Search CVE reports


Toggle filters

121 – 130 of 50831 results

Status is adjusted based on your filters.


CVE-2026-42765

Low priority
Not affected

Issue summary: When a partial-chain certificate verification is enabled together with OCSP response checking for the whole chain, a NULL dereference will happen if the verified chain does not have a self-signed...

5 affected packages

edk2, nodejs, openssl, openssl-fips, openssl1.0

Package 16.04 LTS
edk2
nodejs
openssl Not affected
openssl-fips
openssl1.0
Show less packages

CVE-2026-42764

Medium priority
Not affected

Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer dereference in the OpenSSL QUIC server with address validation disabled. Impact summary: NULL pointer dereference typically causes...

5 affected packages

edk2, nodejs, openssl, openssl-fips, openssl1.0

Package 16.04 LTS
edk2
nodejs
openssl Not affected
openssl-fips
openssl1.0
Show less packages

CVE-2026-42490

Medium priority
Needs evaluation

[Unknown description]

1 affected package

xen

Package 16.04 LTS
xen Needs evaluation
Show less packages

CVE-2026-42489

Medium priority
Needs evaluation

[Unknown description]

1 affected package

xen

Package 16.04 LTS
xen Needs evaluation
Show less packages

CVE-2026-42488

Medium priority
Needs evaluation

[Unknown description]

1 affected package

xen

Package 16.04 LTS
xen Needs evaluation
Show less packages

CVE-2026-42487

Medium priority
Needs evaluation

[Unknown description]

1 affected package

xen

Package 16.04 LTS
xen Needs evaluation
Show less packages

CVE-2026-35188

Medium priority
Not affected

Issue summary: A malicious server can exploit TLS OCSP stapling by delivering a crafted response through the status_request extension, triggering a double-free in the client's certificate verification path. Impact summary:...

5 affected packages

edk2, nodejs, openssl, openssl-fips, openssl1.0

Package 16.04 LTS
edk2
nodejs
openssl Not affected
openssl-fips
openssl1.0
Show less packages

CVE-2026-34183

Medium priority
Not affected

Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing PATH_CHALLENGE frames. Impact summary: A malicious remote peer can cause an unbounded memory allocation which...

5 affected packages

edk2, nodejs, openssl, openssl-fips, openssl1.0

Package 16.04 LTS
edk2
nodejs
openssl Not affected
openssl-fips
openssl1.0
Show less packages

CVE-2026-34182

Medium priority
Not affected

Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the cipher and tag length fields of AuthEnvelopedData containers, leading to various potential compromises. Impact...

5 affected packages

edk2, nodejs, openssl, openssl-fips, openssl1.0

Package 16.04 LTS
edk2
nodejs
openssl Not affected
openssl-fips
openssl1.0
Show less packages

CVE-2026-34181

Low priority
Not affected

Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files that use Password-Based Message Authentication Code 1 (PBMAC1) integrity mechanism allowing a certificate and private...

5 affected packages

edk2, nodejs, openssl, openssl-fips, openssl1.0

Package 16.04 LTS
edk2
nodejs
openssl Not affected
openssl-fips
openssl1.0
Show less packages