Search CVE reports


Toggle filters

1031 – 1040 of 47986 results

Status is adjusted based on your filters.


CVE-2026-52295

Medium priority
Needs evaluation

FFmpeg before 9.0 has an out-of-bounds read because the copied extradata lacked required padding before GetBitContext-based access in libavformat/iamf_writer.c.

2 affected packages

ffmpeg, libav

Package 20.04 LTS
ffmpeg Needs evaluation
libav
Show less packages

CVE-2026-52023

Medium priority
Needs evaluation

An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the ims_registrar_pcscf module, specifically the pcscf_save_pending/save_pending path and security-agreement parsing...

1 affected package

kamailio

Package 20.04 LTS
kamailio Needs evaluation
Show less packages

CVE-2026-52022

Medium priority
Needs evaluation

An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the IMS P-CSCF registration handling components

1 affected package

kamailio

Package 20.04 LTS
kamailio Needs evaluation
Show less packages

CVE-2026-84270

Medium priority
Needs evaluation

A flaw was found in the MTP backend in gvfs. When reading a file from a mounted MTP device, do_read() in gvfsbackendmtp.c trusts the data length returned by the device without limiting it to the original size requested by the...

1 affected package

gvfs

Package 20.04 LTS
gvfs Needs evaluation
Show less packages

CVE-2026-84269

Medium priority
Needs evaluation

A flaw was found in the AFP backend in gvfs. When mounting a share, a malicious AFP server can cause the DSI read path to process a length that exceeds the size requested by the client. The function does not verify...

1 affected package

gvfs

Package 20.04 LTS
gvfs Needs evaluation
Show less packages

CVE-2026-84268

Medium priority
Needs evaluation

A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify...

1 affected package

gvfs

Package 20.04 LTS
gvfs Needs evaluation
Show less packages

CVE-2026-84267

Medium priority
Needs evaluation

A flaw was found in the SFTP backend in gvfs. When mounting a share, a malicious SFTP server can cause read_string() to allocate a buffer with a certain length but the function does not verify that the buffer is completely filled,...

1 affected package

gvfs

Package 20.04 LTS
gvfs Needs evaluation
Show less packages

CVE-2026-84233

Medium priority
Needs evaluation

A flaw was found in rpm. A local attacker could supply a specially crafted `.gem` filename containing RPM macro syntax. When a user or automated workflow invokes `rpmuncompress -x` on this file, the macro expansion occurs during...

1 affected package

rpm

Package 20.04 LTS
rpm Needs evaluation
Show less packages

CVE-2026-83619

Medium priority
Needs evaluation

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.7.0 until 0.8.15, the release-0.8.x parser in lib/sax.js trims captured end-tag names with the unanchored global...

1 affected package

node-xmldom

Package 20.04 LTS
node-xmldom Needs evaluation
Show less packages

CVE-2026-83618

Medium priority
Needs evaluation

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.10 until 0.9.12, the requireWellFormed: true serializer validates DocumentType.publicId and DocumentType.systemId...

1 affected package

node-xmldom

Package 20.04 LTS
node-xmldom Needs evaluation
Show less packages