Search CVE reports


Toggle filters

1171 – 1180 of 58662 results

Status is adjusted based on your filters.


CVE-2026-91948

Medium priority
Needs evaluation

FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in server-side static virtual channel handling when CHANNEL_OPTION_SHOW_PROTOCOL is enabled. Authenticated clients can queue oversized channel messages...

3 affected packages

freerdp, freerdp2, freerdp3

Package 16.04 LTS
freerdp Needs evaluation
freerdp2
freerdp3
Show less packages

CVE-2026-91947

Medium priority
Needs evaluation

FreeRDP server versions before 3.31.0 contain a use-after-free vulnerability in the DRDYNVC parser that dereferences a channel pointer after releasing the synchronization lock. Authenticated clients can race AUDIN channel closure...

3 affected packages

freerdp, freerdp2, freerdp3

Package 16.04 LTS
freerdp Needs evaluation
freerdp2
freerdp3
Show less packages

CVE-2026-91946

Medium priority
Needs evaluation

FreeRDP versions before 3.31.0 contain an information disclosure vulnerability in the RDPGFX server's ResetGraphics PDU serializer that fails to initialize padding bytes in the fixed 340-byte wire format. Attackers can receive...

3 affected packages

freerdp, freerdp2, freerdp3

Package 16.04 LTS
freerdp Needs evaluation
freerdp2
freerdp3
Show less packages

CVE-2026-91945

Medium priority
Needs evaluation

FreeRDP versions before 3.31.0 contain an out-of-bounds read vulnerability in smartcard response decoders that fail to validate ATR length fields against fixed inline arrays. Authenticated RDP clients can send oversized ATR...

3 affected packages

freerdp, freerdp2, freerdp3

Package 16.04 LTS
freerdp Needs evaluation
freerdp2
freerdp3
Show less packages

CVE-2026-85013

Medium priority
Needs evaluation

A flaw was found in environment-modules. A local attacker can exploit this vulnerability by placing a maliciously named modulefile in a location visible to the victim's `MODULEPATH`. When the victim uses Bash completion for...

1 affected package

modules

Package 16.04 LTS
modules Needs evaluation
Show less packages

CVE-2024-58384

Medium priority
Needs evaluation

Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers. Attackers can inject CRLF sequences into header values to inject...

1 affected package

python-tornado

Package 16.04 LTS
python-tornado Needs evaluation
Show less packages

CVE-2024-14029

Medium priority
Needs evaluation

Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body and parsing the chunked body as a subsequent request. Attackers can exploit this inconsistency when Tornado is...

1 affected package

python-tornado

Package 16.04 LTS
python-tornado Needs evaluation
Show less packages

CVE-2023-54397

Medium priority
Needs evaluation

Tornado before 6.3.3 contains an HTTP request smuggling vulnerability due to improper parsing of Content-Length headers accepting non-standard characters. Attackers can send crafted HTTP requests with these characters to bypass...

1 affected package

python-tornado

Package 16.04 LTS
python-tornado Needs evaluation
Show less packages

CVE-2026-91926

Medium priority
Needs evaluation

A flaw was found in gss-ntlmssp. A memory leak occurs in the NTLM target-info parser when a crafted NTLM CHALLENGE message contains duplicated string-valued AV_PAIR entries. The parser allocates memory for each string value but...

1 affected package

gss-ntlmssp

Package 16.04 LTS
gss-ntlmssp Needs evaluation
Show less packages

CVE-2026-62379

Medium priority
Needs evaluation

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /authservice PLL endpoint accepts a CustomCallback XML element whose className value selects an arbitrary Java class for...

1 affected package

openam

Package 16.04 LTS
openam Needs evaluation
Show less packages