Search CVE reports


Toggle filters

931 – 940 of 56918 results

Status is adjusted based on your filters.


CVE-2026-19685

Medium priority
Needs evaluation

NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private...

1 affected package

network-manager

Package 16.04 LTS
network-manager Needs evaluation
Show less packages

CVE-2026-65053

Medium priority
Needs evaluation

Horde IMP's AppleDouble MIME viewer writes an attacker-controlled attachment name into an HTML status block without escaping it. In lib/Mime/Viewer/Appledouble.php, _IMPrender() obtains the name of the data part with...

1 affected package

php-horde-imp

Package 16.04 LTS
php-horde-imp Needs evaluation
Show less packages

CVE-2026-78376

Medium priority
Ignored

A flaw was found in WebKitGTK. Processing malicious web content can cause a use-after-free issue due to improper memory handling and result in memory corruption.

5 affected packages

webkitgtk, webkit2gtk, qtwebkit-source, qtwebkit-opensource-src, wpewebkit

Package 16.04 LTS
webkitgtk Ignored
webkit2gtk Ignored
qtwebkit-source Ignored
qtwebkit-opensource-src Ignored
wpewebkit
Show less packages

CVE-2026-78367

Medium priority
Needs evaluation

A vulnerability was found in RPM's rpmbuild tarball processing. When processing a crafted source archive, the getTarSpec() function in tools/rpmbuild.cc passes an attacker-controlled tar archive member name to rpmExpand() as part...

1 affected package

rpm

Package 16.04 LTS
rpm Needs evaluation
Show less packages

CVE-2026-78323

Medium priority
Needs evaluation

A flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trust flags when validating CA certificates, allowing certificates present in the NSS database without TRUSTED_CA flags to be accepted...

1 affected package

jss

Package 16.04 LTS
jss Needs evaluation
Show less packages

CVE-2026-10618

Medium priority
Needs evaluation

Hugo's default fenced-code-block renderer writes attribute values taken from the code-fence info string into the rendered HTML without escaping them. New in markup/internal/attributes/attributes.go converts every attribute value...

1 affected package

hugo

Package 16.04 LTS
hugo Needs evaluation
Show less packages

CVE-2026-10582

Medium priority
Needs evaluation

Hugo's security.http.urls allowlist is the only control on outbound fetches made by resources.GetRemote, and it inspects the URL text alone. CheckAllowedHTTPURL in config/security/securityConfig.go applies the configured pattern...

1 affected package

hugo

Package 16.04 LTS
hugo Needs evaluation
Show less packages

CVE-2026-66897

Medium priority
Needs evaluation

A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root. When...

1 affected package

lxd

Package 16.04 LTS
lxd Needs evaluation
Show less packages

CVE-2026-78161

Medium priority
Needs evaluation

A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted is the function report_raw_cbor of the file lib/misc/lecp.c of the component LECP CBOR Recording. The manipulation results in out-of-bounds write. The attack can...

1 affected package

libwebsockets

Package 16.04 LTS
libwebsockets Needs evaluation
Show less packages

CVE-2026-78183

Medium priority
Needs evaluation

DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float. quote_float() allocates the length of the string + 1, which is the size of the bare numeric symbol plus NULL. But for special literals NaN, Inf, +Inf,...

1 affected package

libdbd-pg-perl

Package 16.04 LTS
libdbd-pg-perl Needs evaluation
Show less packages