Search CVE reports


Toggle filters

1 – 10 of 75 results


CVE-2025-46205

Medium priority
Needs evaluation

A heap-use-after free in the PdfTokenizer::ReadDictionary function of podofo v0.10.0 to v0.10.5 allows attackers to cause a Denial of Service (DoS) by supplying a crafted PDF file. NOTE: this is disputed by the Supplier because...

1 affected package

libpodofo

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpodofo Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-4953

Medium priority
Needs evaluation

A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman build is not discarded. This issue can lead to files created within the container appearing in the temporary...

2 affected packages

libpod, podman

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpod Not in release Needs evaluation Needs evaluation
podman Needs evaluation Not in release Not in release
Show less packages

CVE-2025-9566

Medium priority
Vulnerable

There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file...

2 affected packages

libpod, podman

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpod Not in release Vulnerable Not affected
podman Vulnerable Not in release Not in release
Show less packages

CVE-2025-9394

Medium priority
Needs evaluation

A flaw has been found in PoDoFo 1.1.0-dev. This issue affects the function PdfTokenizer::DetermineDataType of the file src/podofo/main/PdfTokenizer.cpp of the component PDF Dictionary Parser. Executing manipulation can lead to use...

1 affected package

libpodofo

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpodofo Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-3056

Medium priority
Needs evaluation

A flaw was found in Podman. This issue may allow an attacker to create a specially crafted container that, when configured to share the same IPC with at least one other container, can create a large number of IPC resources in...

1 affected package

libpod

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpod Not in release Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2023-31568

Medium priority
Ignored

Podofo v0.10.0 was discovered to contain a heap buffer overflow via the component PoDoFo::PdfEncryptRC4::PdfEncryptRC4.

1 affected package

libpodofo

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpodofo Not affected Not affected Not affected Not affected
Show less packages

CVE-2023-31567

Medium priority
Ignored

Podofo v0.10.0 was discovered to contain a heap buffer overflow via the component PoDoFo::PdfEncryptAESV3::PdfEncryptAESV3.

1 affected package

libpodofo

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpodofo Not affected Not affected Not affected Not affected
Show less packages

CVE-2023-31566

Medium priority
Ignored

Podofo v0.10.0 was discovered to contain a heap-use-after-free via the component PoDoFo::PdfEncrypt::IsMetadataEncrypted().

1 affected package

libpodofo

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpodofo Not affected Not affected Not affected Not affected
Show less packages

CVE-2023-31556

Medium priority
Ignored

podofoinfo 0.10.0 was discovered to contain a segmentation violation via the function PoDoFo::PdfDictionary::findKeyParent.

1 affected package

libpodofo

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpodofo Not affected Not affected Not affected Not affected
Show less packages

CVE-2023-31555

Medium priority
Ignored

podofoinfo 0.10.0 was discovered to contain a segmentation violation via the function PoDoFo::PdfObject::DelayedLoad.

1 affected package

libpodofo

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpodofo Not affected Not affected Not affected Not affected
Show less packages