Search CVE reports


Toggle filters

301 – 310 of 42497 results

Status is adjusted based on your filters.


CVE-2026-55767

Medium priority

Not in release

Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, CookieJar incorrectly accepts cookies with a dot-only Domain attribute and whitespace-padded variants. SetCookie::matchesDomain() removes leading dots from the cookie...

1 affected package

guzzle

Package 22.04 LTS
guzzle Not in release
Show less packages

CVE-2026-55766

Medium priority
Needs evaluation

guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.1, guzzlehttp/psr7 did not reject CR/LF characters in certain first-party HTTP start-line fields: the request method, protocol version, and...

1 affected package

php-guzzlehttp-psr7

Package 22.04 LTS
php-guzzlehttp-psr7 Needs evaluation
Show less packages

CVE-2026-55568

Medium priority

Not in release

Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, in certain configurations, traffic expected to be protected by TLS on the hop to the proxy is transmitted in cleartext. Proxy authentication credentials...

1 affected package

guzzle

Package 22.04 LTS
guzzle Not in release
Show less packages

CVE-2025-55639

Medium priority
Needs evaluation

GPAC MP4Box v2.4 was discovered to contain a NULL pointer dereference in the gf_isom_add_track_kind() function at isomedia/isom_write.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.

1 affected package

gpac

Package 22.04 LTS
gpac Needs evaluation
Show less packages

CVE-2026-12969

Medium priority
Needs evaluation

An out-of-bounds read vulnerability exists in dnsmasq's find_soa() function in src/rfc1035.c. When parsing NS section records, extract_name() is called with extrabytes=0, failing to validate that 10 additional bytes exist...

1 affected package

dnsmasq

Package 22.04 LTS
dnsmasq Needs evaluation
Show less packages

CVE-2026-56379

Medium priority
Needs evaluation

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick...

1 affected package

imagemagick

Package 22.04 LTS
imagemagick Needs evaluation
Show less packages

CVE-2026-56376

Medium priority
Needs evaluation

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a heap use-after-free in the meta coder: when memory allocation fails, a single byte is written to a stale pointer. Remote attackers can trigger it by processing specially crafted...

1 affected package

imagemagick

Package 22.04 LTS
imagemagick Needs evaluation
Show less packages

CVE-2026-56371

Medium priority
Needs evaluation

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a memory leak in coders/txt.c when processing TXT files with texture attributes: the texture object allocated via ReadImage is not released when GetTypeMetrics fails, leaking...

1 affected package

imagemagick

Package 22.04 LTS
imagemagick Needs evaluation
Show less packages

CVE-2026-55655

Medium priority
Needs evaluation

A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is...

2 affected packages

openssh, openssh-ssh1

Package 22.04 LTS
openssh Needs evaluation
openssh-ssh1 Ignored
Show less packages

CVE-2026-55654

Medium priority
Needs evaluation

A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in...

2 affected packages

openssh, openssh-ssh1

Package 22.04 LTS
openssh Needs evaluation
openssh-ssh1 Ignored
Show less packages