Search CVE reports


Toggle filters

1081 – 1090 of 41031 results

Status is adjusted based on your filters.


CVE-2026-8696

Medium priority

Not in release

radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_pids_list() function within the GDB client core that allows remote attackers to cause a denial of service or potentially execute arbitrary code by sending malformed...

1 affected package

radare2

Package 22.04 LTS
radare2 Not in release
Show less packages

CVE-2026-8695

Medium priority

Not in release

radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_threads_list() function that allows remote attackers to trigger memory corruption by sending a valid qfThreadInfo response followed by a malformed qsThreadInfo...

1 affected package

radare2

Package 22.04 LTS
radare2 Not in release
Show less packages

CVE-2026-44699

Medium priority
Needs evaluation

LibJWT is a C JSON Web Token Library. From 3.0.0 to 3.3.2, libjwt accepts an RSA JWK that does not contain an alg parameter as the verification key for an HS256/HS384/HS512 token. In the OpenSSL backend, this causes...

2 affected packages

libjwt, libjwt3

Package 22.04 LTS
libjwt Needs evaluation
libjwt3 Not in release
Show less packages

CVE-2026-44310

Medium priority

Not in release

Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. From 0.4.0 to before 0.15.0, CertVerifier.Verify() in pkg/git/verifier.go unconditionally dereferences certs[0]...

1 affected package

gitsign

Package 22.04 LTS
gitsign Not in release
Show less packages

CVE-2026-44309

Medium priority

Not in release

Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. Prior to 0.16.0, gitsign verify and gitsign verify-tag re-encode commit/tag objects through go-git's EncodeWithoutSignature before...

1 affected package

gitsign

Package 22.04 LTS
gitsign Not in release
Show less packages

CVE-2026-45803

Medium priority
Needs evaluation

`gh` is GitHub’s official command line tool. From 1.6.0 to before 2.92.0, a security vulnerability has been identified in GitHub CLI that could allow terminal escape sequence injection when users view GitHub Actions workflow logs...

1 affected package

gh

Package 22.04 LTS
gh Needs evaluation
Show less packages

CVE-2026-8669

Medium priority
Needs evaluation

Imager versions through 1.030 for Perl allow a heap out of bounds (OOB) write on crafted multi-frame GIF files. Imager::File::GIF's i_readgif_multi_low allocates a single per-row buffer GifRow sized for the GIF's global screen...

1 affected package

libimager-perl

Package 22.04 LTS
libimager-perl Needs evaluation
Show less packages

CVE-2026-46483

Medium priority
Vulnerable

Vim is an open source, command line text editor. Prior to 9.2.0479, a command injection vulnerability exists in tar#Vimuntar() in runtime/autoload/tar.vim when decompressing .tgz archives on Unix-like systems. The function builds...

1 affected package

vim

Package 22.04 LTS
vim Vulnerable
Show less packages

CVE-2026-45736

Medium priority
Needs evaluation

ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument....

1 affected package

node-ws

Package 22.04 LTS
node-ws Needs evaluation
Show less packages

CVE-2026-34253

Medium priority
Needs evaluation

A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulnerability occurs in the remote control functionality when processing...

1 affected package

vorbis-tools

Package 22.04 LTS
vorbis-tools Needs evaluation
Show less packages