Search CVE reports


Toggle filters

1981 – 1990 of 45973 results

Status is adjusted based on your filters.


CVE-2026-64728

Medium priority

Some fixes available 1 of 2

A permissions issue was addressed with improved validation. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Maliciously crafted web content may violate iframe...

5 affected packages

webkitgtk, webkit2gtk, qtwebkit-source, qtwebkit-opensource-src, wpewebkit

Package 24.04 LTS
webkitgtk Not in release
webkit2gtk Fixed
qtwebkit-source Not in release
qtwebkit-opensource-src Ignored
wpewebkit Not in release
Show less packages

CVE-2026-64719

Medium priority

Some fixes available 1 of 2

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6....

5 affected packages

webkitgtk, webkit2gtk, qtwebkit-source, qtwebkit-opensource-src, wpewebkit

Package 24.04 LTS
webkitgtk Not in release
webkit2gtk Fixed
qtwebkit-source Not in release
qtwebkit-opensource-src Ignored
wpewebkit Not in release
Show less packages

CVE-2026-64713

Medium priority

Some fixes available 1 of 2

This issue was addressed with improved checks. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Websites may know if the user has visited a given link.

5 affected packages

webkitgtk, webkit2gtk, qtwebkit-source, qtwebkit-opensource-src, wpewebkit

Package 24.04 LTS
webkitgtk Not in release
webkit2gtk Fixed
qtwebkit-source Not in release
qtwebkit-opensource-src Ignored
wpewebkit Not in release
Show less packages

CVE-2026-63385

Medium priority
Fixed

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has two HTTP parsing weaknesses in http.c. evhttp_decode_uri_internal decodes percent-encoded %00 bytes into literal NUL characters, which can...

1 affected package

libevent

Package 24.04 LTS
libevent Fixed
Show less packages

CVE-2026-63384

Medium priority
Fixed

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an incorrect integer conversion in event_tagging.c when evtag_unmarshal_header uses evtag_decode_int to decode an attacker-controlled uint32...

1 affected package

libevent

Package 24.04 LTS
libevent Fixed
Show less packages

CVE-2026-63383

Medium priority
Fixed

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent can read beyond a contiguous evbuffer region in event_tagging.c when decode_tag_internal requests at most five bytes from evbuffer_pullup but...

1 affected package

libevent

Package 24.04 LTS
libevent Fixed
Show less packages

CVE-2026-63382

Medium priority
Fixed

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, the libevent evhttp parser in http.c inconsistently handles duplicate Transfer-Encoding headers, comma-separated Transfer-Encoding values, and bare line...

1 affected package

libevent

Package 24.04 LTS
libevent Fixed
Show less packages

CVE-2026-63381

Medium priority
Fixed

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use-after-free in buffer.c when evbuffer_add_buffer_reference processes an output buffer whose out_total_len is zero....

1 affected package

libevent

Package 24.04 LTS
libevent Fixed
Show less packages

CVE-2026-43804

Medium priority

Some fixes available 1 of 2

This issue was addressed through improved state management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6. Visiting a website may lead to an app denial-of-service.

5 affected packages

webkitgtk, webkit2gtk, qtwebkit-source, qtwebkit-opensource-src, wpewebkit

Package 24.04 LTS
webkitgtk Not in release
webkit2gtk Fixed
qtwebkit-source Not in release
qtwebkit-opensource-src Ignored
wpewebkit Not in release
Show less packages

CVE-2026-43745

Medium priority

Some fixes available 1 of 2

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS...

5 affected packages

webkitgtk, webkit2gtk, qtwebkit-source, qtwebkit-opensource-src, wpewebkit

Package 24.04 LTS
webkitgtk Not in release
webkit2gtk Fixed
qtwebkit-source Not in release
qtwebkit-opensource-src Ignored
wpewebkit Not in release
Show less packages