Search CVE reports


Toggle filters

1821 – 1830 of 57535 results

Status is adjusted based on your filters.


CVE-2026-49825

Medium priority
Needs evaluation

lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in...

1 affected package

lxml

Package 16.04 LTS
lxml Needs evaluation
Show less packages

CVE-2026-77118

Medium priority
Needs evaluation

A heap out-of-bounds write exists in the Photo CD (PCD) decoder of GraphicsMagick. In DecodeImage() (coders/pcd.c), the Huffman delta loop advances its output pointer with q++ after every decoded delta and never checks it against...

1 affected package

graphicsmagick

Package 16.04 LTS
graphicsmagick Needs evaluation
Show less packages

CVE-2026-7485

Medium priority
Needs evaluation

Incorrect authorization in frozen BI aggregations in Checkmk <2.5.0p2, <2.4.0p29, <2.3.0p47, and all 2.2.0 versions allows an authenticated user with restricted host and service visibility to learn the names and the existence of...

1 affected package

check-mk

Package 16.04 LTS
check-mk Needs evaluation
Show less packages

CVE-2026-73198

Medium priority
Needs evaluation

A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages` endpoint by sending an arbitrarily large request body. This can cause the service to consume excessive memory,...

1 affected package

freeipa

Package 16.04 LTS
freeipa Needs evaluation
Show less packages

CVE-2026-73197

Medium priority
Needs evaluation

A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the `/ipa/migration/migration.py` endpoint. This can force the migration handler to read...

1 affected package

freeipa

Package 16.04 LTS
freeipa Needs evaluation
Show less packages

CVE-2026-73196

Medium priority
Needs evaluation

A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by submitting an oversized One-Time Password (OTP) key value. This oversized key is then decoded and re-encoded without proper size...

1 affected package

freeipa

Package 16.04 LTS
freeipa Needs evaluation
Show less packages

CVE-2026-13097

Medium priority
Needs evaluation

A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the...

1 affected package

freeipa

Package 16.04 LTS
freeipa Needs evaluation
Show less packages

CVE-2026-11861

Medium priority
Needs evaluation

A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP...

1 affected package

freeipa

Package 16.04 LTS
freeipa Needs evaluation
Show less packages

CVE-2026-18917

Medium priority
Needs evaluation

A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This flaw allows crafted values to bypass a size check, leading to an undersized memory...

2 affected packages

libvirt, libvirt-hwe

Package 16.04 LTS
libvirt Needs evaluation
libvirt-hwe
Show less packages

CVE-2026-77014

Medium priority
Needs evaluation

A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c truncates a 64-bit subtraction result to 32-bit int, flipping the sign for range offsets differing by...

2 affected packages

libsoup2.4, libsoup3

Package 16.04 LTS
libsoup2.4 Needs evaluation
libsoup3
Show less packages