Search CVE reports


Toggle filters

11 – 20 of 42041 results

Status is adjusted based on your filters.


CVE-2026-71437

Medium priority

Not in release

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 11.5.0 until 11.16.1, Mermaid Architecture Diagrams are vulnerable to prototype pollution when a diagram defines...

1 affected package

node-mermaid

Package 24.04 LTS
node-mermaid Not in release
Show less packages

CVE-2026-71436

Medium priority

Not in release

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 10.6.0 until 10.9.8 and 11.16.1, Mermaid XY Charts are vulnerable to an infinite loop denial of service in the...

1 affected package

node-mermaid

Package 24.04 LTS
node-mermaid Not in release
Show less packages

CVE-2026-71430

Medium priority
Needs evaluation

node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.25.1, the WrappedRE2::Replace function built its replacement result and passed it to V8 using ToLocalChecked without checking for the empty...

1 affected package

node-re2

Package 24.04 LTS
node-re2 Needs evaluation
Show less packages

CVE-2026-70640

Medium priority

Not in release

llama.cpp builds b1886 through b7445 contain a race condition use-after-free vulnerability in the LLaMA-Android JNI wrapper where bench_1model() and free_1context() lack synchronization, allowing Thread A to operate on freed...

1 affected package

llama.cpp

Package 24.04 LTS
llama.cpp Not in release
Show less packages

CVE-2026-70639

Medium priority

Not in release

llama.cpp builds b1886 through b7445 contain a null pointer dereference vulnerability in the LLaMA-Android JNI wrapper where the bench_1model() function fails to validate the model context pointer before dereferencing it....

1 affected package

llama.cpp

Package 24.04 LTS
llama.cpp Not in release
Show less packages

CVE-2026-70638

Medium priority

Not in release

llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android JNI wrapper where the new_1batch() function multiplies sizeof(llama_seq_id) by an attacker-controlled n_seq_max parameter without...

1 affected package

llama.cpp

Package 24.04 LTS
llama.cpp Not in release
Show less packages

CVE-2026-70632

Medium priority
Needs evaluation

FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI...

2 affected packages

ffmpeg, libav

Package 24.04 LTS
ffmpeg Needs evaluation
libav Not in release
Show less packages

CVE-2026-70631

Medium priority
Needs evaluation

FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in the native TIFF decoder in libavcodec/tiff.c. An attacker who can cause FFmpeg to decode a crafted TIFF file...

2 affected packages

ffmpeg, libav

Package 24.04 LTS
ffmpeg Needs evaluation
libav Not in release
Show less packages

CVE-2026-70630

Medium priority
Needs evaluation

FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native Screenpresso decoder (libavcodec/screenpresso.c) that allows attackers to recover sensitive memory...

2 affected packages

ffmpeg, libav

Package 24.04 LTS
ffmpeg Needs evaluation
libav Not in release
Show less packages

CVE-2026-70629

Medium priority
Needs evaluation

FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native RSCC decoder (libavcodec/rscc.c) that allows attackers to disclose heap memory contents by supplying a...

2 affected packages

ffmpeg, libav

Package 24.04 LTS
ffmpeg Needs evaluation
libav Not in release
Show less packages