Search CVE reports


Toggle filters

981 – 990 of 46017 results

Status is adjusted based on your filters.


CVE-2026-63649

Medium priority
Not affected

The Windows interactive service in OpenVPN 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via...

1 affected package

openvpn

Package 20.04 LTS
openvpn Not affected
Show less packages

CVE-2026-74248

Medium priority
Needs evaluation

OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization. By associating another project's QoS policy with an amphora, an authenticated user may prevent deletion of that policy. All...

1 affected package

octavia

Package 20.04 LTS
octavia Needs evaluation
Show less packages

CVE-2026-45699

Medium priority
Needs evaluation

Netatalk is a Free and Open Source file server suite for Unix-like operating systems. In versions 3.1.19 through 4.4.2, a stack-based buffer overflow exists in the copydir() function of Netatalk's afpd daemon due to an integer...

1 affected package

netatalk

Package 20.04 LTS
netatalk Needs evaluation
Show less packages

CVE-2026-49282

Medium priority
Needs evaluation

Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's public `cs_insn_name()` API forwards caller-supplied instruction IDs directly to the selected architecture backend. Most backends validate the ID...

1 affected package

capstone

Package 20.04 LTS
capstone Needs evaluation
Show less packages

CVE-2026-49263

Medium priority
Needs evaluation

Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's WebAssembly backend accepts attacker-controlled raw WASM instruction bytes through the public `cs_disasm()` and `cs_disasm_iter()` APIs. For a large...

1 affected package

capstone

Package 20.04 LTS
capstone Needs evaluation
Show less packages

CVE-2026-47766

Medium priority
Needs evaluation

crun is an open source OCI Container Runtime fully written in C. Prior to version 1.28, crun's default device setup opens the container rootfs `/dev` directory without `O_NOFOLLOW`. If an OCI bundle contains `rootfs/dev` as...

1 affected package

crun

Package 20.04 LTS
crun Needs evaluation
Show less packages

CVE-2026-46603

Medium priority
Needs evaluation

VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via...

1 affected package

golang-golang-x-image

Package 20.04 LTS
golang-golang-x-image Needs evaluation
Show less packages

CVE-2026-13002

Medium priority
Vulnerable

A flow has been identified into dnssec.c library, causing an infinite loop to dnsmasq service. An attacker who controls any DNSSEC-signed zone can hang the dnsmasq process with a single crafted response, killing all DNS resolution...

1 affected package

dnsmasq

Package 20.04 LTS
dnsmasq Vulnerable
Show less packages

CVE-2026-19879

Medium priority
Needs evaluation

A flaw was found in Undertow, an HTTP server, within its HTTP response header writing path. The `writeString()` method performs a silent narrowing cast from 16-bit Unicode characters to 8-bit bytes when writing HTTP response...

1 affected package

undertow

Package 20.04 LTS
undertow Needs evaluation
Show less packages

CVE-2026-19617

Medium priority
Vulnerable

A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration with deeply nested structures. This could lead to uncontrolled recursion in the libdm configuration...

1 affected package

lvm2

Package 20.04 LTS
lvm2 Vulnerable
Show less packages