Search CVE reports


Toggle filters

81 – 90 of 40097 results

Status is adjusted based on your filters.


CVE-2025-54518

Medium priority
Needs evaluation

Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a different privilege level, potentially resulting in privilege escalation.

1 affected package

xen

Package 20.04 LTS
xen Needs evaluation
Show less packages

CVE-2026-6811

Medium priority
Needs evaluation

Stack exhaustion vulnerability in the MongoDB PHP driver can cause application crashes when processing deeply nested BSON documents in unusual circumstances when the source of these BSON documents is not MongoDB Server.

1 affected package

php-mongodb

Package 20.04 LTS
php-mongodb Needs evaluation
Show less packages

CVE-2026-42327

Medium priority
Needs evaluation

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.7 to before 0.10.79, X509Ref::ocsp_responders returns OCSP responder URLs from a certificate's AIA extension as OpensslString, whose Deref<Target =...

1 affected package

rust-openssl

Package 20.04 LTS
rust-openssl Needs evaluation
Show less packages

CVE-2026-44638

Medium priority
Needs evaluation

libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, a wrong NULL check after an allocation call in sixel_decode_raw and sixel_decode causes a NULL pointer dereference whenever the...

1 affected package

libsixel

Package 20.04 LTS
libsixel Needs evaluation
Show less packages

CVE-2026-43908

Medium priority
Needs evaluation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, a signed 32-bit integer overflow in the pixel-loop index expression...

1 affected package

openimageio

Package 20.04 LTS
openimageio Needs evaluation
Show less packages

CVE-2026-43905

Medium priority
Needs evaluation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, jpeg2000input.cpp:395 computes buffer size as const int bufsize = w...

1 affected package

openimageio

Package 20.04 LTS
openimageio Needs evaluation
Show less packages

CVE-2026-43904

Medium priority
Needs evaluation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, softimageinput.cpp:469 (mixed RLE) and :345 (pure RLE) do not clamp...

1 affected package

openimageio

Package 20.04 LTS
openimageio Needs evaluation
Show less packages

CVE-2026-41888

Medium priority
Needs evaluation

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.1, tag deletion via the DELETE /v2/<name>/manifests/<tag> endpoint bypasses the storage.delete.enabled: false configuration, allowing any...

1 affected package

docker-registry

Package 20.04 LTS
docker-registry Needs evaluation
Show less packages

CVE-2026-45448

Medium priority
Needs evaluation

CWE-601 URL redirection to untrusted site ('open redirect')

1 affected package

ntopng

Package 20.04 LTS
ntopng Needs evaluation
Show less packages

CVE-2026-44312

Medium priority
Needs evaluation

css_parser is a Ruby CSS parser. Prior to 2.1.0 and 1.22.0, the CSS Parser gem does not validate HTTPS connections, allowing a Man-in-the-Middle (MITM) attacker to inject or modify CSS content when stylesheets are loaded via...

1 affected package

ruby-css-parser

Package 20.04 LTS
ruby-css-parser Needs evaluation
Show less packages