Search CVE reports


Toggle filters

11 – 20 of 47927 results

Status is adjusted based on your filters.


CVE-2026-89422

Medium priority
Needs evaluation

Key Exchange without Entity Authentication vulnerability in Erlang/OTP ssl allows a peer that answers a TLS 1.3 client connection to impersonate the intended server. A pre_shared_key extension in the ServerHello that the client...

1 affected package

erlang

Package 24.04 LTS
erlang Needs evaluation
Show less packages

CVE-2026-88807

Medium priority
Needs evaluation

A heap overflow in libXrender before 0.9.13 in RenderQueryPictFormats could be used by malicious X servers to inject code into attached X clients.

1 affected package

libxrender

Package 24.04 LTS
libxrender Needs evaluation
Show less packages

CVE-2026-88806

Medium priority
Needs evaluation

A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing the key_sym_map.

1 affected package

libx11

Package 24.04 LTS
libx11 Needs evaluation
Show less packages

CVE-2026-87082

Medium priority
Needs evaluation

Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return a wrong label via unvalidated malformed UTF-8 in encode_punycode. Neither backend checks that its input is well-formed UTF-8, so a string with the UTF-8 flag...

1 affected package

libnet-idn-encode-perl

Package 24.04 LTS
libnet-idn-encode-perl Needs evaluation
Show less packages

CVE-2026-87081

Medium priority
Needs evaluation

Net::IDN::UTS46 versions before 2.590 for Perl allow CPU exhaustion via quadratic punycode encoding of an overlong label before the length check in to_ascii. to_ascii punycode encodes each label and only then applies the 63-byte...

1 affected package

libnet-idn-encode-perl

Package 24.04 LTS
libnet-idn-encode-perl Needs evaluation
Show less packages

CVE-2026-87080

Medium priority
Needs evaluation

Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncated label to a name containing a character it never encoded in decode_punycode. The pure-Perl decoder reads one digit at a time with four-argument substr and...

1 affected package

libnet-idn-encode-perl

Package 24.04 LTS
libnet-idn-encode-perl Needs evaluation
Show less packages

CVE-2026-87079

Medium priority
Needs evaluation

Net::IDN::Punycode versions before 2.590 for Perl allow CPU exhaustion via quadratic insertion cost when decoding a long label in decode_punycode. The XS backend inserts each decoded code point into a UTF-8 buffer and finds the...

1 affected package

libnet-idn-encode-perl

Package 24.04 LTS
libnet-idn-encode-perl Needs evaluation
Show less packages

CVE-2026-87078

Medium priority
Needs evaluation

Net::IDN::Punycode versions from 2.302 before 2.590 for Perl leak the output buffer on every rejected label in decode_punycode. The XS backend allocates the scalar it returns before it validates the input, sizing the buffer at...

1 affected package

libnet-idn-encode-perl

Package 24.04 LTS
libnet-idn-encode-perl Needs evaluation
Show less packages

CVE-2026-84990

Medium priority
Needs evaluation

ntopng is a web-based network traffic monitoring application. Prior to 6.7.260718, scripts/lua/rest/v2/get/system/configurations/list_available_backups.lua and scripts/lua/rest/v2/get/system/configurations/download_backup.lua...

1 affected package

ntopng

Package 24.04 LTS
ntopng Needs evaluation
Show less packages

CVE-2026-83621

Medium priority
Needs evaluation

ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, POST /lua/rest/v2/edit/system/edit_blacklist.lua in scripts/lua/rest/v2/edit/system/edit_blacklist.lua lacks an administrator check and calls...

1 affected package

ntopng

Package 24.04 LTS
ntopng Needs evaluation
Show less packages