Search CVE reports


Toggle filters

581 – 590 of 48457 results

Status is adjusted based on your filters.


CVE-2026-90616

Medium priority
Needs evaluation

In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read and write access to files on the host, which can be escalated to arbitrary code execution on the host, a different vulnerability than CVE-2026-76925....

1 affected package

flatpak

Package 20.04 LTS
flatpak Needs evaluation
Show less packages

CVE-2026-90558

Medium priority
Needs evaluation

sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit. Attackers can craft malicious SIP packets with oversized...

1 affected package

sngrep

Package 20.04 LTS
sngrep Needs evaluation
Show less packages

CVE-2026-90557

Medium priority
Needs evaluation

Freeciv versions 3.1.0 through 3.2.5 contain an out-of-bounds read vulnerability in sg_load_player_unit() when processing savegame files with invalid unit activity indices. An attacker can craft a malicious savegame file with an...

1 affected package

freeciv

Package 20.04 LTS
freeciv Needs evaluation
Show less packages

CVE-2026-90556

Medium priority
Needs evaluation

Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceeding the fixed array bound of 64 elements. Attackers can craft malicious savegame...

1 affected package

freeciv

Package 20.04 LTS
freeciv Needs evaluation
Show less packages

CVE-2026-90473

Medium priority
Needs evaluation

msgpack-java through 0.9.12 contains an integer overflow vulnerability in MessageUnpacker.skipValue() when processing MAP32 containers with large element counts. Attackers can supply a MAP32 element count at or above 0x40000000...

1 affected package

msgpack-java

Package 20.04 LTS
msgpack-java Needs evaluation
Show less packages

CVE-2026-90472

Medium priority
Needs evaluation

msgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker.unpackValue() that recursively deserializes arrays and maps without nesting depth limits. Attackers can craft payloads with deeply nested...

1 affected package

msgpack-java

Package 20.04 LTS
msgpack-java Needs evaluation
Show less packages

CVE-2026-89266

Medium priority
Needs evaluation

stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int. Attackers can craft a malicious Ogg Vorbis file with large entries and...

1 affected package

libstb

Package 20.04 LTS
libstb Needs evaluation
Show less packages

CVE-2026-90461

Medium priority
Needs evaluation

OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.

1 affected package

ironic

Package 20.04 LTS
ironic Needs evaluation
Show less packages

CVE-2026-90460

Medium priority
Needs evaluation

An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via delegated authentication methods (EC2 credentials, application credentials, OAuth1 access tokens, and trusts) are not blocked from creating,...

1 affected package

keystone

Package 20.04 LTS
keystone Needs evaluation
Show less packages

CVE-2026-54258

Medium priority
Needs evaluation

ZoneMinder is a free, open source closed-circuit television software application. Versions prior to 1.36.39, 1.38.4, and 1.39.11 allow an authenticated low-privileged user with coarse `Events=View` and/or `Snapshots=View`...

1 affected package

zoneminder

Package 20.04 LTS
zoneminder Needs evaluation
Show less packages