Search CVE reports


Toggle filters

1211 – 1220 of 38897 results

Status is adjusted based on your filters.


CVE-2026-81634

Medium priority
Needs evaluation

In NLnet Labs Unbound up to and including 1.26.0, a 255 length query name with a large TCP response can lead to a heap buffer overflow during the RRSet canonicalisation routine. This is caused by missing to add the first owner...

1 affected package

unbound

Package 26.04 LTS
unbound Needs evaluation
Show less packages

CVE-2026-80225

Medium priority
Needs evaluation

In NLnetLabs Unbound up to and including 1.26.0, a degradation of service vulnerability is present in the TCP/DoT reading procedure where there is no limit on consecutive reads. A malicious actor that can stream and sustain a rate...

1 affected package

unbound

Package 26.04 LTS
unbound Needs evaluation
Show less packages

CVE-2026-78227

Medium priority
Needs evaluation

NLnet Labs Unbound 1.22.0 up to and including 1.26.1, has a use-after-free vulnerability when compiled for DNS-over-QUIC support with '--with-libngtcp2'. Each DoQ stream owns an output buffer that holds the DNS response. ngtcp2's...

1 affected package

unbound

Package 26.04 LTS
unbound Needs evaluation
Show less packages

CVE-2026-77955

Medium priority
Needs evaluation

In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) which are located below (but not at) a trust anchor allow for an attack window where (tampered with) zone...

1 affected package

unbound

Package 26.04 LTS
unbound Needs evaluation
Show less packages

CVE-2026-77860

Medium priority
Needs evaluation

In NLnetLabs Unbound 1.20.0 up to and including 1.26.0, a vulnerability on the 'serve-expired' code path can cause a double decrement on the 'wait-limit' counter per client IP essentially bypassing one of the counter measures that...

1 affected package

unbound

Package 26.04 LTS
unbound Needs evaluation
Show less packages

CVE-2026-92091

Medium priority
Needs evaluation

A flaw was found in jwcrypto. The JWK.import_key() function validates the key_ops JWK member for duplicate values using an algorithm with O(n^2) time complexity, and the length of key_ops is not bounded. A remote, unauthenticated...

1 affected package

python-jwcrypto

Package 26.04 LTS
python-jwcrypto Needs evaluation
Show less packages

CVE-2026-19248

Medium priority
Needs evaluation

QDomDocument XML parsing is vulnerable to a remotely-triggerable denial-of-service crash when processing untrusted input.

2 affected packages

qt6-base, qtbase-opensource-src

Package 26.04 LTS
qt6-base Needs evaluation
qtbase-opensource-src Needs evaluation
Show less packages

CVE-2026-39919

Medium priority
Fixed

Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 output adapter (base/sjpx_openjpeg.c) that allows attackers to cause memory corruption by supplying a crafted PDF containing a JPEG...

1 affected package

ghostscript

Package 26.04 LTS
ghostscript Fixed
Show less packages

CVE-2025-11395

Medium priority
Needs evaluation

A flaw was found in Podman. If an attacker can pass a crafted tar archive to the `podman load` command, they can create files on the host machine with the privileges of the user running Podman.

1 affected package

podman

Package 26.04 LTS
podman Needs evaluation
Show less packages

CVE-2026-92248

Medium priority
Needs evaluation

A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially crafted PSD (Photoshop Document) image file, an integer overflow occurs during the multiplication of values from an embedded JPEG...

1 affected package

gimp

Package 26.04 LTS
gimp Needs evaluation
Show less packages