Search CVE reports


Toggle filters

2151 – 2160 of 45973 results

Status is adjusted based on your filters.


CVE-2026-76235

Medium priority
Needs evaluation

A memory leak flaw was found in cockpit-ws. The login page handler leaks a heap allocation on every unauthenticated request that carries a CockpitLang cookie, allowing a remote unauthenticated attacker to exhaust memory on...

1 affected package

cockpit

Package 24.04 LTS
cockpit Needs evaluation
Show less packages

CVE-2026-75900

Medium priority
Needs evaluation

An out-of-bounds read vulnerability was found in swtpm's SWTPM_NVRAM_CheckHeader() function. The entry guard checks the buffer length against sizeof(bh), where bh is a pointer, instead of sizeof(*bh), the actual struct size. This...

1 affected package

swtpm

Package 24.04 LTS
swtpm Needs evaluation
Show less packages

CVE-2026-75589

Medium priority
Needs evaluation

Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with a non-constant-time comparison in verify. Each of the three compares the signature carried in the message against the locally...

1 affected package

libnet-oauth-perl

Package 24.04 LTS
libnet-oauth-perl Needs evaluation
Show less packages

CVE-2026-72889

Medium priority
Needs evaluation

Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verify. verify resolves the signature method class from the signature_method parameter of the incoming message. signature_method is...

1 affected package

libnet-oauth-perl

Package 24.04 LTS
libnet-oauth-perl Needs evaluation
Show less packages

CVE-2026-76014

Medium priority
Needs evaluation

A vulnerability has been found in BusyBox up to 1.30.1. This vulnerability affects unknown code of the file networking/wget.c of the component FEATURE_WGET_TIMEOUT Handler. Such manipulation of the argument -T leads to null...

1 affected package

busybox

Package 24.04 LTS
busybox Needs evaluation
Show less packages

CVE-2026-73073

Medium priority
Fixed

Vim is an open source, command line text editor. Prior to 9.2.0845, StructMembers() in runtime/autoload/ccomplete.vim constructs and executes a vimgrep command using an insufficiently escaped typeref: or typename: value from a...

1 affected package

vim

Package 24.04 LTS
vim Fixed
Show less packages

CVE-2026-62377

Medium priority
Not affected

libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF sequence accepted by heif_context_read_from_memory() can leave the context with no registered sequence tracks and crash when...

1 affected package

libheif

Package 24.04 LTS
libheif Not affected
Show less packages

CVE-2026-52854

Medium priority
Needs evaluation

Maps is a MediaWiki extension that enables visualization of geographic data through dynamic embedded maps. Prior to version 12.1.3, the display_map parser function in the Leaflet service accepts attacker-controlled HTML in the...

1 affected package

mediawiki

Package 24.04 LTS
mediawiki Needs evaluation
Show less packages

CVE-2026-48796

Medium priority
Not affected

CefSharp provides .NET bindings for the Chromium Embedded Framework for Windows Forms and Windows Presentation Foundation applications. Prior to version 148.0.90, CefSharp/SchemeHandler/FolderSchemeHandlerFactory.cs...

1 affected package

chromium-browser

Package 24.04 LTS
chromium-browser Not affected
Show less packages

CVE-2026-76047

Medium priority
Not affected

Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

1 affected package

chromium-browser

Package 24.04 LTS
chromium-browser Not affected
Show less packages