Search CVE reports
1831 – 1840 of 57535 results
libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.
23 affected packages
expat, apache2, apr-util, cmake, ghostscript...
| Package | 16.04 LTS |
|---|---|
| expat | Vulnerable |
| apache2 | Not affected |
| apr-util | Not affected |
| cmake | Not affected |
| ghostscript | Not affected |
| texlive-bin | Not affected |
| xmlrpc-c | Needs evaluation |
| vnc4 | Needs evaluation |
| wbxml2 | Needs evaluation |
| swish-e | Needs evaluation |
| insighttoolkit4 | Needs evaluation |
| cadaver | Needs evaluation |
| gdcm | Needs evaluation |
| ayttm | Needs evaluation |
| cableswig | Needs evaluation |
| coin3 | Needs evaluation |
| matanza | Needs evaluation |
| tdom | Needs evaluation |
| vtk | Needs evaluation |
| smart | Needs evaluation |
| firefox | — |
| thunderbird | — |
| libxmltok | Needs evaluation |
In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content.
23 affected packages
expat, apache2, apr-util, cmake, ghostscript...
| Package | 16.04 LTS |
|---|---|
| expat | Not affected |
| apache2 | Not affected |
| apr-util | Not affected |
| cmake | Not affected |
| ghostscript | Not affected |
| texlive-bin | Not affected |
| xmlrpc-c | Needs evaluation |
| vnc4 | Needs evaluation |
| wbxml2 | Needs evaluation |
| swish-e | Needs evaluation |
| insighttoolkit4 | Needs evaluation |
| cadaver | Needs evaluation |
| gdcm | Needs evaluation |
| ayttm | Needs evaluation |
| cableswig | Needs evaluation |
| coin3 | Needs evaluation |
| matanza | Needs evaluation |
| tdom | Needs evaluation |
| vtk | Needs evaluation |
| smart | Needs evaluation |
| firefox | — |
| thunderbird | — |
| libxmltok | Needs evaluation |
Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is false due to upstream security policy.
1 affected package
binutils
| Package | 16.04 LTS |
|---|---|
| binutils | Not affected |
A flaw has been found in mruby 3.1.0. Affected is the function udiv of the file bigint.c. Executing a manipulation can lead to floating point comparison with incorrect operator. It is possible to launch the attack remotely. The...
1 affected package
mruby
| Package | 16.04 LTS |
|---|---|
| mruby | Needs evaluation |
[Unknown description]
1 affected package
libimager-perl
| Package | 16.04 LTS |
|---|---|
| libimager-perl | Needs evaluation |
[Unknown description]
1 affected package
libimager-perl
| Package | 16.04 LTS |
|---|---|
| libimager-perl | Needs evaluation |
Pcapng file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
1 affected package
wireshark
| Package | 16.04 LTS |
|---|---|
| wireshark | Needs evaluation |
X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
1 affected package
wireshark
| Package | 16.04 LTS |
|---|---|
| wireshark | Needs evaluation |
H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
1 affected package
wireshark
| Package | 16.04 LTS |
|---|---|
| wireshark | Needs evaluation |
BUSMASTER file parser abnormal exit in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
1 affected package
wireshark
| Package | 16.04 LTS |
|---|---|
| wireshark | Needs evaluation |