Search CVE reports


Toggle filters

81 – 90 of 36054 results

Status is adjusted based on your filters.


CVE-2026-41073

Medium priority
Needs evaluation

[Unknown description]

2 affected packages

request-tracker4, request-tracker5

Package 24.04 LTS
request-tracker4 Needs evaluation
request-tracker5 Needs evaluation
Show less packages

CVE-2026-24425

Medium priority
Needs evaluation

Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with template rendering capabilities to pass arbitrary PHP callables to sort, filter,...

1 affected package

php-twig

Package 24.04 LTS
php-twig Needs evaluation
Show less packages

CVE-2026-22554

Medium priority
Needs evaluation

MediaArea MediaInfoLib Channel Splitting heap-based buffer overflow vulnerability

1 affected package

libmediainfo

Package 24.04 LTS
libmediainfo Needs evaluation
Show less packages

CVE-2026-9064

Medium priority
Needs evaluation

A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially...

1 affected package

389-ds-base

Package 24.04 LTS
389-ds-base Needs evaluation
Show less packages

CVE-2026-41054

Medium priority
Needs evaluation

In `src/havegecmd.c`, the `socket_handler` function performs a credential check on the abstract UNIX socket (`\0/sys/entropy/haveged`). However, while it detects if the connecting user is not root (`cred.uid != 0`) and prepares a...

1 affected package

haveged

Package 24.04 LTS
haveged Needs evaluation
Show less packages

CVE-2026-47784

Medium priority
Needs evaluation

In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_userdb_checkpass.

1 affected package

memcached

Package 24.04 LTS
memcached Needs evaluation
Show less packages

CVE-2026-47783

Medium priority
Needs evaluation

In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass.

1 affected package

memcached

Package 24.04 LTS
memcached Needs evaluation
Show less packages

CVE-2026-8975

Medium priority
Ignored

Memory safety bugs present in Thunderbird 140.10 and Thunderbird 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code....

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 24.04 LTS
firefox Not affected
thunderbird Not affected
mozjs38 Not in release
mozjs52 Not in release
mozjs68 Not in release
mozjs78 Not in release
mozjs91 Not in release
mozjs102 Ignored
mozjs115 Ignored
Show all 9 packages Show less packages

CVE-2026-8974

Medium priority
Ignored

Memory safety bugs present in Thunderbird 140.10 and Thunderbird 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code....

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 24.04 LTS
firefox Not affected
thunderbird Not affected
mozjs38 Not in release
mozjs52 Not in release
mozjs68 Not in release
mozjs78 Not in release
mozjs91 Not in release
mozjs102 Ignored
mozjs115 Ignored
Show all 9 packages Show less packages

CVE-2026-8970

Medium priority
Ignored

Privilege escalation in the Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 24.04 LTS
firefox Not affected
thunderbird Not affected
mozjs38 Not in release
mozjs52 Not in release
mozjs68 Not in release
mozjs78 Not in release
mozjs91 Not in release
mozjs102 Ignored
mozjs115 Ignored
Show all 9 packages Show less packages