{"cves":[{"id":"CVE-2025-66047","published":"2025-12-11T17:15:00","updated_at":"2025-12-17T07:06:03.022334+00:00","description":"\nSeveral stack-based buffer overflow vulnerabilities exists in the MFER\nparsing functionality of The Biosig Project libbiosig 3.9.1. A specially\ncrafted MFER file can lead to arbitrary code execution. An attacker can\nprovide a malicious file to trigger these vulnerabilities.When Tag is 131","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-66047","https://sourceforge.net/p/biosig/mailman/message/59271419/","https://talosintelligence.com/vulnerability_reports/TALOS-2025-2296"],"bugs":[""],"patches":{"biosig":[]},"tags":{},"packages":[{"name":"biosig","source":"https://ubuntu.com/security/cve?package=biosig","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=biosig","debian":"https://tracker.debian.org/pkg/biosig","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-66046","published":"2025-12-11T17:15:00","updated_at":"2025-12-17T07:09:33.476760+00:00","description":"\nSeveral stack-based buffer overflow vulnerabilities exists in the MFER\nparsing functionality of The Biosig Project libbiosig 3.9.1. A specially\ncrafted MFER file can lead to arbitrary code execution. An attacker can\nprovide a malicious file to trigger these vulnerabilities.When Tag is 67","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-66046","https://sourceforge.net/p/biosig/mailman/message/59271419/","https://talosintelligence.com/vulnerability_reports/TALOS-2025-2296"],"bugs":[""],"patches":{"biosig":[]},"tags":{},"packages":[{"name":"biosig","source":"https://ubuntu.com/security/cve?package=biosig","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=biosig","debian":"https://tracker.debian.org/pkg/biosig","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-66045","published":"2025-12-11T17:15:00","updated_at":"2025-12-17T07:06:50.934578+00:00","description":"\nSeveral stack-based buffer overflow vulnerabilities exists in the MFER\nparsing functionality of The Biosig Project libbiosig 3.9.1. A specially\ncrafted MFER file can lead to arbitrary code execution. An attacker can\nprovide a malicious file to trigger these vulnerabilities.When Tag is 65","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-66045","https://sourceforge.net/p/biosig/mailman/message/59271419/","https://talosintelligence.com/vulnerability_reports/TALOS-2025-2296"],"bugs":[""],"patches":{"biosig":[]},"tags":{},"packages":[{"name":"biosig","source":"https://ubuntu.com/security/cve?package=biosig","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=biosig","debian":"https://tracker.debian.org/pkg/biosig","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-66044","published":"2025-12-11T17:15:00","updated_at":"2025-12-17T07:08:22.469392+00:00","description":"\nSeveral stack-based buffer overflow vulnerabilities exists in the MFER\nparsing functionality of The Biosig Project libbiosig 3.9.1. A specially\ncrafted MFER file can lead to arbitrary code execution. An attacker can\nprovide a malicious file to trigger these vulnerabilities.When Tag is 64","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-66044","https://sourceforge.net/p/biosig/mailman/message/59271419/","https://talosintelligence.com/vulnerability_reports/TALOS-2025-2296"],"bugs":[""],"patches":{"biosig":[]},"tags":{},"packages":[{"name":"biosig","source":"https://ubuntu.com/security/cve?package=biosig","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=biosig","debian":"https://tracker.debian.org/pkg/biosig","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-66043","published":"2025-12-11T17:15:00","updated_at":"2025-12-17T07:05:19.654932+00:00","description":"\nSeveral stack-based buffer overflow vulnerabilities exists in the MFER\nparsing functionality of The Biosig Project libbiosig 3.9.1. A specially\ncrafted MFER file can lead to arbitrary code execution. An attacker can\nprovide a malicious file to trigger these vulnerabilities.When Tag is 3","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-66043","https://sourceforge.net/p/biosig/mailman/message/59271419/","https://talosintelligence.com/vulnerability_reports/TALOS-2025-2296"],"bugs":[""],"patches":{"biosig":[]},"tags":{},"packages":[{"name":"biosig","source":"https://ubuntu.com/security/cve?package=biosig","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=biosig","debian":"https://tracker.debian.org/pkg/biosig","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-14523","published":"2025-12-11T13:15:00","updated_at":"2026-03-11T18:01:10.097761+00:00","description":"\nA flaw in libsoup’s HTTP header handling allows multiple Host: headers in a\nrequest and returns the last occurrence for server-side processing. Common\nfront proxies often honor the first Host: header, so this mismatch can\ncause vhost confusion where a proxy routes a request to one backend but the\nbackend interprets it as destined for another host. This discrepancy\nenables request-smuggling style attacks, cache poisoning, or bypassing\nhost-based access controls when an attacker supplies duplicate Host\nheaders.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":8.2,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-14523","https://access.redhat.com/security/cve/CVE-2025-14523"],"bugs":["https://gitlab.gnome.org/GNOME/libsoup/-/issues/472","https://bugzilla.redhat.com/show_bug.cgi?id=2421349"],"patches":{"libsoup2.4":[],"libsoup3":["upstream: https://gitlab.gnome.org/GNOME/libsoup/-/commit/aecd8daadc110f8561fb2d6b2806a4cacf2e4c85"]},"tags":{},"packages":[{"name":"libsoup2.4","source":"https://ubuntu.com/security/cve?package=libsoup2.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libsoup2.4","debian":"https://tracker.debian.org/pkg/libsoup2.4","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was deferred [2026-01-13]","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"}]},{"name":"libsoup3","source":"https://ubuntu.com/security/cve?package=libsoup3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libsoup3","debian":"https://tracker.debian.org/pkg/libsoup3","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"3.6.6-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was deferred [2026-01-13]","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.6.5-7","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-12734","published":"2025-12-11T08:15:00","updated_at":"2026-01-21T13:55:15.927250+00:00","description":"\nGitLab has remediated an issue in GitLab CE/EE affecting all versions from\n15.6 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could\nhave allowed an authenticated user to, under certain conditions, render\ncontent in dialogs to other users by injecting malicious HTML content into\nmerge request titles.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"GitLab isn't maintainable as a distro package, and was removed\nfrom Ubuntu because of this. We will not be fixing security\nissues in the gitlab package in Xenial."}],"codename":null,"priority":"medium","cvss3":3.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":3.5,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-12734"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-14512","published":"2025-12-11T07:16:00","updated_at":"2026-01-06T15:53:19.576349+00:00","description":"\nA flaw was found in glib. This vulnerability allows a heap buffer overflow\nand denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib\nInput/Output) escape_byte_string() function when processing malicious file\nor remote filesystem attribute values.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"The fix for this issue was included in USN-7942-1 but wasn't\nmentioned in the USN as the issue did not originally have a CVE\nassigned."}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-14512","https://gitlab.gnome.org/GNOME/glib/-/merge_requests/4935","https://gitlab.gnome.org/GNOME/glib/-/merge_requests/4936","https://access.redhat.com/security/cve/CVE-2025-14512"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1122346","https://gitlab.gnome.org/GNOME/glib/-/issues/3845","https://bugzilla.redhat.com/show_bug.cgi?id=2421339"],"patches":{"glib2.0":["upstream: https://gitlab.gnome.org/GNOME/glib/-/commit/4f0399c0aaf3ffc86b5625424580294bc7460404"]},"tags":{},"packages":[{"name":"glib2.0","source":"https://ubuntu.com/security/cve?package=glib2.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=glib2.0","debian":"https://tracker.debian.org/pkg/glib2.0","statuses":[{"release_codename":"resolute","status":"released","description":"2.86.3-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.86.3-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"2.72.4-0ubuntu2.7","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"2.80.0-6ubuntu3.6","component":null,"pocket":"security"},{"release_codename":"plucky","status":"released","description":"2.84.1-1ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"2.86.0-2ubuntu0.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-8405","published":"2025-12-11T05:16:00","updated_at":"2026-01-21T13:52:52.058427+00:00","description":"\nGitLab has remediated a security issue in GitLab CE/EE affecting all\nversions from 17.1 before 18.4.6, 18.5 before 18.5.4, and 18.6 before\n18.6.2 that could have allowed an authenticated user to perform\nunauthorized actions on behalf of other users by injecting malicious HTML\ninto vulnerability code flow displays.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"GitLab isn't maintainable as a distro package, and was removed\nfrom Ubuntu because of this. We will not be fixing security\nissues in the gitlab package in Xenial."}],"codename":null,"priority":"medium","cvss3":7.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.7,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-8405"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-4097","published":"2025-12-11T05:16:00","updated_at":"2026-02-04T13:18:33.699323+00:00","description":"\nGitLab has remediated an issue in GitLab CE/EE affecting all versions from\n11.10 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could\nhave allowed an authenticated user to cause a denial of service condition\nby uploading specially crafted images.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"GitLab isn't maintainable as a distro package, and was removed\nfrom Ubuntu because of this. We will not be fixing security\nissues in the gitlab package in Xenial."}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-4097"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-11984","published":"2025-12-11T05:16:00","updated_at":"2026-01-21T13:59:56.914691+00:00","description":"\nGitLab has remediated an issue in GitLab CE/EE affecting all versions from\n13.1 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could\nhave allowed an authenticated user to bypass WebAuthn two-factor\nauthentication by manipulating the session state under certain conditions.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"GitLab isn't maintainable as a distro package, and was removed\nfrom Ubuntu because of this. We will not be fixing security\nissues in the gitlab package in Xenial."}],"codename":null,"priority":"medium","cvss3":6.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":6.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-11984"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-14157","published":"2025-12-11T04:15:00","updated_at":"2026-01-21T13:53:13.335838+00:00","description":"\nGitLab has remediated an issue in GitLab CE/EE affecting all versions from\n6.3 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could\nhave allowed an authenticated user to cause a Denial of Service condition\nby sending crafted API calls with large content parameters.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"GitLab isn't maintainable as a distro package, and was removed\nfrom Ubuntu because of this. We will not be fixing security\nissues in the gitlab package in Xenial."}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-14157"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-13978","published":"2025-12-11T04:15:00","updated_at":"2026-01-21T13:54:15.227719+00:00","description":"\nGitLab has remediated an issue in GitLab CE/EE affecting all versions from\n17.5 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could\nhave allowed an authenticated user to discover the names of private\nprojects they do not have access through API requests.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"GitLab isn't maintainable as a distro package, and was removed\nfrom Ubuntu because of this. We will not be fixing security\nissues in the gitlab package in Xenial."}],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-13978"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-12562","published":"2025-12-11T04:15:00","updated_at":"2026-01-21T13:56:35.664725+00:00","description":"\nGitLab has remediated an issue in GitLab CE/EE affecting all versions from\n11.10 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could\nhave allowed an unauthenticated user to create a denial of service\ncondition by sending crafted GraphQL queries that bypass query complexity\nlimits.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"GitLab isn't maintainable as a distro package, and was removed\nfrom Ubuntu because of this. We will not be fixing security\nissues in the gitlab package in Xenial."}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-12562"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-67713","published":"2025-12-11T01:16:00","updated_at":"2026-07-10T19:18:25.251728+00:00","description":"\nMiniflux 2 is an open source feed reader. Versions 2.2.14 and below treat\nredirect_url as safe when url.Parse(...).IsAbs() is false, enabling\nphishing flows after login. Protocol-relative URLs like //ikotaslabs.com\nhave an empty scheme and pass that check, allowing post-login redirects to\nattacker-controlled sites. This issue is fixed in version 2.2.15.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-67713","https://github.com/miniflux/v2/security/advisories/GHSA-wqv2-4wpg-8hc9","https://github.com/miniflux/v2/commit/76df99f3a3db234cf6b312be5e771485213d03c7"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1122583"],"patches":{"miniflux":[]},"tags":{},"packages":[{"name":"miniflux","source":"https://ubuntu.com/security/cve?package=miniflux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=miniflux","debian":"https://tracker.debian.org/pkg/miniflux","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-66004","published":"2025-12-11T00:00:00","updated_at":"2025-12-15T14:19:22.584058+00:00","description":"\nA Path Traversal vulnerability in usbmuxd allows local users to escalate to\nthe service user.This issue affects usbmuxd: before\n3ded00c9985a5108cfc7591a309f9a23d57a8cba.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":5.7,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-66004","https://ubuntu.com/security/notices/USN-7929-1"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1122507","https://bugzilla.opensuse.org/show_bug.cgi?id=1254302","https://github.com/libimobiledevice/usbmuxd/issues/272"],"patches":{"usbmuxd":["upstream: https://github.com/libimobiledevice/usbmuxd/commit/3ded00c9985a5108cfc7591a309f9a23d57a8cba"]},"tags":{},"packages":[{"name":"usbmuxd","source":"https://ubuntu.com/security/cve?package=usbmuxd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=usbmuxd","debian":"https://tracker.debian.org/pkg/usbmuxd","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1.1.1-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1.1.1-5~exp3ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"released","description":"1.1.1-6ubuntu0.25.04.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"1.1.1-6ubuntu0.25.10.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1.1.1-6ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-7929-1"],"notices":[{"id":"USN-7929-1","title":"usbmuxd vulnerability","summary":"usbmuxd could be made to overwrite files.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2025-12-15T12:54:55.768005","description":"It was discovered that usbmuxd incorrectly handled certain paths received\nwith the SavePairRecord command. A local attacker could possibly use this\nissue to delete and write files named *.plist in arbitrary locations.","is_hidden":false,"release_packages":{"jammy":[{"name":"usbmuxd","version":"1.1.1-2ubuntu0.1","description":"USB multiplexor daemon for iPhone and iPod Touch devices","is_source":true},{"name":"usbmuxd","version":"1.1.1-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/usbmuxd","version_link":"https://launchpad.net/ubuntu/+source/usbmuxd/1.1.1-2ubuntu0.1","pocket":"security"}],"noble":[{"name":"usbmuxd","version":"1.1.1-5~exp3ubuntu2.1","description":"USB multiplexor daemon for iPhone and iPod Touch devices","is_source":true},{"name":"usbmuxd","version":"1.1.1-5~exp3ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/usbmuxd","version_link":"https://launchpad.net/ubuntu/+source/usbmuxd/1.1.1-5~exp3ubuntu2.1","pocket":"security"}],"plucky":[{"name":"usbmuxd","version":"1.1.1-6ubuntu0.25.04.1","description":"USB multiplexor daemon for iPhone and iPod Touch devices","is_source":true},{"name":"usbmuxd","version":"1.1.1-6ubuntu0.25.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/usbmuxd","version_link":"https://launchpad.net/ubuntu/+source/usbmuxd/1.1.1-6ubuntu0.25.04.1","pocket":"security"}],"questing":[{"name":"usbmuxd","version":"1.1.1-6ubuntu0.25.10.1","description":"USB multiplexor daemon for iPhone and iPod Touch devices","is_source":true},{"name":"usbmuxd","version":"1.1.1-6ubuntu0.25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/usbmuxd","version_link":"https://launchpad.net/ubuntu/+source/usbmuxd/1.1.1-6ubuntu0.25.10.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2025-66004"]}]},{"id":"CVE-2025-66628","published":"2025-12-10T22:16:00","updated_at":"2025-12-17T07:09:20.595644+00:00","description":"\nImageMagick is a software suite to create, edit, compose, or convert bitmap\nimages. In versions 7.1.2-9 and prior, the TIM (PSX TIM) image parser\ncontains a critical integer overflow vulnerability in its ReadTIMImage\nfunction (coders/tim.c). The code reads width and height (16-bit values)\nfrom the file header and calculates image_size = 2 * width * height without\nchecking for overflow. On 32-bit systems (or where size_t is 32-bit), this\ncalculation can overflow if width and height are large (e.g., 65535),\nwrapping around to a small value. This results in a small heap allocation\nvia AcquireQuantumMemory and later operations relying on the dimensions can\ntrigger an out of bounds read. This issue is fixed in version 7.1.2-10.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-66628","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6hjr-v6g4-3fm8","https://github.com/dlemstra/Magick.NET/commit/2dfa08e15cfd11016a79615994787b14f9048b1c"],"bugs":[""],"patches":{"imagemagick":[]},"tags":{},"packages":[{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"8:7.1.2.12+dfsg1-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.9.13-35, 7.1.2-10","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2024-58281","published":"2025-12-10T22:16:00","updated_at":"2026-08-17T18:49:22.143893+00:00","description":"\nDotclear 2.29 contains a remote code execution vulnerability that allows\nauthenticated attackers to upload malicious PHP files through the media\nupload functionality. Attackers can exploit the file upload process by\ncrafting a PHP shell with a command execution form to gain system access\nthrough the uploaded file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.7,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2024-58281","https://git.dotclear.org/explore/repos","https://github.com/dotclear/dotclear/archive/refs/heads/master.zip","https://www.exploit-db.com/exploits/52037","https://www.vulncheck.com/advisories/dotclear-remote-code-execution-via-authenticated-file-upload"],"bugs":[""],"patches":{"dotclear":[]},"tags":{},"packages":[{"name":"dotclear","source":"https://ubuntu.com/security/cve?package=dotclear","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dotclear","debian":"https://tracker.debian.org/pkg/dotclear","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-24857","published":"2025-12-10T21:16:00","updated_at":"2025-12-17T07:04:59.062466+00:00","description":"\nImproper access control for volatile memory containing boot code in\nUniversal Boot Loader (U-Boot) before 2017.11 and Qualcomm chips IPQ4019,\nIPQ5018, IPQ5322, IPQ6018, IPQ8064, IPQ8074, and IPQ9574 could allow an\nattacker to execute arbitrary code.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.6,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","attackVector":"PHYSICAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.6,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-24857","https://www.cisa.gov/news-events/ics-advisories/icsa-25-343-01"],"bugs":[""],"patches":{"boot":[]},"tags":{},"packages":[{"name":"boot","source":"https://ubuntu.com/security/cve?package=boot","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=boot","debian":"https://tracker.debian.org/pkg/boot","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-65807","published":"2025-12-10T16:16:00","updated_at":"2025-12-17T07:04:22.777075+00:00","description":"\nAn issue in sd command v1.0.0 and before allows attackers to escalate\nprivileges to root via a crafted command.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.4,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-65807","https://gist.github.com/faabbi/827f10e144fdd342e13a3dd838902e83","http://sd.com","https://github.com/chmln/sd"],"bugs":[""],"patches":{"rust-sd":[]},"tags":{},"packages":[{"name":"rust-sd","source":"https://ubuntu.com/security/cve?package=rust-sd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rust-sd","debian":"https://tracker.debian.org/pkg/rust-sd","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":17280,"limit":20,"total_results":79316}