Search CVE reports


Toggle filters

11 – 20 of 43999 results

Status is adjusted based on your filters.


CVE-2026-77584

Medium priority
Needs evaluation

security update

1 affected package

tor

Package 24.04 LTS
tor Needs evaluation
Show less packages

CVE-2026-77506

Medium priority
Needs evaluation

[ZSA-2026-12]

2 affected packages

znuny, otrs2

Package 24.04 LTS
znuny Needs evaluation
otrs2 Not in release
Show less packages

CVE-2026-77118

Medium priority
Needs evaluation

(A heap out-of-bounds write exists in the Photo CD (PCD) decoder of Gra ...)

1 affected package

graphicsmagick

Package 24.04 LTS
graphicsmagick Needs evaluation
Show less packages

CVE-2026-77014

Medium priority
Needs evaluation

A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c truncates a 64-bit subtraction result to 32-bit int, flipping the sign for range offsets differing by...

2 affected packages

libsoup2.4, libsoup3

Package 24.04 LTS
libsoup2.4 Needs evaluation
libsoup3 Needs evaluation
Show less packages

CVE-2026-76957

Medium priority
Needs evaluation

libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.

23 affected packages

expat, apache2, apr-util, cmake, ghostscript...

Package 24.04 LTS
expat Needs evaluation
apache2 Not affected
apr-util Not affected
cmake Not affected
ghostscript Not affected
texlive-bin Not affected
xmlrpc-c Needs evaluation
vnc4 Not in release
wbxml2 Needs evaluation
swish-e Needs evaluation
insighttoolkit4 Not in release
cadaver Needs evaluation
gdcm Not affected
ayttm Not in release
cableswig Not in release
coin3 Not affected
matanza Ignored
tdom Needs evaluation
vtk Not in release
smart Not in release
firefox Not affected
thunderbird Not affected
libxmltok Needs evaluation
Show all 23 packages Show less packages

CVE-2026-76956

Medium priority
Needs evaluation

In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content.

23 affected packages

expat, apache2, apr-util, cmake, ghostscript...

Package 24.04 LTS
expat Needs evaluation
apache2 Not affected
apr-util Not affected
cmake Not affected
ghostscript Not affected
texlive-bin Not affected
xmlrpc-c Needs evaluation
vnc4 Not in release
wbxml2 Needs evaluation
swish-e Needs evaluation
insighttoolkit4 Not in release
cadaver Needs evaluation
gdcm Not affected
ayttm Not in release
cableswig Not in release
coin3 Not affected
matanza Ignored
tdom Needs evaluation
vtk Not in release
smart Not in release
firefox Not affected
thunderbird Not affected
libxmltok Needs evaluation
Show all 23 packages Show less packages

CVE-2026-76929

Medium priority
Needs evaluation

Pcapng file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

1 affected package

wireshark

Package 24.04 LTS
wireshark Needs evaluation
Show less packages

CVE-2026-76928

Medium priority
Needs evaluation

X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

1 affected package

wireshark

Package 24.04 LTS
wireshark Needs evaluation
Show less packages

CVE-2026-76927

Medium priority
Needs evaluation

H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

1 affected package

wireshark

Package 24.04 LTS
wireshark Needs evaluation
Show less packages

CVE-2026-76926

Medium priority
Needs evaluation

BUSMASTER file parser abnormal exit in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

1 affected package

wireshark

Package 24.04 LTS
wireshark Needs evaluation
Show less packages