Search CVE reports


Toggle filters

21 – 30 of 37995 results

Status is adjusted based on your filters.


CVE-2026-4923

Medium priority
Needs evaluation

Impact: When using multiple wildcards, combined with at least one parameter, a regular expression can be generated that is vulnerable to ReDoS. This backtracking vulnerability requires the second wildcard to be somewhere other...

1 affected package

node-path-to-regexp

Package 20.04 LTS
node-path-to-regexp Needs evaluation
Show less packages

CVE-2026-4897

Medium priority
Needs evaluation

A flaw was found in polkit. A local user can exploit this by providing a specially crafted, excessively long input to the `polkit-agent-helper-1` setuid binary via standard input (stdin). This unbounded input can lead to an...

1 affected package

policykit-1

Package 20.04 LTS
policykit-1 Needs evaluation
Show less packages

CVE-2026-4887

Medium priority
Needs evaluation

A flaw was found in GIMP. This issue is a heap buffer over-read in GIMP PCX file loader due to an off-by-one error. A remote attacker could exploit this by convincing a user to open a specially crafted PCX image....

1 affected package

gimp

Package 20.04 LTS
gimp Needs evaluation
Show less packages

CVE-2026-4867

Medium priority
Needs evaluation

Impact: A bad regular expression is generated any time you have three or more parameters within a single segment, separated by something that is not a period (.). For example, /:a-:b-:c or /:a-:b-:c-:d. The backtrack protection...

1 affected package

node-path-to-regexp

Package 20.04 LTS
node-path-to-regexp Needs evaluation
Show less packages

CVE-2026-3650

Medium priority
Needs evaluation

A memory leak exists in the Grassroots DICOM library (GDCM). The bug occurs when parsing malformed DICOM files with non-standard VR types in file meta information. The vulnerability leads to vast memory allocations and resource...

1 affected package

gdcm

Package 20.04 LTS
gdcm Needs evaluation
Show less packages

CVE-2026-34475

Medium priority
Needs evaluation

Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass.

1 affected package

varnish

Package 20.04 LTS
varnish Needs evaluation
Show less packages

CVE-2026-34353

Medium priority
Needs evaluation

In OCaml through 4.14.3, Bigarray.reshape allows an integer overflow, and resultant reading of arbitrary memory, when untrusted data is processed.

1 affected package

ocaml

Package 20.04 LTS
ocaml Needs evaluation
Show less packages

CVE-2026-34352

Medium priority
Needs evaluation

In TigerVNC before 1.16.2, Image.cxx in x0vncserver allows other users to observe or manipulate the screen contents, or cause an application crash, because of incorrect permissions.

1 affected package

tigervnc

Package 20.04 LTS
tigervnc Needs evaluation
Show less packages

CVE-2026-33996

Medium priority
Needs evaluation

LibJWT is a C JSON Web Token Library. Starting in version 3.0.0 and prior to version 3.3.0, the JWK parsing for RSA-PSS did not protect against a NULL value when expecting to parse JSON string values. A specially crafted JWK file...

2 affected packages

libjwt, libjwt3

Package 20.04 LTS
libjwt Needs evaluation
libjwt3
Show less packages

CVE-2026-33995

Medium priority
Needs evaluation

[double free in kerberos_AcceptSecurityContext and kerberos_IntitalizeSecurityContextA]

3 affected packages

freerdp, freerdp2, freerdp3

Package 20.04 LTS
freerdp
freerdp2 Needs evaluation
freerdp3
Show less packages