Search CVE reports


Toggle filters

1751 – 1760 of 35604 results

Status is adjusted based on your filters.


CVE-2026-41035

Low priority
Vulnerable

In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all)...

1 affected package

rsync

Package 24.04 LTS
rsync Vulnerable
Show less packages

CVE-2026-40960

Medium priority

Not in release

Luanti 5 before 5.15.2 sometimes allows unintended access to an insecure environment. If at least one mod is listed as secure.trusted_mods or secure.http_mods, then a crafted mod can intercept the request for the insecure...

1 affected package

luanti

Package 24.04 LTS
luanti Not in release
Show less packages

CVE-2026-40959

Medium priority

Not in release

[Luanti Mod security sandbox escape]

1 affected package

luanti

Package 24.04 LTS
luanti Not in release
Show less packages

CVE-2026-40919

Medium priority
Needs evaluation

[Stack Buffer overflow - Seattle-Filmworks Image]

1 affected package

gimp

Package 24.04 LTS
gimp Needs evaluation
Show less packages

CVE-2026-40916

Medium priority
Needs evaluation

[TIM File Parsing: Stack Out-of-Bounds Write in 4BPP Decode Path]

1 affected package

gimp

Package 24.04 LTS
gimp Needs evaluation
Show less packages

CVE-2026-40915

Medium priority
Needs evaluation

[FITS File Parsing: Integer Overflow in Buffer Allocation Leads to Heap Overflow]

1 affected package

gimp

Package 24.04 LTS
gimp Needs evaluation
Show less packages

CVE-2026-40176

Medium priority
Needs evaluation

[Command injection via malicious Perforce repository definition]

1 affected package

composer

Package 24.04 LTS
composer Needs evaluation
Show less packages

CVE-2026-35469

Medium priority
Needs evaluation

spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation...

1 affected package

golang-github-docker-spdystream

Package 24.04 LTS
golang-github-docker-spdystream Needs evaluation
Show less packages

CVE-2026-40261

Medium priority
Needs evaluation

Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::syncCodeBase() method, which appends the $sourceReference parameter to a shell...

1 affected package

composer

Package 24.04 LTS
composer Needs evaluation
Show less packages

CVE-2026-6384

Medium priority
Needs evaluation

A flaw was found in gimp. This buffer overflow vulnerability in the GIF image loading component's `ReadJeffsImage` function allows an attacker to write beyond an allocated buffer by processing a specially crafted GIF file. This...

1 affected package

gimp

Package 24.04 LTS
gimp Needs evaluation
Show less packages