Search CVE reports


Toggle filters

2121 – 2130 of 45973 results

Status is adjusted based on your filters.


CVE-2026-68555

Medium priority
Needs evaluation

Coturn is a free open source implementation of TURN and STUN Server. In 4.15.0, an authenticated TURN user can repeatedly resume one allocation from fresh UDP 5-tuples without completing a handoff when the server enables...

1 affected package

coturn

Package 24.04 LTS
coturn Needs evaluation
Show less packages

CVE-2026-68554

Medium priority
Needs evaluation

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, an on-path attacker can append attributes after MESSAGE-INTEGRITY to an authenticated STUN request on plain UDP or TCP, adjust the STUN header...

1 affected package

coturn

Package 24.04 LTS
coturn Needs evaluation
Show less packages

CVE-2026-68553

Medium priority
Needs evaluation

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, an authenticated TURN user can place printf-style format specifiers in the STUN USERNAME or REALM attribute, which passes is_secure_string()...

1 affected package

coturn

Package 24.04 LTS
coturn Needs evaluation
Show less packages

CVE-2026-68552

Medium priority
Needs evaluation

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, an unauthenticated remote client can send a STUN message over TCP or TLS with a body-length field from 65520 through 65532, causing the uint16_t...

1 affected package

coturn

Package 24.04 LTS
coturn Needs evaluation
Show less packages

CVE-2026-63652

Medium priority

Some fixes available 1 of 2

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, rdpsnd_server_recv_formats in channels/rdpsnd/server/rdpsnd_main.c frees context->client_formats on a malformed Client Audio Formats PDU without...

3 affected packages

freerdp, freerdp2, freerdp3

Package 24.04 LTS
freerdp Not in release
freerdp2 Needs evaluation
freerdp3 Fixed
Show less packages

CVE-2026-63633

Medium priority

Some fixes available 1 of 2

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, freerdp_dsp_decode_opus in libfreerdp/codec/dsp.c calls Stream_EnsureRemainingCapacity on context->common.buffer even though opus_decode writes...

3 affected packages

freerdp, freerdp2, freerdp3

Package 24.04 LTS
freerdp Not in release
freerdp2 Needs evaluation
freerdp3 Fixed
Show less packages

CVE-2026-63117

Medium priority

Some fixes available 1 of 2

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, an authenticated RDP client can advertise DVI ADPCM with nBlockAlign equal to 8 and nChannels equal to 2 to make the `bs` calculation in...

3 affected packages

freerdp, freerdp2, freerdp3

Package 24.04 LTS
freerdp Not in release
freerdp2 Needs evaluation
freerdp3 Fixed
Show less packages

CVE-2026-17183

Medium priority

Not in release

An authenticated user with permission to create or edit alert rules can bypass datasource query authorization by marking an alert rule query as a server-side expression while referencing a real datasource UID...

1 affected package

grafana

Package 24.04 LTS
grafana Not in release
Show less packages

CVE-2026-75147

Medium priority
Needs evaluation

FFmpeg before commit 983dae9 contains an out-of-bounds read in the AV1 RTP packetizer (libavformat/rtpenc_av1.c). The keyframe detection loop that searches for a sequence header OBU advanced its pointer and remaining-size counter...

2 affected packages

ffmpeg, libav

Package 24.04 LTS
ffmpeg Needs evaluation
libav Not in release
Show less packages

CVE-2026-75146

Medium priority
Fixed

FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec.c). When a live DASH manifest is refreshed with a startNumber that is lower than the previous value, the current sequence number...

2 affected packages

ffmpeg, libav

Package 24.04 LTS
ffmpeg Fixed
libav Not in release
Show less packages