Search CVE reports


Toggle filters

1451 – 1460 of 38850 results

Status is adjusted based on your filters.


CVE-2026-90558

Medium priority
Needs evaluation

sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit. Attackers can craft malicious SIP packets with oversized...

1 affected package

sngrep

Package 26.04 LTS
sngrep Needs evaluation
Show less packages

CVE-2026-90557

Medium priority
Needs evaluation

Freeciv versions 3.1.0 through 3.2.5 contain an out-of-bounds read vulnerability in sg_load_player_unit() when processing savegame files with invalid unit activity indices. An attacker can craft a malicious savegame file with an...

1 affected package

freeciv

Package 26.04 LTS
freeciv Needs evaluation
Show less packages

CVE-2026-90556

Medium priority
Needs evaluation

Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceeding the fixed array bound of 64 elements. Attackers can craft malicious savegame...

1 affected package

freeciv

Package 26.04 LTS
freeciv Needs evaluation
Show less packages

CVE-2026-90473

Medium priority
Needs evaluation

msgpack-java through 0.9.12 contains an integer overflow vulnerability in MessageUnpacker.skipValue() when processing MAP32 containers with large element counts. Attackers can supply a MAP32 element count at or above 0x40000000...

1 affected package

msgpack-java

Package 26.04 LTS
msgpack-java Needs evaluation
Show less packages

CVE-2026-90472

Medium priority
Needs evaluation

msgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker.unpackValue() that recursively deserializes arrays and maps without nesting depth limits. Attackers can craft payloads with deeply nested...

1 affected package

msgpack-java

Package 26.04 LTS
msgpack-java Needs evaluation
Show less packages

CVE-2026-90467

Medium priority
Needs evaluation

aiosmtplib before 5.1.3 fails to properly validate email addresses supplied by callers, allowing attackers to inject ESMTP parameters into MAIL FROM and RCPT TO command lines. Attackers can craft malicious addresses containing...

1 affected package

aiosmtplib

Package 26.04 LTS
aiosmtplib Needs evaluation
Show less packages

CVE-2026-89266

Medium priority
Needs evaluation

stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int. Attackers can craft a malicious Ogg Vorbis file with large entries and...

1 affected package

libstb

Package 26.04 LTS
libstb Needs evaluation
Show less packages

CVE-2026-90461

Medium priority
Needs evaluation

OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.

1 affected package

ironic

Package 26.04 LTS
ironic Needs evaluation
Show less packages

CVE-2026-90460

Medium priority
Needs evaluation

An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via delegated authentication methods (EC2 credentials, application credentials, OAuth1 access tokens, and trusts) are not blocked from creating,...

1 affected package

keystone

Package 26.04 LTS
keystone Needs evaluation
Show less packages

CVE-2026-54258

Medium priority
Needs evaluation

ZoneMinder is a free, open source closed-circuit television software application. Versions prior to 1.36.39, 1.38.4, and 1.39.11 allow an authenticated low-privileged user with coarse `Events=View` and/or `Snapshots=View`...

1 affected package

zoneminder

Package 26.04 LTS
zoneminder Needs evaluation
Show less packages