Search CVE reports


Toggle filters

1701 – 1710 of 43788 results

Status is adjusted based on your filters.


CVE-2026-71391

Medium priority
Needs evaluation

GNU Emacs for Android contains an off-by-one error in the gvar table parser in src/sfnt.c. The shared-coordinate index boundary check in sfnt_vary_simple_glyph() and sfnt_vary_compound_glyph() uses a strict greater-than comparison...

5 affected packages

emacs, xemacs21, xemacs21-packages, emacs24, emacs25

Package 24.04 LTS
emacs Needs evaluation
xemacs21 Needs evaluation
xemacs21-packages Needs evaluation
emacs24 Not in release
emacs25 Not in release
Show less packages

CVE-2026-66486

Medium priority
Vulnerable

GNU cpio is vulnerable to improper encoding or escaping of output in its archive member listing functionality. When listing archive members via cpio -it, member names are printed directly to output without quoting or escaping. An...

1 affected package

cpio

Package 24.04 LTS
cpio Vulnerable
Show less packages

CVE-2026-66485

Medium priority
Vulnerable

GNU cpio is vulnerable to an uncontrolled memory allocation in the make_path function at src/makepath.c. The function uses alloca to allocate stack memory based on the length of argpath, which is derived from an archive-controlled...

1 affected package

cpio

Package 24.04 LTS
cpio Vulnerable
Show less packages

CVE-2026-66484

Medium priority
Vulnerable

GNU cpio contains a Path Traversal vulnerability in its tar archive extraction functionality. When extracting a tar archive in copy-in mode with the --no-absolute-filenames option, the extracted file name is normalized but the tar...

1 affected package

cpio

Package 24.04 LTS
cpio Vulnerable
Show less packages

CVE-2026-59087

Medium priority
Needs evaluation

A flaw was found in the GIMP image manipulation program, specifically within its Seattle Filmworks file loader. A remote attacker could exploit this vulnerability by tricking a user into opening a specially crafted Seattle...

1 affected package

gimp

Package 24.04 LTS
gimp Needs evaluation
Show less packages

CVE-2026-19404

Medium priority
Needs evaluation

A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operations perform no authorization check, allowing an unauthenticated remote attacker to invoke them when...

1 affected package

389-ds-base

Package 24.04 LTS
389-ds-base Needs evaluation
Show less packages

CVE-2026-12570

Medium priority

Not in release

A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model files via the keras.models.load_model() function. The H5IOStore.__getitem__ method...

1 affected package

keras

Package 24.04 LTS
keras Not in release
Show less packages

CVE-2026-72522

Medium priority
Needs evaluation

libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.

23 affected packages

expat, apache2, apr-util, cmake, ghostscript...

Package 24.04 LTS
expat Needs evaluation
apache2 Not affected
apr-util Not affected
cmake Not affected
ghostscript Not affected
texlive-bin Not affected
xmlrpc-c Needs evaluation
vnc4 Not in release
wbxml2 Needs evaluation
swish-e Needs evaluation
insighttoolkit4 Not in release
cadaver Needs evaluation
gdcm Not affected
ayttm Not in release
cableswig Not in release
coin3 Not affected
matanza Ignored
tdom Needs evaluation
vtk Not in release
smart Not in release
firefox Not affected
thunderbird Not affected
libxmltok Needs evaluation
Show all 23 packages Show less packages

CVE-2026-19389

Medium priority
Needs evaluation

Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation...

1 affected package

gst-plugins-ugly1.0

Package 24.04 LTS
gst-plugins-ugly1.0 Needs evaluation
Show less packages

CVE-2026-19387

Medium priority
Needs evaluation

A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a...

1 affected package

gst-plugins-bad1.0

Package 24.04 LTS
gst-plugins-bad1.0 Needs evaluation
Show less packages