Search CVE reports


Toggle filters

811 – 820 of 38218 results

Status is adjusted based on your filters.


CVE-2025-69647

Medium priority
Needs evaluation

GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same...

1 affected package

binutils

Package 20.04 LTS
binutils Needs evaluation
Show less packages

CVE-2026-3731

Medium priority
Fixed

A weakness has been identified in libssh up to 0.11.3. The impacted element is the function sftp_extensions_get_name/sftp_extensions_get_data of the file src/sftp.c of the component SFTP Extension Name Handler. Executing...

1 affected package

libssh

Package 20.04 LTS
libssh Fixed
Show less packages

CVE-2026-3713

Medium priority
Not affected

A flaw has been found in pnggroup libpng up to 1.6.55. Affected by this vulnerability is the function do_pnm2png of the file contrib/pngminus/pnm2png.c of the component pnm2png. This manipulation of the argument width/height...

5 affected packages

libpng, libpng1.6, firefox, thunderbird, chromium-browser

Package 20.04 LTS
libpng
libpng1.6 Not affected
firefox
thunderbird
chromium-browser
Show less packages

CVE-2026-3706

Medium priority
Needs evaluation

A vulnerability was determined in mkj Dropbear up to 2025.89. Impacted is the function unpackneg of the file src/curve25519.c of the component S Range Check. This manipulation causes improper verification of cryptographic...

1 affected package

dropbear

Package 20.04 LTS
dropbear Needs evaluation
Show less packages

CVE-2026-30838

Medium priority
Needs evaluation

league/commonmark is a PHP Markdown parser. Prior to version 2.8.1, the DisallowedRawHtml extension can be bypassed by inserting a newline, tab, or other ASCII whitespace character between a disallowed HTML tag name and...

1 affected package

php-league-commonmark

Package 20.04 LTS
php-league-commonmark Needs evaluation
Show less packages

CVE-2026-29786

Medium priority
Needs evaluation

node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the extraction directory by using a drive-relative link target such as C:../target.txt, which...

1 affected package

node-tar

Package 20.04 LTS
node-tar Needs evaluation
Show less packages

CVE-2026-24308

Medium priority
Needs evaluation

Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an attacker to expose sensitive information stored in client configuration in the client's logfile. Configuration...

1 affected package

zookeeper

Package 20.04 LTS
zookeeper Needs evaluation
Show less packages

CVE-2026-24281

Medium priority
Needs evaluation

Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control or spoof PTR records to impersonate ZooKeeper servers or clients with a valid...

1 affected package

zookeeper

Package 20.04 LTS
zookeeper Needs evaluation
Show less packages

CVE-2026-2219

Medium priority
Needs evaluation

It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream when uncompressing a zstd-compressed .deb archive, which may result in denial of...

1 affected package

dpkg

Package 20.04 LTS
dpkg Needs evaluation
Show less packages

CVE-2026-29063

Medium priority
Needs evaluation

Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject()...

1 affected package

node-immutable

Package 20.04 LTS
node-immutable Needs evaluation
Show less packages