Search CVE reports


Toggle filters

1041 – 1050 of 43788 results

Status is adjusted based on your filters.


CVE-2026-73515

Medium priority
Needs evaluation

PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure or a server crash by supplying a malformed FlatGeobuf buffer. The FlatGeobuf property metadata...

1 affected package

postgis

Package 24.04 LTS
postgis Needs evaluation
Show less packages

CVE-2026-19487

Medium priority
Needs evaluation

Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass. The prescan walks the subject for positions where the full...

1 affected package

perl

Package 24.04 LTS
perl Needs evaluation
Show less packages

CVE-2026-73508

Medium priority
Needs evaluation

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.dns.AbstractDnsRecord, io.netty.handler.codec.dns.DefaultDnsRecordDecoder.decodeRecord(),...

1 affected package

netty

Package 24.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-73507

Medium priority
Needs evaluation

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.xml.XmlFrameDecoder.decode() failed to preserve closing-tag parser state across invocations, so...

1 affected package

netty

Package 24.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-14456

Medium priority
Not affected

Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit. Impact...

5 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2

Package 24.04 LTS
openssl Not affected
openssl-fips Not in release
openssl1.0 Not in release
nodejs Not affected
edk2 Not affected
Show less packages

CVE-2026-67986

Medium priority

Not in release

amazing-print/amazing_print at commit dc890dfafdf07088ea901df53c19c2710e5c5234 contains a Ruby code injection condition in AwesomeMethodArray#grep. A specially named method containing Ruby interpolation syntax can be interpolated...

1 affected package

ruby-amazing-print

Package 24.04 LTS
ruby-amazing-print Not in release
Show less packages

CVE-2026-48702

Medium priority

Not in release

Rekor is a software supply chain transparency log. Starting in version 0.3.0 and prior to version 1.5.2, the `Package.Unmarshal()` function in `pkg/types/alpine/apk.go` decompresses the signature and control gzip members of an APK...

1 affected package

rekor

Package 24.04 LTS
rekor Not in release
Show less packages

CVE-2026-73585

Medium priority
Needs evaluation

A flaw was found in sblim-cmpi-base. Insecure temporary file creation in the provider registration scripts allows a local unprivileged user to perform a symlink attack. By creating a symlink in a world-writable directory, an...

1 affected package

sblim-cmpi-base

Package 24.04 LTS
sblim-cmpi-base Needs evaluation
Show less packages

CVE-2026-73584

Medium priority
Needs evaluation

A flaw was found in sblim-sfcb. A local, low-privileged attacker can exploit a race condition during privileged instance migration by manipulating a temporary file in the `/tmp` directory. By repeatedly recreating a symbolic link,...

1 affected package

sblim-sfcb

Package 24.04 LTS
sblim-sfcb Needs evaluation
Show less packages

CVE-2026-73583

Medium priority
Needs evaluation

A flaw was found in sblim-sfcb. A local attacker with access to the system can exploit an unsafe deserialization vulnerability in the provider-manager's inter-process communication (IPC) message parsing. By sending a specially...

1 affected package

sblim-sfcb

Package 24.04 LTS
sblim-sfcb Needs evaluation
Show less packages