Search CVE reports


Toggle filters

851 – 860 of 48899 results

Status is adjusted based on your filters.


CVE-2026-33526

Medium priority
Needs evaluation

Squid is a caching proxy for the Web. Prior to version 7.5, due to heap Use-After-Free, Squid is vulnerable to Denial of Service when handling ICP traffic. This problem allows a remote attacker to perform a reliable and repeatable...

2 affected packages

squid, squid3

Package 16.04 LTS
squid
squid3 Needs evaluation
Show less packages

CVE-2026-33515

Medium priority
Needs evaluation

Squid is a caching proxy for the Web. Prior to version 7.5, due to improper input validation, Squid is vulnerable to out of bounds read when handling ICP traffic. This problem allows a remote attacker to receive small amounts of...

2 affected packages

squid, squid3

Package 16.04 LTS
squid
squid3 Needs evaluation
Show less packages

CVE-2026-32748

Medium priority
Needs evaluation

Squid is a caching proxy for the Web. Prior to version 7.5, due to premature release of resource during expected lifetime and heap Use-After-Free bugs, Squid is vulnerable to Denial of Service when handling ICP traffic. This...

2 affected packages

squid, squid3

Package 16.04 LTS
squid
squid3 Needs evaluation
Show less packages

CVE-2014-125112

Medium priority
Needs evaluation

Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution. Plack::Middleware::Session::Cookie versions through 0.21 has a security vulnerability where it allows an attacker to execute arbitrary...

1 affected package

libplack-middleware-session-perl

Package 16.04 LTS
libplack-middleware-session-perl Needs evaluation
Show less packages

CVE-2025-70888

Medium priority
Needs evaluation

An issue in mtrojnar Osslsigncode affected at v2.10 and before allows a remote attacker to escalate privileges via the osslsigncode.c component

1 affected package

osslsigncode

Package 16.04 LTS
osslsigncode Needs evaluation
Show less packages

CVE-2025-67030

Medium priority
Needs evaluation

Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code

1 affected package

plexus-utils

Package 16.04 LTS
plexus-utils Needs evaluation
Show less packages

CVE-2026-34085

Medium priority
Not affected

fontconfig before 2.17.1 has an off-by-one error in allocation during sfnt capability handling, leading to a one-byte out-of-bounds write, and potentially a crash or code execution. This is in FcFontCapabilities in fcfreetype.c.

1 affected package

fontconfig

Package 16.04 LTS
fontconfig Not affected
Show less packages

CVE-2026-2745

Medium priority
Ignored

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 7.11 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to bypass WebAuthn...

1 affected package

gitlab

Package 16.04 LTS
gitlab Ignored
Show less packages

CVE-2026-2726

Medium priority
Ignored

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to perform unauthorized actions on merge...

1 affected package

gitlab

Package 16.04 LTS
gitlab Ignored
Show less packages

CVE-2026-25645

Low priority
Needs evaluation

Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the...

2 affected packages

requests, python-pip

Package 16.04 LTS
requests Needs evaluation
python-pip Needs evaluation
Show less packages