Search CVE reports


Toggle filters

431 – 440 of 38817 results

Status is adjusted based on your filters.


CVE-2026-3446

Medium priority
Needs evaluation

When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted...

13 affected packages

pypy3, python2.7, python3.4, python3.5, python3.6...

Package 20.04 LTS
pypy3 Needs evaluation
python2.7 Needs evaluation
python3.4
python3.5
python3.6
python3.7
python3.8 Needs evaluation
python3.9 Needs evaluation
python3.10
python3.11
python3.12
python3.13
python3.14
Show all 13 packages Show less packages

CVE-2026-1502

Medium priority
Needs evaluation

CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.

14 affected packages

jython, pypy3, python2.7, python3.4, python3.5...

Package 20.04 LTS
jython Needs evaluation
pypy3 Needs evaluation
python2.7 Needs evaluation
python3.4
python3.5
python3.6
python3.7
python3.8 Needs evaluation
python3.9 Needs evaluation
python3.10
python3.11
python3.12
python3.13
python3.14
Show all 14 packages Show less packages

CVE-2026-40200

Medium priority
Needs evaluation

An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur during qsort of very large arrays, due to incorrectly implemented double-word primitives. The number of elements must exceed about...

1 affected package

musl

Package 20.04 LTS
musl Needs evaluation
Show less packages

CVE-2026-40228

Medium priority
Needs evaluation

In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p emerg" command is executed, if ForwardToWall=yes is set.

1 affected package

systemd

Package 20.04 LTS
systemd Needs evaluation
Show less packages

CVE-2026-40227

Medium priority
Needs evaluation

In systemd 260 before 261, a local unprivileged user can trigger an assert via an IPC API call with an array or map that has a null element.

1 affected package

systemd

Package 20.04 LTS
systemd Needs evaluation
Show less packages

CVE-2026-40226

Medium priority
Needs evaluation

In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file.

1 affected package

systemd

Package 20.04 LTS
systemd Needs evaluation
Show less packages

CVE-2026-40225

Medium priority
Needs evaluation

In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output.

1 affected package

systemd

Package 20.04 LTS
systemd Needs evaluation
Show less packages

CVE-2026-40224

Medium priority
Needs evaluation

In systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink can be used to reach the root namespace.

1 affected package

systemd

Package 20.04 LTS
systemd Needs evaluation
Show less packages

CVE-2026-40223

Medium priority
Needs evaluation

In systemd 258 before 260, a local unprivileged user can trigger an assert when a Delegate=yes and User=<unset> unit exists and is running.

1 affected package

systemd

Package 20.04 LTS
systemd Needs evaluation
Show less packages

CVE-2026-40023

Medium priority
Needs evaluation

Apache Log4cxx's XMLLayout https://logging.apache.org/log4cxx/1.7.0/classlog4cxx_1_1xml_1_1XMLLayout.html , in versions before 1.7.0, fails to sanitize characters forbidden by the XML 1.0 specification...

1 affected package

log4cxx

Package 20.04 LTS
log4cxx Needs evaluation
Show less packages