Search CVE reports


Toggle filters

811 – 820 of 46705 results

Status is adjusted based on your filters.


CVE-2026-61915

Medium priority
Needs evaluation

An issue was discovered in Cyrus IMAP before 3.12.4. There is a VPATCH BYPARAM double-free. An authenticated calendar user could crash a Cyrus CalDAV worker with a PATCH containing PATCH-ACTION="BYPARAM@..." against a resource...

1 affected package

cyrus-imapd

Package 24.04 LTS
cyrus-imapd Needs evaluation
Show less packages

CVE-2026-61911

Medium priority
Needs evaluation

An issue was discovered in Cyrus IMAP before 3.12.4. There is a Sieve mailbox existence oracle. An authenticated user could install a Sieve script that probed whether another user's private mailbox existed, or read the value of...

1 affected package

cyrus-imapd

Package 24.04 LTS
cyrus-imapd Needs evaluation
Show less packages

CVE-2026-61910

Medium priority
Needs evaluation

An issue was discovered in Cyrus IMAP before 3.12.4. Mailbox/set let a sharee change a special-use role on shared mailboxes. An authenticated user with maySetKeywords on another user's mailbox could change that...

1 affected package

cyrus-imapd

Package 24.04 LTS
cyrus-imapd Needs evaluation
Show less packages

CVE-2026-61909

Medium priority
Needs evaluation

An issue was discovered in Cyrus IMAP before 3.12.4. CalDAV/CardDAV multiget bypasses a per-href ACL. An authenticated DAV user with some shared access to another user's calendar or address book could read even unshared events or...

1 affected package

cyrus-imapd

Package 24.04 LTS
cyrus-imapd Needs evaluation
Show less packages

CVE-2026-61908

Medium priority
Needs evaluation

An issue was discovered in Cyrus IMAP before 3.12.4. A JMAP email-header blob ID can reference an out-of-bounds index. An authenticated user could attempt to download a crafted JMAP blob ID of the form H<emailid>-<index>, which...

1 affected package

cyrus-imapd

Package 24.04 LTS
cyrus-imapd Needs evaluation
Show less packages

CVE-2026-61907

Medium priority
Needs evaluation

An issue was discovered in Cyrus IMAP before 3.12.4. JMAP snooze bypasses the destination-mailbox ACL. An authenticated user with insert permissions on another user's snoozed mailbox could cause insertion of mail to that user's...

1 affected package

cyrus-imapd

Package 24.04 LTS
cyrus-imapd Needs evaluation
Show less packages

CVE-2026-87819

Medium priority
Needs evaluation

GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields. Attackers can craft a commit object with a malformed author field...

1 affected package

python-git

Package 24.04 LTS
python-git Needs evaluation
Show less packages

CVE-2026-87818

Medium priority
Needs evaluation

GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to...

1 affected package

python-git

Package 24.04 LTS
python-git Needs evaluation
Show less packages

CVE-2026-87817

Medium priority
Needs evaluation

GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by...

1 affected package

python-git

Package 24.04 LTS
python-git Needs evaluation
Show less packages

CVE-2026-74761

Medium priority
Needs evaluation

Improper input validation in TopicRegion in Apache ActiveMQ, Apache ActiveMQ Broker, and Apache ActiveMQ AllĀ on all platforms. An authenticated client can spoof clientId when removing a durable topic subscription. This issue...

1 affected package

activemq

Package 24.04 LTS
activemq Needs evaluation
Show less packages