Search CVE reports


Toggle filters

271 – 280 of 38012 results

Status is adjusted based on your filters.


CVE-2026-3608

Medium priority
Needs evaluation

Sending a maliciously crafted message to the kea-ctrl-agent, kea-dhcp-ddns, kea-dhcp4, or kea-dhcp6 daemons over any configured API socket or HA listener can cause the receiving daemon to exit with a stack overflow error. This...

1 affected package

isc-kea

Package 20.04 LTS
isc-kea Needs evaluation
Show less packages

CVE-2026-3591

Medium priority
Needs evaluation

A use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0). Using a specially-crafted DNS request, an attacker may be able to cause an ACL to improperly (mis)match an IP address. In...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 20.04 LTS
bind9 Not affected
isc-dhcp Not affected
bind9-libs Needs evaluation
Show less packages

CVE-2026-3119

Medium priority
Needs evaluation

Under certain conditions, `named` may crash when processing a correctly signed query containing a TKEY record. The affected code can only be reached if an incoming request has a valid transaction signature (TSIG) from a key...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 20.04 LTS
bind9 Not affected
isc-dhcp Not affected
bind9-libs Needs evaluation
Show less packages

CVE-2026-3104

Medium priority
Needs evaluation

A specially crafted domain can be used to cause a memory leak in a BIND resolver simply by querying this domain. This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 20.04 LTS
bind9 Not affected
isc-dhcp Not affected
bind9-libs Needs evaluation
Show less packages

CVE-2026-1519

Medium priority
Needs evaluation

If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-only servers are generally unaffected, although there are circumstances where...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 20.04 LTS
bind9 Needs evaluation
isc-dhcp Not affected
bind9-libs Needs evaluation
Show less packages

CVE-2026-4371

Medium priority
Ignored

A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser...

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 20.04 LTS
firefox
thunderbird
mozjs38
mozjs52 Ignored
mozjs68 Ignored
mozjs78
mozjs91
mozjs102
mozjs115
Show all 9 packages Show less packages

CVE-2026-3889

Medium priority
Ignored

Spoofing issue in Thunderbird. This vulnerability affects Thunderbird < 149 and Thunderbird < 140.9.

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 20.04 LTS
firefox
thunderbird
mozjs38
mozjs52 Ignored
mozjs68 Ignored
mozjs78
mozjs91
mozjs102
mozjs115
Show all 9 packages Show less packages

CVE-2026-33412

Medium priority
Needs evaluation

Vim is an open source, command line text editor. Prior to version 9.2.0202, a command injection vulnerability exists in Vim's glob() function on Unix-like systems. By including a newline character (\n) in a pattern passed to...

1 affected package

vim

Package 20.04 LTS
vim Needs evaluation
Show less packages

CVE-2026-33347

Medium priority
Needs evaluation

league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in the Embed extension is vulnerable to an allowlist bypass due to a missing hostname boundary assertion in the...

1 affected package

php-league-commonmark

Package 20.04 LTS
php-league-commonmark Needs evaluation
Show less packages

CVE-2026-32854

Medium priority
Needs evaluation

LibVNCServer versions 0.9.15 and prior (fixed in commit dc78dee) contain null pointer dereference vulnerabilities in the HTTP proxy handlers within httpProcessInput() in httpd.c that allow remote attackers to cause a denial of...

6 affected packages

libvncserver, vino, x11vnc, veyon, italc, tightvnc

Package 20.04 LTS
libvncserver Needs evaluation
vino Needs evaluation
x11vnc Needs evaluation
veyon Needs evaluation
italc
tightvnc Needs evaluation
Show less packages