Search CVE reports


Toggle filters

231 – 240 of 42038 results

Status is adjusted based on your filters.


CVE-2026-68945

Medium priority
Needs evaluation

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.2, HttpTransferCache comma-joins repeated request parameters,...

1 affected package

angular.js

Package 24.04 LTS
angular.js Needs evaluation
Show less packages

CVE-2026-61372

Medium priority
Needs evaluation

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki. This issue affects Apache Jena Fuseki: through 6.1.0. Users are recommended to upgrade to version 6.2.0, which...

1 affected package

apache-jena

Package 24.04 LTS
apache-jena Needs evaluation
Show less packages

CVE-2026-18477

Medium priority
Needs evaluation

A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has...

1 affected package

tar

Package 24.04 LTS
tar Needs evaluation
Show less packages

CVE-2026-18651

Medium priority
Needs evaluation

A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the account is subsequently found to be locked,...

1 affected package

389-ds-base

Package 24.04 LTS
389-ds-base Needs evaluation
Show less packages

CVE-2026-18508

Medium priority
Needs evaluation

A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A...

1 affected package

tar

Package 24.04 LTS
tar Needs evaluation
Show less packages

CVE-2026-69097

Medium priority
Needs evaluation

GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers can inject core.sshCommand or other...

1 affected package

python-git

Package 24.04 LTS
python-git Needs evaluation
Show less packages

CVE-2026-68742

Medium priority
Needs evaluation

A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate the addrlen field against the remaining packet body size. A local attacker can exploit this via a crafted GETHOSTBYADDR...

1 affected package

sssd

Package 24.04 LTS
sssd Needs evaluation
Show less packages

CVE-2026-12259

Medium priority
Needs evaluation

In nltk version 3.9.4, the `nltk.downloader.Downloader._download_package()` function writes downloaded package bytes to disk and may extract them before enforcing SHA-256 or MD5 checksum validation. This allows an attacker to...

1 affected package

nltk

Package 24.04 LTS
nltk Needs evaluation
Show less packages

CVE-2026-6695

Medium priority
Needs evaluation

A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially crafted PAA (Paint Shop Pro Array) image file. This vulnerability, a heap-based out-of-bounds write in the decode_lzss()...

1 affected package

gimp

Package 24.04 LTS
gimp Needs evaluation
Show less packages

CVE-2026-6694

Medium priority
Needs evaluation

A flaw was found in GIMP's file-png plugin. A remote attacker can exploit this by crafting a malicious Animated Portable Network Graphics (APNG) image containing an oversized tRNS chunk. This can lead to a stack-based buffer...

1 affected package

gimp

Package 24.04 LTS
gimp Needs evaluation
Show less packages