Search CVE reports


Toggle filters

1761 – 1770 of 46017 results

Status is adjusted based on your filters.


CVE-2026-59679

Medium priority
Needs evaluation

[Font Server Client encoding Out-Of-Bounds Read/Write]

2 affected packages

libxfont, libxfont2

Package 20.04 LTS
libxfont Needs evaluation
libxfont2
Show less packages

CVE-2026-54876

Medium priority
Not affected

Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP response that contains no single response entries. Impact summary: An attacker can leak an...

5 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2

Package 20.04 LTS
openssl Not affected
openssl-fips
openssl1.0
nodejs Not affected
edk2 Not affected
Show less packages

CVE-2026-44950

Medium priority
Needs evaluation

[Font Server Client Cumulative Glyph Data Heap Buffer Overflow]

2 affected packages

libxfont, libxfont2

Package 20.04 LTS
libxfont Needs evaluation
libxfont2
Show less packages

CVE-2026-51401

Medium priority
Vulnerable

An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/src/os_vms.c

1 affected package

vim

Package 20.04 LTS
vim Vulnerable
Show less packages

CVE-2026-51400

Medium priority
Vulnerable

An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/src/os_vms.c

1 affected package

vim

Package 20.04 LTS
vim Vulnerable
Show less packages

CVE-2026-68743

Medium priority
Needs evaluation

A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted...

1 affected package

sssd

Package 20.04 LTS
sssd Needs evaluation
Show less packages

CVE-2026-56848

Medium priority
Needs evaluation

A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. This vulnerability affects Node.js **26.x**,...

1 affected package

nodejs

Package 20.04 LTS
nodejs Needs evaluation
Show less packages

CVE-2026-15920

Medium priority
Needs evaluation

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.contrib.admin.utils.display_for_field()` renders `URLField` values as clickable links in the admin without validating the URL. A value stored with...

1 affected package

python-django

Package 20.04 LTS
python-django Needs evaluation
Show less packages

CVE-2026-15830

Medium priority
Needs evaluation

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects...

1 affected package

python-django

Package 20.04 LTS
python-django Needs evaluation
Show less packages

CVE-2026-15337

Medium priority
Needs evaluation

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.check_for_language()` is subject to a potential denial-of-service attack when given many distinct, very long language codes, which...

1 affected package

python-django

Package 20.04 LTS
python-django Needs evaluation
Show less packages