Search CVE reports


Toggle filters

281 – 290 of 42497 results

Status is adjusted based on your filters.


CVE-2025-61024

Medium priority
Needs evaluation

An issue in the sqlo_try_in_loop component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

1 affected package

virtuoso-opensource

Package 22.04 LTS
virtuoso-opensource Needs evaluation
Show less packages

CVE-2026-56968

Medium priority
Needs evaluation

GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.

1 affected package

gsasl

Package 22.04 LTS
gsasl Needs evaluation
Show less packages

CVE-2026-56117

Medium priority

Not in release

dhcpcd through 10.3.2, fixed in commit 78ea09e, contains a heap use-after-free vulnerability in the control socket handling within src/control.c that allows local unprivileged attackers to trigger memory corruption when privilege...

1 affected package

dhcpcd

Package 22.04 LTS
dhcpcd Not in release
Show less packages

CVE-2026-56116

Medium priority

Not in release

dhcpcd through 10.3.2, fixed in commit 708b4a5, contains a memory leak vulnerability in the IPv6 Router Advertisement route information handling that allows an unauthenticated same-link attacker to cause denial of service by...

1 affected package

dhcpcd

Package 22.04 LTS
dhcpcd Not in release
Show less packages

CVE-2026-56115

Medium priority

Not in release

dhcpcd through 10.3.2, fixed in commit 2f00c7b, contains a one-byte stack out-of-bounds write vulnerability in dhcp6_makemessage() in src/dhcp6.c that allows unauthenticated same-link attackers to write beyond a fixed local buffer...

1 affected package

dhcpcd

Package 22.04 LTS
dhcpcd Not in release
Show less packages

CVE-2026-56114

Medium priority

Not in release

dhcpcd through 10.3.2, fixed in commit 2f00c7b, contains a one-byte stack out-of-bounds write vulnerability in dhcp6_makemessage() in src/dhcp6.c that allows unauthenticated same-link attackers to write beyond a fixed local buffer...

1 affected package

dhcpcd

Package 22.04 LTS
dhcpcd Not in release
Show less packages

CVE-2026-56113

Medium priority

Not in release

dhcpcd through 10.3.2, fixed in commit 5733d3c, contains a heap use-after-free vulnerability that allows unauthenticated same-link attackers to crash the daemon by sending a crafted DHCPv6 RENEW reply with RFC6603...

1 affected package

dhcpcd

Package 22.04 LTS
dhcpcd Not in release
Show less packages

CVE-2026-50574

Medium priority
Needs evaluation

yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, if aria2c is used as an external downloader for a fragmented manifest format (such as an HLS/DASH stream), yt-dlp passes insufficiently sanitized input to...

1 affected package

yt-dlp

Package 22.04 LTS
yt-dlp Needs evaluation
Show less packages

CVE-2026-50023

Medium priority
Needs evaluation

yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, a vulnerability exists in yt-dlp that allows a remote attacker to write arbitrary OS-shortcut files (such as .desktop, .url, .webloc) to the user's filesystem,...

1 affected package

yt-dlp

Package 22.04 LTS
yt-dlp Needs evaluation
Show less packages

CVE-2026-50019

Medium priority
Needs evaluation

yt-dlp is a command-line audio/video downloader. From 2023.09.24 until 2026.06.09, if curl is used as an external downloader for yt-dlp, cookies may be leaked to an unintended host upon HTTP redirect or when the host for download...

1 affected package

yt-dlp

Package 22.04 LTS
yt-dlp Needs evaluation
Show less packages