Search CVE reports


Toggle filters

791 – 800 of 39047 results

Status is adjusted based on your filters.


CVE-2026-5731

Medium priority
Ignored

Memory safety bugs present in Firefox ESR 115.34.0, Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough...

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 20.04 LTS
firefox
thunderbird
mozjs38
mozjs52 Ignored
mozjs68 Ignored
mozjs78
mozjs91
mozjs102
mozjs115
Show all 9 packages Show less packages

CVE-2026-32144

Medium priority
Needs evaluation

Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_ocsp module) allows OCSP designated-responder authorization bypass via missing signature verification. The OCSP response validation in...

1 affected package

erlang

Package 20.04 LTS
erlang Needs evaluation
Show less packages

CVE-2026-28808

Medium priority
Needs evaluation

Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protected by directory rules when served via script_alias. When script_alias maps a URL prefix to a directory outside...

1 affected package

erlang

Package 20.04 LTS
erlang Needs evaluation
Show less packages

CVE-2026-31842

Medium priority
Needs evaluation

Tinyproxy through 1.11.3 is vulnerable to HTTP request parsing desynchronization due to a case-sensitive comparison of the Transfer-Encoding header in src/reqs.c. The is_chunked_transfer() function uses strcmp() to compare the...

1 affected package

tinyproxy

Package 20.04 LTS
tinyproxy Needs evaluation
Show less packages

CVE-2026-34197

High priority
Needs evaluation

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web...

1 affected package

activemq

Package 20.04 LTS
activemq Needs evaluation
Show less packages

CVE-2026-33227

Medium priority
Needs evaluation

Improper validation and restriction of a classpath path name vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ Web, Apache ActiveMQ. In two instances (when creating a Stomp...

1 affected package

activemq

Package 20.04 LTS
activemq Needs evaluation
Show less packages

CVE-2026-31790

Medium priority
Not affected

Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer. Impact summary: The uninitialized buffer might contain...

5 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2

Package 20.04 LTS
openssl Not affected
openssl-fips
openssl1.0
nodejs Not affected
edk2 Not affected
Show less packages

CVE-2026-31789

Low priority
Not affected

Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms. Impact summary: A heap buffer overflow may lead to a crash or possibly an attacker...

5 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2

Package 20.04 LTS
openssl Not affected
openssl-fips
openssl1.0
nodejs Not affected
edk2 Not affected
Show less packages

CVE-2026-28810

Medium priority
Needs evaluation

Generation of Predictable Numbers or Identifiers vulnerability in Erlang/OTP kernel (inet_res, inet_db modules) allows DNS Cache Poisoning. The built-in DNS resolver (inet_res) uses a sequential, process-global 16-bit transaction...

1 affected package

erlang

Package 20.04 LTS
erlang Needs evaluation
Show less packages

CVE-2026-28390

Low priority

Some fixes available 1 of 2

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before...

5 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2

Package 20.04 LTS
openssl Fixed
openssl-fips
openssl1.0
nodejs Not affected
edk2 Needs evaluation
Show less packages