Search CVE reports


Toggle filters

2021 – 2030 of 58108 results

Status is adjusted based on your filters.


CVE-2026-19401

Medium priority
Needs evaluation

Any remote client can crash a (debugging/non-release build type) NSD serve child by sending it a special crafted message with a specially tuned number of DNS Cookie options (17 when UDP payload size is 512). By...

1 affected package

nsd

Package 16.04 LTS
nsd Needs evaluation
Show less packages

CVE-2026-19197

Medium priority
Needs evaluation

A user with organization administrator permissions can delete dashboard snapshots belonging to other organizations on the same Grafana instance, and can recover a snapshot's secret delete key using only its public share key...

1 affected package

grafana

Package 16.04 LTS
grafana Needs evaluation
Show less packages

CVE-2026-18916

Medium priority
Needs evaluation

Any remote client can crash a NSD serve child, by throttling the TCP receive window after a TCP query. By continuously crashing the serve childs, the remote client can denial all TCP service to this NSD instance.

1 affected package

nsd

Package 16.04 LTS
nsd Needs evaluation
Show less packages

CVE-2026-18664

Medium priority
Needs evaluation

When ranges are used for access control (i.e. of the form 1.2.3.4-1.2.3.25), because NSD wrongly compares the IP address with the range on little endian systems, IPs that were meant to be allowed may be denied, and, IPs that were...

1 affected package

nsd

Package 16.04 LTS
nsd Needs evaluation
Show less packages

CVE-2026-80186

Medium priority
Needs evaluation

A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer...

1 affected package

bluez

Package 16.04 LTS
bluez Needs evaluation
Show less packages

CVE-2026-80185

Medium priority
Needs evaluation

BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceRecord can corrupt the SDP XML parser stack so scalar union data is treated as a sequence...

1 affected package

bluez

Package 16.04 LTS
bluez Needs evaluation
Show less packages

CVE-2026-80184

Medium priority
Needs evaluation

In OpenStack Keystone before 29.0.3, tokens obtained via delegated authentication mechanisms (OAuth1 access tokens, application credentials, trusts) could be submitted to the token-method authentication path for reauthentication...

1 affected package

keystone

Package 16.04 LTS
keystone Needs evaluation
Show less packages

CVE-2026-80182

Medium priority
Needs evaluation

In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application credential, or trust-scoped authentication could create new long-lived credentials or authorize new delegations that persist independently...

1 affected package

keystone

Package 16.04 LTS
keystone Needs evaluation
Show less packages

CVE-2026-73180

Medium priority
Needs evaluation

Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session was changed after a WebSocket connection had been established under that authenticated HTTP session, the...

6 affected packages

tomcat6, tomcat7, tomcat8, tomcat9, tomcat10, tomcat11

Package 16.04 LTS
tomcat6 Not affected
tomcat7 Needs evaluation
tomcat8 Needs evaluation
tomcat9
tomcat10
tomcat11
Show less packages

CVE-2026-68763

Medium priority
Needs evaluation

Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking when a stream is reset This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through...

6 affected packages

tomcat6, tomcat7, tomcat8, tomcat9, tomcat10, tomcat11

Package 16.04 LTS
tomcat6 Not affected
tomcat7 Needs evaluation
tomcat8 Needs evaluation
tomcat9
tomcat10
tomcat11
Show less packages