Search CVE reports


Toggle filters

971 – 980 of 57535 results

Status is adjusted based on your filters.


CVE-2026-78043

Medium priority
Not affected

The Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via specially crafted paths

1 affected package

openvpn

Package 16.04 LTS
openvpn Not affected
Show less packages

CVE-2026-71197

Medium priority
Needs evaluation

[Unknown description]

1 affected package

glance

Package 16.04 LTS
glance Needs evaluation
Show less packages

CVE-2026-71196

Medium priority
Needs evaluation

[Unknown description]

1 affected package

glance

Package 16.04 LTS
glance Needs evaluation
Show less packages

CVE-2026-85458

Medium priority
Needs evaluation

Divide-by-zero in Xpdf 4.06 (and earlier), when a glyph in a Type 3 font has a zero height.

2 affected packages

xpdf, ipe

Package 16.04 LTS
xpdf Needs evaluation
ipe Needs evaluation
Show less packages

CVE-2026-84185

Medium priority
Needs evaluation

A flaw was found in the jwcrypto library, which is used for implementing Javascript Object Signing and Encryption (JOSE) standards. The issue occurs when the library verifies a General JSON Serialization JWS using a set of keys....

1 affected package

python-jwcrypto

Package 16.04 LTS
python-jwcrypto Needs evaluation
Show less packages

CVE-2026-85396

Medium priority
Needs evaluation

rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers can craft archive entries...

1 affected package

ruby-zip

Package 16.04 LTS
ruby-zip Needs evaluation
Show less packages

CVE-2026-33630

Medium priority
Needs evaluation

c-ares is an asynchronous resolver library. From ver 1.32.3 until 1.34.7, a use-after-free / double-free in c-ares' query-completion handling. The same flaw — a query's callback being invoked while the query is still linked in the...

1 affected package

c-ares

Package 16.04 LTS
c-ares Needs evaluation
Show less packages

CVE-2026-84968

Medium priority
Needs evaluation

An out-of-bounds read in the BSON decoding component of the MongoDB PHP driver may allow an unauthenticated party who supplies specially formed input to have a small amount of adjacent process memory copied into an error message...

1 affected package

php-mongodb

Package 16.04 LTS
php-mongodb Needs evaluation
Show less packages

CVE-2026-84989

Medium priority
Needs evaluation

ntopng is a web-based network traffic monitoring application. In versions 6.7.0 through 6.7.260717, two REST v2 endpoints that manage ntopng's tag/badge feature — `POST /lua/rest/v2/delete/tag/tag.lua` and...

1 affected package

ntopng

Package 16.04 LTS
ntopng Needs evaluation
Show less packages

CVE-2026-85150

Medium priority
Vulnerable

A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Authorization or WWW-Authenticate header that uses Digest authentication. Specially crafted whitespace...

1 affected package

gst-plugins-base1.0

Package 16.04 LTS
gst-plugins-base1.0 Vulnerable
Show less packages