Search CVE reports


Toggle filters

2021 – 2030 of 45973 results

Status is adjusted based on your filters.


CVE-2026-77639

Medium priority
Needs evaluation

Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-stream detection threshold, to avoid the compression bomb check entirely. This is...

1 affected package

tor

Package 24.04 LTS
tor Needs evaluation
Show less packages

CVE-2026-77638

Medium priority
Needs evaluation

Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonate) the onion service that the client was trying to reach.

1 affected package

tor

Package 24.04 LTS
tor Needs evaluation
Show less packages

CVE-2026-77587

Medium priority
Needs evaluation

Tor before 0.4.9.11 is prone to a use-after-free (and potential double free) of a conflux object when a recovery leg revives a conflux set whose last linked leg has already been closed. A malicious exit node could use this to...

1 affected package

tor

Package 24.04 LTS
tor Needs evaluation
Show less packages

CVE-2026-77584

Medium priority
Needs evaluation

Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on a circuit which already has attached streams. A malicious client could send a RELAY_COMMAND_BEGIN before the CONFLUX_LINK on the same circuit, attaching an...

1 affected package

tor

Package 24.04 LTS
tor Needs evaluation
Show less packages

CVE-2026-77506

Medium priority
Needs evaluation

Znuny before LTS 6.5.22 allows AgentTicketEmailResend template XSS.

2 affected packages

znuny, otrs2

Package 24.04 LTS
znuny Needs evaluation
otrs2 Not in release
Show less packages

CVE-2026-76023

Medium priority
Not affected

Improper resource control in Linux Toolkit Theming in Google Chrome prior to 151.0.7922.173 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page....

1 affected package

chromium-browser

Package 24.04 LTS
chromium-browser Not affected
Show less packages

CVE-2026-76022

Medium priority
Not affected

Buffer overflow in Network in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

1 affected package

chromium-browser

Package 24.04 LTS
chromium-browser Not affected
Show less packages

CVE-2026-76021

Medium priority
Not affected

Use after free in DOM in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

1 affected package

chromium-browser

Package 24.04 LTS
chromium-browser Not affected
Show less packages

CVE-2026-76020

Medium priority
Not affected

Race condition in V8 in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

1 affected package

chromium-browser

Package 24.04 LTS
chromium-browser Not affected
Show less packages

CVE-2026-76019

Medium priority
Not affected

Incorrect authorization in Workers in Google Chrome prior to 151.0.7922.173 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page....

1 affected package

chromium-browser

Package 24.04 LTS
chromium-browser Not affected
Show less packages