Search CVE reports


Toggle filters

411 – 420 of 37368 results

Status is adjusted based on your filters.


CVE-2026-3260

Medium priority
Needs evaluation

A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending an HTTP GET request containing multipart/form-data content. If the underlying application processes parameters using methods like...

1 affected package

undertow

Package 22.04 LTS
undertow Needs evaluation
Show less packages

CVE-2026-4739

Medium priority
Needs evaluation

Integer Overflow or Wraparound vulnerability in InsightSoftwareConsortium ITK (‎Modules/ThirdParty/Expat/src/expat modules).This issue affects ITK: before 2.7.1.

23 affected packages

smart, expat, apache2, apr-util, cmake...

Package 22.04 LTS
smart Not in release
expat Needs evaluation
apache2 Not affected
apr-util Not affected
cmake Not affected
ghostscript Not affected
texlive-bin Not affected
xmlrpc-c Needs evaluation
vnc4 Not in release
wbxml2 Needs evaluation
swish-e Needs evaluation
insighttoolkit4 Needs evaluation
cadaver Needs evaluation
gdcm Not affected
ayttm Not in release
cableswig Not in release
coin3 Not affected
matanza Ignored
tdom Needs evaluation
vtk Not in release
firefox Not affected
thunderbird Not affected
libxmltok Needs evaluation
Show all 23 packages Show less packages

CVE-2026-4738

Medium priority
Needs evaluation

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in OSGeo gdal (frmts/zlib/contrib/infback9 modules). This vulnerability is associated with program files inftree9.C‎. This issue affects gdal:...

1 affected package

gdal

Package 22.04 LTS
gdal Needs evaluation
Show less packages

CVE-2026-33308

Medium priority
Needs evaluation

Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. Prior to version 0.13.0, code for client certificate verification did not check the key purpose as set in the Extended Key Usage extension. An attacker with access to...

1 affected package

mod-gnutls

Package 22.04 LTS
mod-gnutls Needs evaluation
Show less packages

CVE-2026-33307

Medium priority
Needs evaluation

Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. In versions prior to 0.12.3 and 0.13.0, code for client certificate verification imported the certificate chain sent by the client into a fixed size `gnutls_x509_crt_t...

1 affected package

mod-gnutls

Package 22.04 LTS
mod-gnutls Needs evaluation
Show less packages

CVE-2026-33320

Medium priority

Not in release

Dasel is a command-line tool and library for querying, modifying, and transforming data structures. Starting in version 3.0.0 and prior to version 3.3.1, Dasel's YAML reader allows an attacker who can supply YAML for processing to...

1 affected package

dasel

Package 22.04 LTS
dasel Not in release
Show less packages

CVE-2026-33306

Medium priority

Not in release

bcrypt-ruby is a Ruby binding for the OpenBSD bcrypt() password hashing algorithm. Prior to version 3.1.22, an integer overflow in the Java BCrypt implementation for JRuby can cause zero iterations in the strengthening loop. ...

1 affected package

bcrypt

Package 22.04 LTS
bcrypt Not in release
Show less packages

CVE-2026-33298

Medium priority

Not in release

llama.cpp is an inference of several LLM models in C/C++. Prior to b7824, an integer overflow vulnerability in the `ggml_nbytes` function allows an attacker to bypass memory validation by crafting a GGUF file with specific tensor...

1 affected package

llama.cpp

Package 22.04 LTS
llama.cpp Not in release
Show less packages

CVE-2026-33250

Medium priority
Needs evaluation

Freeciv21 is a free open source, turn-based, empire-building strategy game. Versions prior to 3.1.1 crash with a stack overflow when receiving specially-crafted packets. A remote attacker can use this to take down any public...

1 affected package

freeciv

Package 22.04 LTS
freeciv Needs evaluation
Show less packages

CVE-2026-33202

Medium priority
Needs evaluation

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#delete_prefixed` passes blob keys directly to `Dir.glob` without...

1 affected package

rails

Package 22.04 LTS
rails Needs evaluation
Show less packages