Search CVE reports


Toggle filters

1411 – 1420 of 51995 results

Status is adjusted based on your filters.


CVE-2026-90775

Medium priority

Not in release

PostGIS address_standardizer through 3.7.0 fails to validate the Weight parameter from caller-supplied rules tables before using it as an array index. Attackers can craft malicious rule rows with out-of-range Weight values to...

1 affected package

address-standardizer

Package 22.04 LTS
address-standardizer Not in release
Show less packages

CVE-2026-90773

Medium priority

Not in release

procs through 0.14.12 fails to sanitize escape sequences in process command lines before displaying them in the Command column. Local attackers can execute processes with malicious ANSI or OSC escape sequences in their command...

1 affected package

rust-procs

Package 22.04 LTS
rust-procs Not in release
Show less packages

CVE-2026-90678

Medium priority
Not affected

An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 3.5-dev1 through 3.5-dev5. Exploitation requires an HTTP/3 frontend: HAProxy must be built with QUIC support and configured with a QUIC bind listener, and the affected...

1 affected package

haproxy

Package 22.04 LTS
haproxy Not affected
Show less packages

CVE-2026-90648

Medium priority
Needs evaluation

wasm2c in WebAssembly wabt through 1.0.41 allows sandbox escape in some situations that primarily involve 32-bit platforms, aka a "table flip" attack. It does not check the return value of calloc()...

1 affected package

wabt

Package 22.04 LTS
wabt Needs evaluation
Show less packages

CVE-2026-90616

Medium priority
Needs evaluation

In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read and write access to files on the host, which can be escalated to arbitrary code execution on the host, a different vulnerability than CVE-2026-76925....

1 affected package

flatpak

Package 22.04 LTS
flatpak Needs evaluation
Show less packages

CVE-2026-90560

Medium priority

Not in release

zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds. Attackers can...

1 affected package

zstd-jni-java

Package 22.04 LTS
zstd-jni-java Not in release
Show less packages

CVE-2026-90558

Medium priority
Needs evaluation

sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit. Attackers can craft malicious SIP packets with oversized...

1 affected package

sngrep

Package 22.04 LTS
sngrep Needs evaluation
Show less packages

CVE-2026-90557

Medium priority
Needs evaluation

Freeciv versions 3.1.0 through 3.2.5 contain an out-of-bounds read vulnerability in sg_load_player_unit() when processing savegame files with invalid unit activity indices. An attacker can craft a malicious savegame file with an...

1 affected package

freeciv

Package 22.04 LTS
freeciv Needs evaluation
Show less packages

CVE-2026-90556

Medium priority
Needs evaluation

Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceeding the fixed array bound of 64 elements. Attackers can craft malicious savegame...

1 affected package

freeciv

Package 22.04 LTS
freeciv Needs evaluation
Show less packages

CVE-2026-90473

Medium priority
Needs evaluation

msgpack-java through 0.9.12 contains an integer overflow vulnerability in MessageUnpacker.skipValue() when processing MAP32 containers with large element counts. Attackers can supply a MAP32 element count at or above 0x40000000...

1 affected package

msgpack-java

Package 22.04 LTS
msgpack-java Needs evaluation
Show less packages