Search CVE reports


Toggle filters

41 – 50 of 38129 results

Status is adjusted based on your filters.


CVE-2026-56371

Medium priority
Needs evaluation

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a memory leak in coders/txt.c when processing TXT files with texture attributes: the texture object allocated via ReadImage is not released when GetTypeMetrics fails, leaking...

1 affected package

imagemagick

Package 24.04 LTS
imagemagick Needs evaluation
Show less packages

CVE-2026-55655

Medium priority
Needs evaluation

A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is...

2 affected packages

openssh, openssh-ssh1

Package 24.04 LTS
openssh Needs evaluation
openssh-ssh1 Ignored
Show less packages

CVE-2026-55654

Medium priority
Needs evaluation

A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in...

2 affected packages

openssh, openssh-ssh1

Package 24.04 LTS
openssh Needs evaluation
openssh-ssh1 Ignored
Show less packages

CVE-2026-55653

Medium priority
Needs evaluation

A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode...

2 affected packages

openssh, openssh-ssh1

Package 24.04 LTS
openssh Needs evaluation
openssh-ssh1 Ignored
Show less packages

CVE-2026-10658

Medium priority
Needs evaluation

A missing length validation in the Zephyr Bluetooth Host ISO receive path can be triggered by malformed HCI ISO data. In bt_iso_recv() (subsys/bluetooth/host/iso.c), when processing PB=START/SINGLE fragments, the code pulls a TS...

1 affected package

zephyr

Package 24.04 LTS
zephyr Needs evaluation
Show less packages

CVE-2026-10651

Medium priority
Needs evaluation

A malformed Bluetooth Classic SDP attribute can trigger a reachable assertion in Zephyr's SDP parser. In subsys/bluetooth/host/classic/sdp.c, bt_sdp_parse_attribute() accepts an input buffer once it contains the 1-byte attribute...

1 affected package

zephyr

Package 24.04 LTS
zephyr Needs evaluation
Show less packages

CVE-2026-10645

Medium priority
Needs evaluation

Zephyr's ext2 directory-entry parser does not fully validate on-disk directory entry structure before copying the entry name and advancing traversal state. In ext2_fetch_direntry() (subsys/fs/ext2/ext2_diskops.c), the code only...

1 affected package

zephyr

Package 24.04 LTS
zephyr Needs evaluation
Show less packages

CVE-2026-54911

Medium priority
Needs evaluation

UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.13.0, ujson.dumps() (or ujson.dump() or ujson.encode()) have a reject_bytes=False option. When set, they may accept malformed...

3 affected packages

ujson, pandas, collada2gltf

Package 24.04 LTS
ujson Needs evaluation
pandas Needs evaluation
collada2gltf Not in release
Show less packages

CVE-2026-55599

Medium priority
Needs evaluation

phpseclib is a PHP secure communications library. From 0.1.1 until 1.0.30, 2.0.55, and 3.0.54, when an application validates an untrusted X.509 certificate with phpseclib, X509::validateSignature() reads a URL out of that...

1 affected package

phpseclib

Package 24.04 LTS
phpseclib Needs evaluation
Show less packages

CVE-2026-54651

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to 6.13.1, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires merging a file with threads/articles into a writer....

3 affected packages

pypdf, pypdf2, python-pypdf

Package 24.04 LTS
pypdf Needs evaluation
pypdf2 Needs evaluation
python-pypdf Not in release
Show less packages