Search CVE reports


Toggle filters

671 – 680 of 42759 results

Status is adjusted based on your filters.


CVE-2026-19404

Medium priority
Needs evaluation

A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operations perform no authorization check, allowing an unauthenticated remote attacker to invoke them when...

1 affected package

389-ds-base

Package 24.04 LTS
389-ds-base Needs evaluation
Show less packages

CVE-2026-12570

Medium priority

Not in release

A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model files via the keras.models.load_model() function. The H5IOStore.__getitem__ method...

1 affected package

keras

Package 24.04 LTS
keras Not in release
Show less packages

CVE-2026-72522

Medium priority
Needs evaluation

libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.

23 affected packages

expat, apache2, apr-util, cmake, ghostscript...

Package 24.04 LTS
expat Needs evaluation
apache2 Not affected
apr-util Not affected
cmake Not affected
ghostscript Not affected
texlive-bin Not affected
xmlrpc-c Needs evaluation
vnc4 Not in release
wbxml2 Needs evaluation
swish-e Needs evaluation
insighttoolkit4 Not in release
cadaver Needs evaluation
gdcm Not affected
ayttm Not in release
cableswig Not in release
coin3 Not affected
matanza Ignored
tdom Needs evaluation
vtk Not in release
smart Not in release
firefox Not affected
thunderbird Not affected
libxmltok Needs evaluation
Show all 23 packages Show less packages

CVE-2026-19389

Medium priority
Needs evaluation

Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation...

1 affected package

gst-plugins-ugly1.0

Package 24.04 LTS
gst-plugins-ugly1.0 Needs evaluation
Show less packages

CVE-2026-19387

Medium priority
Needs evaluation

A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a...

1 affected package

gst-plugins-bad1.0

Package 24.04 LTS
gst-plugins-bad1.0 Needs evaluation
Show less packages

CVE-2026-16742

Medium priority
Fixed

systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user

1 affected package

systemd

Package 24.04 LTS
systemd Fixed
Show less packages

CVE-2026-15060

Medium priority
Not affected

When systemd-machined >= v259 (or v258 with a custom `polkit` policy that allows `register-machine` access) is running on a desktop system, an unprivileged user logged in a desktop graphical session can kill arbitrary processes,...

1 affected package

systemd

Package 24.04 LTS
systemd Not affected
Show less packages

CVE-2026-15059

Medium priority
Fixed

Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation.

1 affected package

systemd

Package 24.04 LTS
systemd Fixed
Show less packages

CVE-2026-12372

Medium priority
Needs evaluation

A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. The `nltk.pathsec.validate_network_url()` function, intended to prevent SSRF by rejecting internal network...

1 affected package

nltk

Package 24.04 LTS
nltk Needs evaluation
Show less packages

CVE-2026-15534

Medium priority
Needs evaluation

Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch. The regex engine's superlinear cache holds one bit per subject position...

1 affected package

perl

Package 24.04 LTS
perl Needs evaluation
Show less packages