Search CVE reports


Toggle filters

151 – 160 of 32556 results

Status is adjusted based on your filters.


CVE-2026-3284

Medium priority
Needs evaluation

A vulnerability was found in libvips 8.19.0. Impacted is the function vips_extract_area_build of the file libvips/conversion/extract.c. The manipulation of the argument extract_area results in integer overflow. The attack requires...

1 affected package

vips

Package 24.04 LTS
vips Needs evaluation
Show less packages

CVE-2026-3283

Medium priority
Needs evaluation

A vulnerability has been found in libvips 8.19.0. This issue affects the function vips_extract_band_build of the file libvips/conversion/extract.c. The manipulation of the argument extract_band leads to out-of-bounds read. The...

1 affected package

vips

Package 24.04 LTS
vips Needs evaluation
Show less packages

CVE-2026-3282

Medium priority
Needs evaluation

A flaw has been found in libvips 8.19.0. This vulnerability affects the function vips_unpremultiply_build of the file libvips/conversion/unpremultiply.c. Executing a manipulation of the argument alpha_band can lead to...

1 affected package

vips

Package 24.04 LTS
vips Needs evaluation
Show less packages

CVE-2026-3281

Medium priority
Needs evaluation

A vulnerability was detected in libvips 8.19.0. This affects the function vips_bandrank_build of the file libvips/conversion/bandrank.c. Performing a manipulation of the argument index results in heap-based buffer overflow. The...

1 affected package

vips

Package 24.04 LTS
vips Needs evaluation
Show less packages

CVE-2026-28372

Medium priority
Vulnerable

telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service credentials support added to the login(1) implementation of util-linux in release 2.40. This is related to client...

1 affected package

inetutils

Package 24.04 LTS
inetutils Vulnerable
Show less packages

CVE-2026-28370

Medium priority
Needs evaluation

In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage API may trigger code execution on the Vitrage service host as the user the Vitrage service runs under. This...

1 affected package

vitrage

Package 24.04 LTS
vitrage Needs evaluation
Show less packages

CVE-2026-28364

Medium priority
Needs evaluation

In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds validation...

1 affected package

ocaml

Package 24.04 LTS
ocaml Needs evaluation
Show less packages

CVE-2025-40932

Medium priority
Needs evaluation

Apache::SessionX versions through 2.01 for Perl create insecure session id. Apache::SessionX generates session ids insecurely. The default session id generator in Apache::SessionX::Generate::MD5 returns a MD5 hash seeded with the...

1 affected package

libapache-sessionx-perl

Package 24.04 LTS
libapache-sessionx-perl Needs evaluation
Show less packages

CVE-2021-4456

Medium priority
Needs evaluation

Net::CIDR versions before 0.24 for Perl mishandle leading zeros in IP CIDR addresses, which may have unspecified impact. The functions `addr2cidr` and `cidrlookup` may return leading zeros in a CIDR string, which may in turn be...

1 affected package

libnet-cidr-perl

Package 24.04 LTS
libnet-cidr-perl Needs evaluation
Show less packages

CVE-2026-22206

Medium priority
Needs evaluation

SPIP versions prior to 4.4.10 contain a SQL injection vulnerability that allows authenticated low-privilege users to execute arbitrary SQL queries by manipulating union-based injection techniques. Attackers can exploit this SQL...

1 affected package

spip

Package 24.04 LTS
spip Needs evaluation
Show less packages