Search CVE reports


Toggle filters

61 – 70 of 38813 results

Status is adjusted based on your filters.


CVE-2026-93452

Medium priority
Needs evaluation

snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of the destination buffer. Attackers can supply incompressible data that exceeds the...

1 affected package

snappy-java

Package 26.04 LTS
snappy-java Needs evaluation
Show less packages

CVE-2026-93451

Medium priority
Needs evaluation

snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in typed Snappy.uncompress*Array methods that allocate output arrays by dividing uncompressed length by element size but pass the undivided length to native...

1 affected package

snappy-java

Package 26.04 LTS
snappy-java Needs evaluation
Show less packages

CVE-2026-93395

Medium priority
Needs evaluation

A missing lower-bound validation in the bson_new_from_buffer() function of libbson allows an integer underflow when processing BSON data with a zero-length prefix. The function reads a 32-bit document length from the input buffer...

1 affected package

mongo-c-driver

Package 26.04 LTS
mongo-c-driver Needs evaluation
Show less packages

CVE-2026-93394

Medium priority
Needs evaluation

A flaw in libmongoc's SCRAM authentication implementation caused the client to continue the authentication handshake and transmit the client proof even when a nonce mismatch was detected in the server's first message....

1 affected package

mongo-c-driver

Package 26.04 LTS
mongo-c-driver Needs evaluation
Show less packages

CVE-2026-93393

Medium priority
Needs evaluation

A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A remote endpoint that the client connects to can cause the driver to write uncontrolled data...

1 affected package

mongo-c-driver

Package 26.04 LTS
mongo-c-driver Needs evaluation
Show less packages

CVE-2026-93387

Medium priority
Not affected

Improper state validation in Skia in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

1 affected package

chromium-browser

Package 26.04 LTS
chromium-browser Not affected
Show less packages

CVE-2026-93386

Medium priority
Not affected

UI misrepresentation in WebAppInstalls in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

1 affected package

chromium-browser

Package 26.04 LTS
chromium-browser Not affected
Show less packages

CVE-2026-93385

Medium priority
Not affected

Information leak in Paint in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

1 affected package

chromium-browser

Package 26.04 LTS
chromium-browser Not affected
Show less packages

CVE-2026-93384

Medium priority
Not affected

Server-side request forgery in Omnibox in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic....

1 affected package

chromium-browser

Package 26.04 LTS
chromium-browser Not affected
Show less packages

CVE-2026-93383

Medium priority
Not affected

Information leak in Permissions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

1 affected package

chromium-browser

Package 26.04 LTS
chromium-browser Not affected
Show less packages