Search CVE reports


Toggle filters

381 – 390 of 46705 results

Status is adjusted based on your filters.


CVE-2026-90616

Medium priority
Needs evaluation

In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read and write access to files on the host, which can be escalated to arbitrary code execution on the host, a different vulnerability than CVE-2026-76925....

1 affected package

flatpak

Package 24.04 LTS
flatpak Needs evaluation
Show less packages

CVE-2026-90560

Medium priority
Needs evaluation

zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds. Attackers can...

1 affected package

zstd-jni-java

Package 24.04 LTS
zstd-jni-java Needs evaluation
Show less packages

CVE-2026-90558

Medium priority
Needs evaluation

sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit. Attackers can craft malicious SIP packets with oversized...

1 affected package

sngrep

Package 24.04 LTS
sngrep Needs evaluation
Show less packages

CVE-2026-90557

Medium priority
Needs evaluation

Freeciv versions 3.1.0 through 3.2.5 contain an out-of-bounds read vulnerability in sg_load_player_unit() when processing savegame files with invalid unit activity indices. An attacker can craft a malicious savegame file with an...

1 affected package

freeciv

Package 24.04 LTS
freeciv Needs evaluation
Show less packages

CVE-2026-90556

Medium priority
Needs evaluation

Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceeding the fixed array bound of 64 elements. Attackers can craft malicious savegame...

1 affected package

freeciv

Package 24.04 LTS
freeciv Needs evaluation
Show less packages

CVE-2026-90473

Medium priority
Needs evaluation

msgpack-java through 0.9.12 contains an integer overflow vulnerability in MessageUnpacker.skipValue() when processing MAP32 containers with large element counts. Attackers can supply a MAP32 element count at or above 0x40000000...

1 affected package

msgpack-java

Package 24.04 LTS
msgpack-java Needs evaluation
Show less packages

CVE-2026-90472

Medium priority
Needs evaluation

msgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker.unpackValue() that recursively deserializes arrays and maps without nesting depth limits. Attackers can craft payloads with deeply nested...

1 affected package

msgpack-java

Package 24.04 LTS
msgpack-java Needs evaluation
Show less packages

CVE-2026-90467

Medium priority

Not in release

aiosmtplib before 5.1.3 fails to properly validate email addresses supplied by callers, allowing attackers to inject ESMTP parameters into MAIL FROM and RCPT TO command lines. Attackers can craft malicious addresses containing...

1 affected package

aiosmtplib

Package 24.04 LTS
aiosmtplib Not in release
Show less packages

CVE-2026-89266

Medium priority
Needs evaluation

stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int. Attackers can craft a malicious Ogg Vorbis file with large entries and...

1 affected package

libstb

Package 24.04 LTS
libstb Needs evaluation
Show less packages

CVE-2026-90461

Medium priority
Needs evaluation

OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.

1 affected package

ironic

Package 24.04 LTS
ironic Needs evaluation
Show less packages