Search CVE reports


Toggle filters

1011 – 1020 of 46017 results

Status is adjusted based on your filters.


CVE-2026-73508

Medium priority
Needs evaluation

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.dns.AbstractDnsRecord, io.netty.handler.codec.dns.DefaultDnsRecordDecoder.decodeRecord(),...

1 affected package

netty

Package 20.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-73507

Medium priority
Needs evaluation

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.xml.XmlFrameDecoder.decode() failed to preserve closing-tag parser state across invocations, so...

1 affected package

netty

Package 20.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-14456

Medium priority
Not affected

Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit. Impact...

5 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2

Package 20.04 LTS
openssl Not affected
openssl-fips
openssl1.0
nodejs Not affected
edk2 Not affected
Show less packages

CVE-2026-73585

Medium priority
Needs evaluation

A flaw was found in sblim-cmpi-base. Insecure temporary file creation in the provider registration scripts allows a local unprivileged user to perform a symlink attack. By creating a symlink in a world-writable directory, an...

1 affected package

sblim-cmpi-base

Package 20.04 LTS
sblim-cmpi-base Needs evaluation
Show less packages

CVE-2026-73584

Medium priority
Needs evaluation

A flaw was found in sblim-sfcb. A local, low-privileged attacker can exploit a race condition during privileged instance migration by manipulating a temporary file in the `/tmp` directory. By repeatedly recreating a symbolic link,...

1 affected package

sblim-sfcb

Package 20.04 LTS
sblim-sfcb Needs evaluation
Show less packages

CVE-2026-73583

Medium priority
Needs evaluation

A flaw was found in sblim-sfcb. A local attacker with access to the system can exploit an unsafe deserialization vulnerability in the provider-manager's inter-process communication (IPC) message parsing. By sending a specially...

1 affected package

sblim-sfcb

Package 20.04 LTS
sblim-sfcb Needs evaluation
Show less packages

CVE-2026-6471

Medium priority
Needs evaluation

Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. ...

7 affected packages

postgresql-18, postgresql-16, postgresql-14, postgresql-12, postgresql-10...

Package 20.04 LTS
postgresql-18
postgresql-16
postgresql-14
postgresql-12 Needs evaluation
postgresql-10
postgresql-9.5
postgresql-9.3
Show all 7 packages Show less packages

CVE-2026-6470

Medium priority
Needs evaluation

Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check the privilege, but...

7 affected packages

postgresql-18, postgresql-16, postgresql-14, postgresql-12, postgresql-10...

Package 20.04 LTS
postgresql-18
postgresql-16
postgresql-14
postgresql-12 Needs evaluation
postgresql-10
postgresql-9.5
postgresql-9.3
Show all 7 packages Show less packages

CVE-2026-6469

Medium priority
Needs evaluation

Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run DROP STATISTICS and ALTER STATISTICS...

7 affected packages

postgresql-18, postgresql-16, postgresql-14, postgresql-12, postgresql-10...

Package 20.04 LTS
postgresql-18
postgresql-16
postgresql-14
postgresql-12 Needs evaluation
postgresql-10
postgresql-9.5
postgresql-9.3
Show all 7 packages Show less packages

CVE-2026-6464

Medium priority
Needs evaluation

Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the...

7 affected packages

postgresql-18, postgresql-16, postgresql-14, postgresql-12, postgresql-10...

Package 20.04 LTS
postgresql-18
postgresql-16
postgresql-14
postgresql-12 Needs evaluation
postgresql-10
postgresql-9.5
postgresql-9.3
Show all 7 packages Show less packages