Search CVE reports


Toggle filters

1221 – 1230 of 49291 results

Status is adjusted based on your filters.


CVE-2026-91947

Medium priority
Needs evaluation

FreeRDP server versions before 3.31.0 contain a use-after-free vulnerability in the DRDYNVC parser that dereferences a channel pointer after releasing the synchronization lock. Authenticated clients can race AUDIN channel closure...

3 affected packages

freerdp, freerdp2, freerdp3

Package 20.04 LTS
freerdp
freerdp2 Needs evaluation
freerdp3
Show less packages

CVE-2026-91946

Medium priority
Needs evaluation

FreeRDP versions before 3.31.0 contain an information disclosure vulnerability in the RDPGFX server's ResetGraphics PDU serializer that fails to initialize padding bytes in the fixed 340-byte wire format. Attackers can receive...

3 affected packages

freerdp, freerdp2, freerdp3

Package 20.04 LTS
freerdp
freerdp2 Needs evaluation
freerdp3
Show less packages

CVE-2026-91945

Medium priority
Needs evaluation

FreeRDP versions before 3.31.0 contain an out-of-bounds read vulnerability in smartcard response decoders that fail to validate ATR length fields against fixed inline arrays. Authenticated RDP clients can send oversized ATR...

3 affected packages

freerdp, freerdp2, freerdp3

Package 20.04 LTS
freerdp
freerdp2 Needs evaluation
freerdp3
Show less packages

CVE-2026-85013

Medium priority
Needs evaluation

A flaw was found in environment-modules. A local attacker can exploit this vulnerability by placing a maliciously named modulefile in a location visible to the victim's `MODULEPATH`. When the victim uses Bash completion for...

1 affected package

modules

Package 20.04 LTS
modules Needs evaluation
Show less packages

CVE-2024-58384

Medium priority
Needs evaluation

Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers. Attackers can inject CRLF sequences into header values to inject...

1 affected package

python-tornado

Package 20.04 LTS
python-tornado Needs evaluation
Show less packages

CVE-2024-14029

Medium priority
Needs evaluation

Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body and parsing the chunked body as a subsequent request. Attackers can exploit this inconsistency when Tornado is...

1 affected package

python-tornado

Package 20.04 LTS
python-tornado Needs evaluation
Show less packages

CVE-2023-54397

Medium priority
Needs evaluation

Tornado before 6.3.3 contains an HTTP request smuggling vulnerability due to improper parsing of Content-Length headers accepting non-standard characters. Attackers can send crafted HTTP requests with these characters to bypass...

1 affected package

python-tornado

Package 20.04 LTS
python-tornado Needs evaluation
Show less packages

CVE-2026-92079

Medium priority
Ignored

Mitigation bypass in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 20.04 LTS
firefox
thunderbird
mozjs38
mozjs52 Ignored
mozjs68 Ignored
mozjs78
mozjs91
mozjs102
mozjs115
Show all 9 packages Show less packages

CVE-2026-92078

Medium priority
Ignored

Denial-of-service in the Security component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 20.04 LTS
firefox
thunderbird
mozjs38
mozjs52 Ignored
mozjs68 Ignored
mozjs78
mozjs91
mozjs102
mozjs115
Show all 9 packages Show less packages

CVE-2026-92077

Medium priority
Ignored

Denial-of-service in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 20.04 LTS
firefox
thunderbird
mozjs38
mozjs52 Ignored
mozjs68 Ignored
mozjs78
mozjs91
mozjs102
mozjs115
Show all 9 packages Show less packages