Search CVE reports


Toggle filters

161 – 170 of 47851 results

Status is adjusted based on your filters.


CVE-2026-32597

Medium priority
Needs evaluation

PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 ยง4.1.11. When a JWS token contains a crit array listing extensions that PyJWT...

1 affected package

pyjwt

Package 16.04 LTS
pyjwt Needs evaluation
Show less packages

CVE-2026-32259

Medium priority
Needs evaluation

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-16 and 6.9.13-41, when a memory allocation fails in the sixel encoder it would be possible to write past the end of a...

1 affected package

imagemagick

Package 16.04 LTS
imagemagick Needs evaluation
Show less packages

CVE-2026-32249

Medium priority
Needs evaluation

Vim is an open source, command line text editor. From 9.1.0011 to before 9.2.0137, Vim's NFA regex compiler, when encountering a collection containing a combining character as the endpoint of a character range (e.g. [0-0\u05bb]),...

1 affected package

vim

Package 16.04 LTS
vim Needs evaluation
Show less packages

CVE-2026-32240

Medium priority
Needs evaluation

Cap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, when using Transfer-Encoding: chunked, if a chunk's size parsed to a value of 2^64 or larger, it would be truncated to a 64-bit integer. In...

1 affected package

capnproto

Package 16.04 LTS
capnproto Needs evaluation
Show less packages

CVE-2026-32239

Medium priority
Needs evaluation

Cap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, a negative Content-Length value was converted to unsigned, treating it as an impossibly large length instead. In theory, this bug could...

1 affected package

capnproto

Package 16.04 LTS
capnproto Needs evaluation
Show less packages

CVE-2025-70873

Medium priority
Not affected

An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.

2 affected packages

sqlite, sqlite3

Package 16.04 LTS
sqlite Not affected
sqlite3 Not affected
Show less packages

CVE-2025-13462

Medium priority
Needs evaluation

The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being...

12 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7...

Package 16.04 LTS
python2.7 Needs evaluation
python3.4
python3.5 Needs evaluation
python3.6
python3.7
python3.8
python3.9
python3.10
python3.11
python3.12
python3.13
python3.14
Show all 12 packages Show less packages

CVE-2026-3497

Medium priority
Not affected

Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patches added by various Linux distributions and does not affect the OpenSSH upstream project itself. The...

2 affected packages

openssh, openssh-ssh1

Package 16.04 LTS
openssh Not affected
openssh-ssh1
Show less packages

CVE-2026-3099

Low priority
Vulnerable

A flaw was found in Libsoup. The server-side digest authentication implementation in the SoupAuthDomainDigest class does not properly track issued nonces or enforce the required incrementing nonce-count (nc) attribute. This...

2 affected packages

libsoup2.4, libsoup3

Package 16.04 LTS
libsoup2.4 Vulnerable
libsoup3
Show less packages

CVE-2026-4016

Medium priority
Needs evaluation

A security vulnerability has been detected in GPAC 26.03-DEV. Affected by this vulnerability is the function svgin_process of the file src/filters/load_svg.c of the component SVG Parser. The manipulation leads to out-of-bounds...

1 affected package

gpac

Package 16.04 LTS
gpac Needs evaluation
Show less packages