Search CVE reports


Toggle filters

1741 – 1750 of 43788 results

Status is adjusted based on your filters.


CVE-2026-71557

Medium priority
Needs evaluation

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, reference names are not sanitized before being used to construct on-disk paths under the reference storage directory, so a...

2 affected packages

golang-github-go-git-go-git, golang-github-go-git-go-git-v6

Package 24.04 LTS
golang-github-go-git-go-git Needs evaluation
golang-github-go-git-go-git-v6 Not in release
Show less packages

CVE-2026-71556

Medium priority
Needs evaluation

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, status, and add) resolve symbolic links inside the working tree without confining...

2 affected packages

golang-github-go-git-go-git, golang-github-go-git-go-git-v6

Package 24.04 LTS
golang-github-go-git-go-git Needs evaluation
golang-github-go-git-go-git-v6 Not in release
Show less packages

CVE-2026-20348

Medium priority
Needs evaluation

A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This...

1 affected package

clamav

Package 24.04 LTS
clamav Needs evaluation
Show less packages

CVE-2026-20347

Medium priority
Needs evaluation

A vulnerability in the Mach-O file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an...

1 affected package

clamav

Package 24.04 LTS
clamav Needs evaluation
Show less packages

CVE-2026-20346

Medium priority
Needs evaluation

A vulnerability in the PDF file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This...

1 affected package

clamav

Package 24.04 LTS
clamav Needs evaluation
Show less packages

CVE-2026-20345

Medium priority
Needs evaluation

A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This...

1 affected package

clamav

Package 24.04 LTS
clamav Needs evaluation
Show less packages

CVE-2026-20339

Medium priority
Needs evaluation

A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an...

1 affected package

clamav

Package 24.04 LTS
clamav Needs evaluation
Show less packages

CVE-2026-20338

Medium priority
Needs evaluation

A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper memory handling when processing content in...

1 affected package

clamav

Package 24.04 LTS
clamav Needs evaluation
Show less packages

CVE-2026-20337

Medium priority
Needs evaluation

A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper boundary checks for content in zip files...

1 affected package

clamav

Package 24.04 LTS
clamav Needs evaluation
Show less packages

CVE-2026-62996

Medium priority
Needs evaluation

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. From 5.0.0 until 5.8.4, Smarty's stream: resource-name handling does not adequately restrict which PHP stream...

2 affected packages

smarty3, smarty4

Package 24.04 LTS
smarty3 Needs evaluation
smarty4 Needs evaluation
Show less packages