Search CVE reports


Toggle filters

151 – 160 of 41037 results

Status is adjusted based on your filters.


CVE-2026-45149

Medium priority
Needs evaluation

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. From 5.0.0 to before 5.0.6, the max option was being applied too late. When expanding a single large numeric range like {1..10000000},...

1 affected package

node-brace-expansion

Package 20.04 LTS
node-brace-expansion Needs evaluation
Show less packages

CVE-2026-44422

Medium priority
Needs evaluation

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's RDPEAR NDR parser accepts one non-null NDR pointer ref-id for multiple logical pointer fields without tracking the pointed...

3 affected packages

freerdp, freerdp2, freerdp3

Package 20.04 LTS
freerdp
freerdp2 Needs evaluation
freerdp3
Show less packages

CVE-2026-44421

Medium priority
Needs evaluation

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client by sending crafted RDPGFX PDUs. The bug is...

3 affected packages

freerdp, freerdp2, freerdp3

Package 20.04 LTS
freerdp
freerdp2 Needs evaluation
freerdp3
Show less packages

CVE-2026-44420

Medium priority
Needs evaluation

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a heap-buffer-overflow write in FreeRDP's server-side clipboard (cliprdr) channel by sending a CB_CLIP_CAPS PDU...

3 affected packages

freerdp, freerdp2, freerdp3

Package 20.04 LTS
freerdp
freerdp2 Needs evaluation
freerdp3
Show less packages

CVE-2026-42500

Medium priority
Needs evaluation

Decoding a paletted BMP file with an out-of-range palette index results in a panic when accessing pixels in the invalid image.

1 affected package

golang-golang-x-image

Package 20.04 LTS
golang-golang-x-image Needs evaluation
Show less packages

CVE-2026-48840

Medium priority
Fixed

Exim 4.88 before 4.99.4, in some proxy configurations, mishandles certain short payloads, leading to disclosure of uninitialized stack memory values to a client.

1 affected package

exim4

Package 20.04 LTS
exim4 Fixed
Show less packages

CVE-2026-6324

Medium priority
Needs evaluation

A flaw was found in libsoup. A remote attacker could exploit an unsigned to signed conversion error in the `soup_body_input_stream_read_chunked()` function by sending a malicious HTTP request. This vulnerability occurs when...

2 affected packages

libsoup2.4, libsoup3

Package 20.04 LTS
libsoup2.4 Needs evaluation
libsoup3
Show less packages

CVE-2026-49214

Medium priority
Needs evaluation

[Unknown description]

1 affected package

php-guzzlehttp-psr7

Package 20.04 LTS
php-guzzlehttp-psr7 Needs evaluation
Show less packages

CVE-2026-48998

Medium priority
Needs evaluation

[Unknown description]

1 affected package

php-guzzlehttp-psr7

Package 20.04 LTS
php-guzzlehttp-psr7 Needs evaluation
Show less packages

CVE-2026-48863

Medium priority
Needs evaluation

[Unknown description]

1 affected package

libsolv

Package 20.04 LTS
libsolv Needs evaluation
Show less packages