Search CVE reports


Toggle filters

1751 – 1760 of 45973 results

Status is adjusted based on your filters.


CVE-2026-75509

Medium priority

Not in release

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to version 1.7.3, JWTClaimsRegistry applies membership matching to list-valued iss and sub claims,...

1 affected package

joserfc

Package 24.04 LTS
joserfc Not in release
Show less packages

CVE-2026-71832

Medium priority
Needs evaluation

Aria2 version 1.37.0 and below is affected by a Divide By Zero issue in src/bittorrent_helper.cc, which allows a remote malicious user to cause a Denial of Service

1 affected package

aria2

Package 24.04 LTS
aria2 Needs evaluation
Show less packages

CVE-2026-78475

Medium priority
Needs evaluation

A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array (VLA) on the stack without proper bounds checking, causing an unbounded stack...

1 affected package

gimp

Package 24.04 LTS
gimp Needs evaluation
Show less packages

CVE-2026-78465

Medium priority
Needs evaluation

A flaw was found in the file-pcx plugin in GIMP, affecting 32-bit builds only. When processing a PCX image file, the plugin calculates memory allocation sizes based on the image dimensions and the number of color planes. If a...

1 affected package

gimp

Package 24.04 LTS
gimp Needs evaluation
Show less packages

CVE-2026-19685

Medium priority
Needs evaluation

NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private...

1 affected package

network-manager

Package 24.04 LTS
network-manager Needs evaluation
Show less packages

CVE-2026-65053

Medium priority

Not in release

Horde IMP's AppleDouble MIME viewer writes an attacker-controlled attachment name into an HTML status block without escaping it. In lib/Mime/Viewer/Appledouble.php, _IMPrender() obtains the name of the data part with...

1 affected package

php-horde-imp

Package 24.04 LTS
php-horde-imp Not in release
Show less packages

CVE-2026-78376

Medium priority
Vulnerable

A flaw was found in WebKitGTK. Processing malicious web content can cause a use-after-free issue due to improper memory handling and result in memory corruption.

5 affected packages

webkitgtk, webkit2gtk, qtwebkit-source, qtwebkit-opensource-src, wpewebkit

Package 24.04 LTS
webkitgtk Not in release
webkit2gtk Vulnerable
qtwebkit-source Not in release
qtwebkit-opensource-src Ignored
wpewebkit Not in release
Show less packages

CVE-2026-78367

Medium priority
Needs evaluation

A vulnerability was found in RPM's rpmbuild tarball processing. When processing a crafted source archive, the getTarSpec() function in tools/rpmbuild.cc passes an attacker-controlled tar archive member name to rpmExpand() as part...

1 affected package

rpm

Package 24.04 LTS
rpm Needs evaluation
Show less packages

CVE-2026-78323

Medium priority
Needs evaluation

A flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trust flags when validating CA certificates, allowing certificates present in the NSS database without TRUSTED_CA flags to be accepted...

1 affected package

jss

Package 24.04 LTS
jss Needs evaluation
Show less packages

CVE-2026-76172

Medium priority
Needs evaluation

fast-uri is a URI parser for Node.js. During parsing it runs a legacy decoding pass over the scheme component and never re-escapes the result, and serialization writes the scheme back out verbatim, unlike the host component which...

1 affected package

node-ajv

Package 24.04 LTS
node-ajv Needs evaluation
Show less packages