Search CVE reports


Toggle filters

2461 – 2470 of 39365 results

Status is adjusted based on your filters.


CVE-2026-32945

Medium priority

Not in release

PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below have a Heap-based Buffer Overflowvulnerability in the DNS parser's name length handler. Thisimpacts applications using PJSIP's...

1 affected package

pjproject

Package 22.04 LTS
pjproject Not in release
Show less packages

CVE-2026-32942

Medium priority

Not in release

PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below contain a heap use-after-free vulnerability in the ICE session that occurs when there are race conditions between...

1 affected package

pjproject

Package 22.04 LTS
pjproject Not in release
Show less packages

CVE-2026-32711

Medium priority
Needs evaluation

pydicom is a pure Python package for working with DICOM files. Versions 2.0.0-rc.1 through 3.0.1 are vulnerable to Path Traversal through a maliciously crafted DICOMDIR ReferencedFileID when it is set to a path outside the...

1 affected package

pydicom

Package 22.04 LTS
pydicom Needs evaluation
Show less packages

CVE-2026-32829

Medium priority

Not in release

lz4_flex is a pure Rust implementation of LZ4 compression/decompression. In versions 0.11.5 and below, and 0.12.0, decompressing invalid LZ4 data can leak sensitive information from uninitialized memory or from...

1 affected package

rust-lz4-flex

Package 22.04 LTS
rust-lz4-flex Not in release
Show less packages

CVE-2026-22737

Medium priority
Needs evaluation

Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This...

1 affected package

libspring-java

Package 22.04 LTS
libspring-java Needs evaluation
Show less packages

CVE-2026-22735

Medium priority
Needs evaluation

Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25,...

1 affected package

libspring-java

Package 22.04 LTS
libspring-java Needs evaluation
Show less packages

CVE-2026-4464

Medium priority
Not affected

Integer overflow in ANGLE in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

1 affected package

chromium-browser

Package 22.04 LTS
chromium-browser Not affected
Show less packages

CVE-2026-4463

Medium priority
Not affected

Heap buffer overflow in WebRTC in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

1 affected package

chromium-browser

Package 22.04 LTS
chromium-browser Not affected
Show less packages

CVE-2026-4462

Medium priority
Not affected

Out of bounds read in Blink in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

1 affected package

chromium-browser

Package 22.04 LTS
chromium-browser Not affected
Show less packages

CVE-2026-4461

Medium priority
Not affected

Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

1 affected package

chromium-browser

Package 22.04 LTS
chromium-browser Not affected
Show less packages