabs/scs-library-client is the Go client for the Singular ...check details, might as well affect golang-github-apptainer-container-library-client
CVE-2023-26044react/http is an event-driven, streaming HTTP client and server implem ...check, is embedded inicinga-php-thirdparty, icingaweb2-module-reactbundle possibly affected
CVE-2023-49316In Math/BinaryField.php in phpseclib 3 before 3.0.34, excessively larg ...check if affecting ldap-account-manager or unused path
CVE-2023-50251php-svg-lib is an SVG file parsing / rendering library. Prior to versi ...check, other packages are embedding the library: civicrm, icinga-php-thirdparty and icingaweb2 to be checked
CVE-2023-50252php-svg-lib is an SVG file parsing / rendering library. Prior to versi ...check, other packages are embedding the library: civicrm, icinga-php-thirdparty and icingaweb2 to be checked
CVE-2023-50262Dompdf is an HTML to PDF converter for PHP. When parsing SVG images Do ...check sources embedding php-dompdf if affected
CVE-2024-3884A flaw was found in Undertow that can cause remote denial of service a ...check, RH bug not public
CVE-2024-22420JupyterLab is an extensible environment for interactive and reproducib ...check completeness, src:jupyter-notebook?
CVE-2024-22421JupyterLab is an extensible environment for interactive and reproducib ...check completeness, src:jupyter-notebook?
CVE-2025-4382A flaw was found in systems utilizing LUKS-encrypted disks with GRUB c ...double check if vulnerability only considered present after grub_is_cli_disabled is introduced
CVE-2025-4690A regular expression used by AngularJS' linky https://docs.angularjs.o ...check
CVE-2025-6499A vulnerability classified as problematic was found in vstakhov libucl ...check if impacts security wise rspamd, which embeds libucl and uses it a compile time
CVE-2025-8671A mismatch caused by client-triggered server-sent stream resets betwee ...check, some projects will assign own CVEs and should then be covered under that specific CVE instead
CVE-2025-8941A flaw was found in linux-pam. The pam_namespace module may improperly ...check if RedHat specific incomplete fix for CVE-2025-6020
CVE-2025-11010A vulnerability has been found in vstakhov libucl up to 0.9.2. Affecte ...check if impacts security wise rspamd, which embeds libucl and uses it a compile time
CVE-2025-11147Reflected cross-site scripting (XSS) in Apt-Cacher-NG v3.2.1. The vuln ...clarifying with reporter and Eduard Bloch on the issue.
CVE-2025-12383In Eclipse Jersey versions 2.45, 3.0.16, 3.1.9 a race condition can ca ...check
CVE-2025-41066Horde Groupware v5.2.22 has a user enumeration vulnerability that allo ...check, light on details
CVE-2025-58064CKEditor 5 is a modern JavaScript rich-text editor with an MVC archite ...check
CVE-2025-60796phpPgAdmin 7.13.0 and earlier contains multiple cross-site scripting ( ...check, possibly not reported upstream
CVE-2025-60797phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability i ...check, possibly not reported upstream
CVE-2025-60798phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability i ...check, possibly not reported upstream
CVE-2025-60799phpPgAdmin 7.13.0 and earlier contains an incorrect access control vul ...check, possibly not reported upstream
CVE-2025-61261A reflected cross-site scripting (XSS) vulnerability in CKeditor v46.1 ...check
CVE-2025-65102PJSIP is a free and open source multimedia communication library. Prio ...check, might affect asterisk and ring
CVE-2025-65548NUT-14 allows cashu tokens to be created with a preimage hash. However ...check
CVE-2025-65803An integer overflow in the psdParser::ReadImageData function of FreeIm ...check upstream details/report
CVE-2025-65807An issue in sd command v1.0.0 and before allows attackers to escalate ...check details and impact/severity
CVE-2025-66035Angular is a development platform for building mobile and desktop web ...check
CVE-2025-66412Angular is a development platform for building mobile and desktop web ...check
CVE-2025-66433HTCondor Access Point before 25.3.1 allows an authenticated user to im ...check, upstream advisory claims only affects 24.7.3 and above but unclear if only listing supported versions, and no details on fix
CVE-2025-66567The ruby-saml library is for implementing the client side of a SAML au ...check
CVE-2025-66568The ruby-saml library implements the client side of an SAML authorizat ...check
CVE-2025-66578xmlseclibs is a library written in PHP for working with XML Encryption ...check

Search for package or bug name: Reporting problems