Search CVE reports


Toggle filters

1071 – 1080 of 45918 results

Status is adjusted based on your filters.


CVE-2026-38344

Medium priority
Needs evaluation

A NULL pointer dereference in the get_min_buffer_size function (/libswscale/slice.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted video file.

2 affected packages

ffmpeg, libav

Package 24.04 LTS
ffmpeg Needs evaluation
libav Not in release
Show less packages

CVE-2026-38343

Medium priority
Needs evaluation

An integer overflow in the libavfilter/vf_scale.c component of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted video file.

2 affected packages

ffmpeg, libav

Package 24.04 LTS
ffmpeg Needs evaluation
libav Not in release
Show less packages

CVE-2025-30156

Medium priority
Needs evaluation

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the CephX authentication protocol encrypts tickets with AES-128-CBC in an unauthenticated mode...

1 affected package

ceph

Package 24.04 LTS
ceph Needs evaluation
Show less packages

CVE-2026-73209

Medium priority
Needs evaluation

An attacker that has valid credentials can send crafted compressed data that causes the affected process to exhaust its stack and crash. The affected process is terminated, which can cause degradation or denial of service for...

1 affected package

dovecot

Package 24.04 LTS
dovecot Needs evaluation
Show less packages

CVE-2026-73208

Medium priority
Needs evaluation

An attacker that holds a token intended for a different purpose can authenticate, because when an OAuth2 token response does not contain a scope claim, the audience claim is used in its place and checked against the configured...

1 affected package

dovecot

Package 24.04 LTS
dovecot Needs evaluation
Show less packages

CVE-2026-52687

Medium priority
Needs evaluation

An attacker that has valid credentials can select a compression algorithm for the IMAP connection whose decompression state requires a large amount of memory, and open several such connections. The memory limit of the process is...

1 affected package

dovecot

Package 24.04 LTS
dovecot Needs evaluation
Show less packages

CVE-2026-52681

Medium priority
Needs evaluation

Sieve CPU resource usage is tracked in the compiled script, so an attacker that has valid credentials can reset the accounting by repeatedly changing the active script. Compiled script files are also not removed when a script is...

1 affected package

dovecot

Package 24.04 LTS
dovecot Needs evaluation
Show less packages

CVE-2026-42395

Medium priority
Needs evaluation

A host listed as a trusted proxy can send forwarding information containing a NUL byte, which crashes the login process on the following login attempt. The login process is terminated, which can cause degradation or denial...

1 affected package

dovecot

Package 24.04 LTS
dovecot Needs evaluation
Show less packages

CVE-2026-42393

Medium priority
Needs evaluation

The comparison used for the doveadm password and API key is not fully timing safe and can reveal the length of the configured secret. An attacker with access to the same network as the doveadm service, able to make repeated...

1 affected package

dovecot

Package 24.04 LTS
dovecot Needs evaluation
Show less packages

CVE-2026-42392

Medium priority
Needs evaluation

An attacker that has valid credentials can send an invalid IMAP URLFETCH command, which causes uninitialized memory to be included in the error response returned to the client. Process memory contents can be disclosed to the...

1 affected package

dovecot

Package 24.04 LTS
dovecot Needs evaluation
Show less packages