Search CVE reports


Toggle filters

481 – 490 of 48457 results

Status is adjusted based on your filters.


CVE-2026-90816

Medium priority
Needs evaluation

A vulnerability was found in FFmpeg 8.0.x. This affects the function parse_playlist of the file libavformat/hlsproto.c of the component Duration Parser. Performing a manipulation of the argument duration/target_duration results in...

2 affected packages

ffmpeg, libav

Package 20.04 LTS
ffmpeg Needs evaluation
libav
Show less packages

CVE-2026-90815

Medium priority
Needs evaluation

A vulnerability has been found in FFmpeg up to 4.4.6/5.1.8/6.1.4/7.1.3/8.0.1. Affected by this issue is the function setup_3x3 of the file libavfilter/vf_convolution.c of the component Convolution Filter. Such manipulation leads...

2 affected packages

ffmpeg, libav

Package 20.04 LTS
ffmpeg Needs evaluation
libav
Show less packages

CVE-2026-54559

Medium priority
Needs evaluation

PocketSphinx is a small speech recognizer. Prior to 5.1.1, the trie language-model loaders in src/lm/ngram_model_trie.c do not adequately validate boundary conditions in ARPA, DMP, and binary format headers, and the acoustic-model...

1 affected package

pocketsphinx

Package 20.04 LTS
pocketsphinx Needs evaluation
Show less packages

CVE-2026-19816

Medium priority
Needs evaluation

A flaw was found in PackageKit. PackageKit skips the polkit authorization check for transactions carrying the SIMULATE (dry-run) flag. In the dnf5 backend, the RepoRemove handler ignores that contract and always executes the real...

1 affected package

packagekit

Package 20.04 LTS
packagekit Needs evaluation
Show less packages

CVE-2026-19624

Medium priority
Needs evaluation

A flaw was found in NetworkManager-l2tp. The plugin writes attacker-controlled VPN connection properties (vpn.data and vpn.secrets values) unescaped into a generated ipsec.conf file that pluto loads as root. A local unprivileged...

1 affected package

network-manager-l2tp

Package 20.04 LTS
network-manager-l2tp Needs evaluation
Show less packages

CVE-2026-82049

Medium priority
Needs evaluation

In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or...

12 affected packages

pypy3, python2.7, python3.4, python3.5, python3.6...

Package 20.04 LTS
pypy3 Needs evaluation
python2.7 Needs evaluation
python3.4
python3.5
python3.6
python3.7
python3.8 Needs evaluation
python3.9 Needs evaluation
python3.10
python3.11
python3.12
python3.14
Show all 12 packages Show less packages

CVE-2026-82035

Medium priority
Needs evaluation

PyMuPDF through 1.28.2, fixed in commit b2c8f3a, contains a path traversal vulnerability in the font branch of extract_objects() in src/__main__.py, where the output filename is constructed by joining a...

1 affected package

pymupdf

Package 20.04 LTS
pymupdf Needs evaluation
Show less packages

CVE-2026-55847

Medium priority
Needs evaluation

Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the ansi.js helper at allure-generator/src/main/javascript/helpers/ansi.js passes attacker-influenced statusMessage and...

1 affected package

allure

Package 20.04 LTS
allure Needs evaluation
Show less packages

CVE-2026-55846

Medium priority
Needs evaluation

Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the HTTP server started by allure serve and allure open uses URI.getPath() in Commands.setUpServer()...

1 affected package

allure

Package 20.04 LTS
allure Needs evaluation
Show less packages

CVE-2026-53495

Medium priority
Needs evaluation

containerd is an open-source container runtime. Prior to 1.7.35, 2.0.12, 2.2.8, and 2.3.5, containerd on Linux with the CRI plugin enabled can indefinitely block the drainExecSyncIO goroutine...

3 affected packages

containerd, containerd-app, containerd-stable

Package 20.04 LTS
containerd Needs evaluation
containerd-app Needs evaluation
containerd-stable
Show less packages