Search CVE reports


Toggle filters

1501 – 1510 of 39983 results

Status is adjusted based on your filters.


CVE-2026-30656

Medium priority
Needs evaluation

A NULL pointer dereference vulnerability exists in fio (Flexible I/O Tester) v3.41 when parsing job files containing the fdp_pli option. The callback function str_fdp_pli_cb() does not validate the input pointer and calls strdup()...

1 affected package

fio

Package 20.04 LTS
fio Needs evaluation
Show less packages

CVE-2026-41015

Medium priority
Needs evaluation

radare2 before 9236f44, when configured on UNIX without SSL, allows command injection via a PDB name to rabin2 -PP. NOTE: although users are supposed to use the latest version from git (not a release), the date range for...

1 affected package

radare2

Package 20.04 LTS
radare2 Needs evaluation
Show less packages

CVE-2026-40962

Medium priority
Needs evaluation

FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data to libavformat/mov.c.

2 affected packages

ffmpeg, libav

Package 20.04 LTS
ffmpeg Needs evaluation
libav
Show less packages

CVE-2026-40505

Medium priority
Needs evaluation

MuPDF before 1.27 contains an ANSI injection vulnerability in mutool that allows attackers to inject arbitrary ANSI escape sequences through crafted PDF metadata fields. Attackers can embed malicious ANSI escape codes in...

1 affected package

mupdf

Package 20.04 LTS
mupdf Needs evaluation
Show less packages

CVE-2026-40947

Medium priority
Not affected

Yubico libfido2 before 1.17.0, python-fido2 before 2.2.0, and yubikey-manager before 5.9.1 have an unintended DLL search path.

3 affected packages

libfido2, python-fido2, yubikey-manager

Package 20.04 LTS
libfido2 Not affected
python-fido2 Not affected
yubikey-manager Not affected
Show less packages

CVE-2026-41035

Low priority
Vulnerable

In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all)...

1 affected package

rsync

Package 20.04 LTS
rsync Vulnerable
Show less packages

CVE-2026-35469

Medium priority
Needs evaluation

spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation...

1 affected package

golang-github-docker-spdystream

Package 20.04 LTS
golang-github-docker-spdystream Needs evaluation
Show less packages

CVE-2026-40179

Medium priority
Needs evaluation

Prometheus is an open-source monitoring system and time series database. Versions 3.0 through 3.5.1 and 3.6.0 through 3.11.1 have stored cross-site scripting vulnerabilities in multiple components of the Prometheus web UI where...

1 affected package

prometheus

Package 20.04 LTS
prometheus Needs evaluation
Show less packages

CVE-2026-40261

Medium priority
Needs evaluation

Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::syncCodeBase() method, which appends the $sourceReference parameter to a shell...

1 affected package

composer

Package 20.04 LTS
composer Needs evaluation
Show less packages

CVE-2026-40176

Medium priority
Needs evaluation

Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::generateP4Command() method, which constructs shell commands by interpolating...

1 affected package

composer

Package 20.04 LTS
composer Needs evaluation
Show less packages