Search CVE reports


Toggle filters

41 – 50 of 47927 results

Status is adjusted based on your filters.


CVE-2026-94055

Medium priority
Needs evaluation

Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.

1 affected package

exim4

Package 24.04 LTS
exim4 Needs evaluation
Show less packages

CVE-2026-94054

Medium priority
Needs evaluation

Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.

1 affected package

exim4

Package 24.04 LTS
exim4 Needs evaluation
Show less packages

CVE-2026-93990

Medium priority
Needs evaluation

Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume...

23 affected packages

expat, apache2, apr-util, cmake, ghostscript...

Package 24.04 LTS
expat Needs evaluation
apache2 Not affected
apr-util Not affected
cmake Not affected
ghostscript Not affected
texlive-bin Not affected
xmlrpc-c Needs evaluation
vnc4 Not in release
wbxml2 Needs evaluation
swish-e Needs evaluation
insighttoolkit4 Not in release
cadaver Needs evaluation
gdcm Not affected
ayttm Not in release
cableswig Not in release
coin3 Not affected
matanza Ignored
tdom Needs evaluation
vtk Not in release
smart Not in release
firefox Not affected
thunderbird Not affected
libxmltok Needs evaluation
Show all 23 packages Show less packages

CVE-2026-93987

Medium priority
Needs evaluation

rclone versions 1.56.0 through 1.75.0 contain a path traversal vulnerability in the `rclone serve docker` volume plugin. newVolume() in cmd/serve/docker/volume.go computes a volume's mountpoint as filepath.Join(drv.root, name)...

1 affected package

rclone

Package 24.04 LTS
rclone Needs evaluation
Show less packages

CVE-2026-93986

Medium priority
Needs evaluation

rclone before 1.75.1 fails to confine names from server and third-party listing responses to the listed directory, allowing path traversal sequences in object names. Attackers can craft special names containing forward slashes and...

1 affected package

rclone

Package 24.04 LTS
rclone Needs evaluation
Show less packages

CVE-2026-93962

Medium priority
Needs evaluation

A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_malloc of the file src/modules/cdp/receiver.c of the component CDP Diameter Receiver. Executing a manipulation...

1 affected package

kamailio

Package 24.04 LTS
kamailio Needs evaluation
Show less packages

CVE-2026-93894

Medium priority
Needs evaluation

In Vinyl Cache before 9.0,2, workspace buffer overflow vulnerability was found in the .upper() and .lower() string type methods of VCL. This can be used as a remote denial of service (DoS) vector to make the child process segfault...

2 affected packages

varnish, vinyl-cache

Package 24.04 LTS
varnish Needs evaluation
vinyl-cache Not in release
Show less packages

CVE-2026-93854

Medium priority

Not in release

In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce object-level authorization on its update and delete operations (PUT /v2/leases/{lease_id} and DELETE /v2/leases/{lease_id}). The policy authorize() wrapper...

1 affected package

blazar

Package 24.04 LTS
blazar Not in release
Show less packages

CVE-2026-93852

Medium priority

Not in release

In OpenStack Blazar before 17.0.1, the V2 lease listing operation (GET /v2/leases) returns leases for every project without enforcing project scoping or an administrator-only policy. Any authenticated user with access to the...

1 affected package

blazar

Package 24.04 LTS
blazar Not in release
Show less packages

CVE-2026-93753

Medium priority
Needs evaluation

deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects. Attackers can supply malicious source objects in...

1 affected package

node-deepmerge

Package 24.04 LTS
node-deepmerge Needs evaluation
Show less packages