Search CVE reports


Toggle filters

2861 – 2870 of 50764 results

Status is adjusted based on your filters.


CVE-2026-32853

Medium priority
Needs evaluation

LibVNCServer versions 0.9.15 and prior (fixed in commit 009008e) contain a heap out-of-bounds read vulnerability in the UltraZip encoding handler that allows a malicious VNC server to cause information disclosure or application...

6 affected packages

italc, libvncserver, tightvnc, veyon, vino, x11vnc

Package 16.04 LTS
italc Ignored
libvncserver Needs evaluation
tightvnc Ignored
veyon
vino Needs evaluation
x11vnc Ignored
Show less packages

CVE-2026-4775

Medium priority
Needs evaluation

A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile function by providing a specially crafted TIFF file. This flaw can lead to an...

5 affected packages

gdal, neuron, qtwebengine-opensource-src, texmaker, tiff

Package 16.04 LTS
gdal Ignored
neuron
qtwebengine-opensource-src
texmaker Not affected
tiff Needs evaluation
Show less packages

CVE-2026-33554

Low priority
Needs evaluation

ipmi-oem in FreeIPMI before 1.16.17 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented...

1 affected package

freeipmi

Package 16.04 LTS
freeipmi Needs evaluation
Show less packages

CVE-2026-32647

Medium priority
Fixed

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX worker memory resulting in its termination or possibly...

1 affected package

nginx

Package 16.04 LTS
nginx Fixed
Show less packages

CVE-2026-28755

Medium priority
Not affected

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when configured with the ssl_verify_client on and ssl_ocsp on directives, allowing the...

1 affected package

nginx

Package 16.04 LTS
nginx Not affected
Show less packages

CVE-2026-28753

Medium priority
Fixed

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of CRLF sequences in DNS responses. This allows an attacker-controlled DNS server to inject arbitrary headers...

1 affected package

nginx

Package 16.04 LTS
nginx Fixed
Show less packages

CVE-2026-27784

Medium priority
Fixed

The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to over-read or over-write NGINX worker memory resulting in its termination, using a specially...

1 affected package

nginx

Package 16.04 LTS
nginx Fixed
Show less packages

CVE-2026-27654

Medium priority
Fixed

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination of the...

1 affected package

nginx

Package 16.04 LTS
nginx Fixed
Show less packages

CVE-2026-27651

Medium priority
Fixed

When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and...

1 affected package

nginx

Package 16.04 LTS
nginx Fixed
Show less packages

CVE-2025-64998

Medium priority
Ignored

Exposure of session signing secret in Checkmk <2.4.0p23, <2.3.0p45 and 2.2.0 allows an administrator of a remote site with config sync enabled to hijack sessions on the central site by forging session cookies.

1 affected package

check-mk

Package 16.04 LTS
check-mk Ignored
Show less packages