Search CVE reports


Toggle filters

91 – 100 of 36612 results

Status is adjusted based on your filters.


CVE-2026-28422

Medium priority
Needs evaluation

Vim is an open source, command line text editor. Prior to version 9.2.0078, a stack-buffer-overflow occurs in `build_stl_str_hl()` when rendering a statusline with a multi-byte fill character on a very wide terminal. Version...

1 affected package

vim

Package 22.04 LTS
vim Needs evaluation
Show less packages

CVE-2026-28421

Medium priority
Needs evaluation

Vim is an open source, command line text editor. Versions prior to 9.2.0077 have a heap-buffer-overflow and a segmentation fault (SEGV) exist in Vim's swap file recovery logic. Both are caused by unvalidated fields read...

1 affected package

vim

Package 22.04 LTS
vim Needs evaluation
Show less packages

CVE-2026-28420

Medium priority
Needs evaluation

Vim is an open source, command line text editor. Prior to version 9.2.0076, a heap-based buffer overflow WRITE and an out-of-bounds READ exist in Vim's terminal emulator when processing maximum combining characters from...

1 affected package

vim

Package 22.04 LTS
vim Needs evaluation
Show less packages

CVE-2026-28419

Medium priority
Needs evaluation

Vim is an open source, command line text editor. Prior to version 9.2.0075, a heap-based buffer underflow exists in Vim's Emacs-style tags file parsing logic. When processing a malformed tags file where a delimiter appears at the...

1 affected package

vim

Package 22.04 LTS
vim Needs evaluation
Show less packages

CVE-2026-28418

Medium priority
Needs evaluation

Vim is an open source, command line text editor. Prior to version 9.2.0074, a heap-based buffer overflow out-of-bounds read exists in Vim's Emacs-style tags file parsing logic. When processing a malformed tags file, Vim can...

1 affected package

vim

Package 22.04 LTS
vim Needs evaluation
Show less packages

CVE-2026-28417

Medium priority
Needs evaluation

Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists in the `netrw` standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using...

1 affected package

vim

Package 22.04 LTS
vim Needs evaluation
Show less packages

CVE-2026-28351

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.4, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires parsing the content stream using...

2 affected packages

pypdf, pypdf2

Package 22.04 LTS
pypdf Not in release
pypdf2 Needs evaluation
Show less packages

CVE-2026-27824

Medium priority
Needs evaluation

calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.4.0, the calibre Content Server's brute-force protection mechanism uses a ban key derived from both...

1 affected package

calibre

Package 22.04 LTS
calibre Needs evaluation
Show less packages

CVE-2026-27810

Medium priority
Needs evaluation

calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.4.0, an HTTP Response Header Injection vulnerability in the calibre Content Server allows any authenticated...

1 affected package

calibre

Package 22.04 LTS
calibre Needs evaluation
Show less packages

CVE-2025-10990

Medium priority
Vulnerable

A flaw was found in REXML. A remote attacker could exploit inefficient regular expression (regex) parsing when processing hex numeric character references (&#x...;) in XML documents. This could lead to a Regular Expression Denial...

7 affected packages

ruby2.3, ruby2.5, ruby2.7, ruby3.0, ruby3.2...

Package 22.04 LTS
ruby2.3 Not in release
ruby2.5 Not in release
ruby2.7 Not in release
ruby3.0 Vulnerable
ruby3.2 Not in release
ruby3.3 Not in release
jruby Not in release
Show all 7 packages Show less packages