Search CVE reports


Toggle filters

2131 – 2140 of 45973 results

Status is adjusted based on your filters.


CVE-2026-75145

Medium priority
Needs evaluation

FFmpeg before commit b4c199c contains an incorrect integer narrowing conversion in the AV1 RTP packetizer (libavformat/rtpenc_av1.c). The OBU size is cast to long before comparison against the remaining frame size. On targets...

2 affected packages

ffmpeg, libav

Package 24.04 LTS
ffmpeg Needs evaluation
libav Not in release
Show less packages

CVE-2026-75144

Medium priority
Fixed

FFmpeg before commit 1cdeb3c contains a heap buffer overflow vulnerability in the VC-2/Dirac RTP packetizer (libavformat/rtpenc_vc2hq.c) that allows attackers to trigger memory corruption by supplying a crafted Dirac data unit....

2 affected packages

ffmpeg, libav

Package 24.04 LTS
ffmpeg Fixed
libav Not in release
Show less packages

CVE-2026-75143

Medium priority
Fixed

FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (libavformat/librist.c). librist_read() ignored its size argument and copied the full received payload length into the caller-provided...

2 affected packages

ffmpeg, libav

Package 24.04 LTS
ffmpeg Fixed
libav Not in release
Show less packages

CVE-2026-75142

Medium priority
Fixed

FFmpeg before commit 9d786e4 contains a stack buffer overflow in the MPEG-PS muxer (libavformat/mpegenc.c). When muxing input with more streams than the muxer's fixed-size stack buffer accommodates, the buffer is overflowed. A...

2 affected packages

ffmpeg, libav

Package 24.04 LTS
ffmpeg Fixed
libav Not in release
Show less packages

CVE-2026-75141

Medium priority
Fixed

FFmpeg before commit acf5d7c contains a heap buffer overflow in the hvcC box writer. When writing an HEVC configuration record with more NAL units of a single type than the count field can represent, the NAL unit count overflows,...

2 affected packages

ffmpeg, libav

Package 24.04 LTS
ffmpeg Fixed
libav Not in release
Show less packages

CVE-2026-19672

Medium priority
Needs evaluation

The tarfile module's tar and data extraction filters created directories outside the destination for members whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the...

11 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7...

Package 24.04 LTS
python2.7 Not in release
python3.4 Not in release
python3.5 Not in release
python3.6 Not in release
python3.7 Not in release
python3.8 Not in release
python3.9 Not in release
python3.10 Not in release
python3.11 Not in release
python3.12 Needs evaluation
python3.14 Not in release
Show all 11 packages Show less packages

CVE-2026-49289

Medium priority
Needs evaluation

The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. In 4.19.2 and 4.20.2, the library permits attacker-controlled XPath transforms while processing XML signatures in specially crafted SAML messages....

1 affected package

simplesamlphp

Package 24.04 LTS
simplesamlphp Needs evaluation
Show less packages

CVE-2026-49283

Medium priority
Needs evaluation

The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.19.3, 4.20.2, 5.0.6, and 6.2.1, the HTTPArtifact::receive() flow can treat an unsigned embedded SAML Response as...

1 affected package

simplesamlphp

Package 24.04 LTS
simplesamlphp Needs evaluation
Show less packages

CVE-2026-48711

Medium priority
Needs evaluation

SSHFS is a network filesystem client for connecting to SSH servers. From version 1.4 until 3.7.6, SSHFS accepts a bracketed mount source such as [-oProxyCommand=CMD]:/path and find_base_path() removes the brackets, leaving a host...

1 affected package

sshfs-fuse

Package 24.04 LTS
sshfs-fuse Needs evaluation
Show less packages

CVE-2026-47187

Medium priority
Needs evaluation

SSHFS is a network filesystem client for connecting to SSH servers. Prior to version 3.7.6, a rogue SFTP server can return absolute symlink targets or relative targets containing parent-directory components that SSHFS passes...

1 affected package

sshfs-fuse

Package 24.04 LTS
sshfs-fuse Needs evaluation
Show less packages