Search CVE reports


Toggle filters

61 – 70 of 48501 results

Status is adjusted based on your filters.


CVE-2026-40025

Medium priority
Needs evaluation

The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the APFS filesystem keybag parser where the wrapped_key_parser class follows attacker-controlled length fields without bounds checking, causing heap...

1 affected package

sleuthkit

Package 16.04 LTS
sleuthkit Needs evaluation
Show less packages

CVE-2026-40024

Medium priority
Needs evaluation

The Sleuth Kit through 4.14.0 contains a path traversal vulnerability in tsk_recover that allows an attacker to write files to arbitrary locations outside the intended recovery directory via crafted filenames or directory paths...

1 affected package

sleuthkit

Package 16.04 LTS
sleuthkit Needs evaluation
Show less packages

CVE-2026-39892

Medium priority
Not affected

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g....

1 affected package

python-cryptography

Package 16.04 LTS
python-cryptography Not affected
Show less packages

CVE-2026-39864

Medium priority
Needs evaluation

Kamailio is an open source implementation of a SIP Signaling Server. Prior to 6.0.5 and 5.8.7, an out-of-bounds read in the auth module of Kamailio (formerly OpenSER and SER) allows remote attackers to cause a denial of service...

1 affected package

kamailio

Package 16.04 LTS
kamailio Needs evaluation
Show less packages

CVE-2026-39863

Medium priority
Needs evaluation

Kamailio is an open source implementation of a SIP Signaling Server. Prior to 6.1.1, 6.0.6, and 5.8.8, an out-of-bounds access in the core of Kamailio (formerly OpenSER and SER) allows remote attackers to cause a denial of service...

1 affected package

kamailio

Package 16.04 LTS
kamailio Needs evaluation
Show less packages

CVE-2026-34757

Medium priority
Needs evaluation

[Use-after-free in `png_set_PLTE`, `png_set_tRNS` and `png_set_hIST` leading to corrupted chunk data and potential heap information disclosure]

5 affected packages

libpng, libpng1.6, firefox, thunderbird, chromium-browser

Package 16.04 LTS
libpng Needs evaluation
libpng1.6 Needs evaluation
firefox
thunderbird
chromium-browser
Show less packages

CVE-2026-2619

Medium priority
Ignored

GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that under certain circumstances could have allowed an authenticated user with...

1 affected package

gitlab

Package 16.04 LTS
gitlab Ignored
Show less packages

CVE-2026-2104

Medium priority
Ignored

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user to access confidential issues assigned to...

1 affected package

gitlab

Package 16.04 LTS
gitlab Ignored
Show less packages

CVE-2026-1752

Medium priority
Ignored

GitLab has remediated an issue in GitLab EE affecting all versions from 11.3 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user with developer-role permissions to modify...

1 affected package

gitlab

Package 16.04 LTS
gitlab Ignored
Show less packages

CVE-2026-1516

Medium priority
Ignored

GitLab has remediated an issue in GitLab EE affecting all versions from 18.0.0 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that in Code Quality reports could have allowed an authenticated user to leak IP addresses...

1 affected package

gitlab

Package 16.04 LTS
gitlab Ignored
Show less packages