Search CVE reports


Toggle filters

2551 – 2560 of 26567 results

Status is adjusted based on your filters.


CVE-2026-3591

Medium priority
Needs evaluation

A use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0). Using a specially-crafted DNS request, an attacker may be able to cause an ACL to improperly (mis)match an IP address. In...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 26.04 LTS
bind9 Not affected
isc-dhcp Needs evaluation
bind9-libs Not in release
Show less packages

CVE-2026-3119

Medium priority
Needs evaluation

Under certain conditions, `named` may crash when processing a correctly signed query containing a TKEY record. The affected code can only be reached if an incoming request has a valid transaction signature (TSIG) from a key...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 26.04 LTS
bind9 Not affected
isc-dhcp Needs evaluation
bind9-libs Not in release
Show less packages

CVE-2026-3104

Medium priority
Needs evaluation

A specially crafted domain can be used to cause a memory leak in a BIND resolver simply by querying this domain. This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 26.04 LTS
bind9 Not affected
isc-dhcp Needs evaluation
bind9-libs Not in release
Show less packages

CVE-2026-1519

Medium priority
Needs evaluation

If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-only servers are generally unaffected, although there are circumstances where...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 26.04 LTS
bind9 Not affected
isc-dhcp Needs evaluation
bind9-libs Not in release
Show less packages

CVE-2026-4371

Medium priority
Not affected

A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser...

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 26.04 LTS
firefox Not affected
thunderbird Not affected
mozjs38 Not in release
mozjs52 Not in release
mozjs68 Not in release
mozjs78 Not in release
mozjs91 Not in release
mozjs102 Not in release
mozjs115 Not in release
Show all 9 packages Show less packages

CVE-2026-3889

Medium priority
Not affected

Spoofing issue in Thunderbird. This vulnerability was fixed in Thunderbird 149 and Thunderbird 140.9.

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 26.04 LTS
firefox Not affected
thunderbird Not affected
mozjs38 Not in release
mozjs52 Not in release
mozjs68 Not in release
mozjs78 Not in release
mozjs91 Not in release
mozjs102 Not in release
mozjs115 Not in release
Show all 9 packages Show less packages

CVE-2026-33215

Medium priority
Needs evaluation

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The nats-server provides an MQTT client interface. Prior to versions 2.11.15 and 2.12.5, Sessions and Messages can by hijacked via...

1 affected package

nats-server

Package 26.04 LTS
nats-server Needs evaluation
Show less packages

CVE-2026-33349

Medium priority
Needs evaluation

fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From version 4.0.0-beta.3 to before version 5.5.7, the DocTypeReader in fast-xml-parser uses JavaScript truthy checks to...

1 affected package

node-webfont

Package 26.04 LTS
node-webfont Needs evaluation
Show less packages

CVE-2026-33347

Medium priority
Vulnerable

league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in the Embed extension is vulnerable to an allowlist bypass due to a missing hostname boundary assertion in the...

1 affected package

php-league-commonmark

Package 26.04 LTS
php-league-commonmark Vulnerable
Show less packages

CVE-2026-23924

Medium priority
Needs evaluation

Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding them to the Docker daemon. An attacker capable of invoking Agent 2 can read arbitrary files from running Docker...

1 affected package

zabbix

Package 26.04 LTS
zabbix Needs evaluation
Show less packages