Search CVE reports


Toggle filters

791 – 800 of 44358 results

Status is adjusted based on your filters.


CVE-2026-66374

Medium priority
Needs evaluation

Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path.

1 affected package

knot-resolver

Package 20.04 LTS
knot-resolver Needs evaluation
Show less packages

CVE-2026-66373

Medium priority
Needs evaluation

Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because...

1 affected package

redis

Package 20.04 LTS
redis Needs evaluation
Show less packages

CVE-2026-66339

Medium priority
Needs evaluation

A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header to subsequent HTTPS requests sent through that tunnel to the destination server....

2 affected packages

libsoup2.4, libsoup3

Package 20.04 LTS
libsoup2.4 Needs evaluation
libsoup3
Show less packages

CVE-2026-66338

Medium priority
Needs evaluation

A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk sizes that silently accepts inputs violating RFC 9112, including leading whitespace, plus sign prefixes, and trailing...

2 affected packages

libsoup2.4, libsoup3

Package 20.04 LTS
libsoup2.4 Needs evaluation
libsoup3
Show less packages

CVE-2026-66337

Medium priority
Needs evaluation

A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes a heap buffer over-read when parsing multipart HTTP responses. A malicious HTTP server can exploit this by...

2 affected packages

libsoup2.4, libsoup3

Package 20.04 LTS
libsoup2.4 Needs evaluation
libsoup3
Show less packages

CVE-2025-71408

Medium priority
Needs evaluation

NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to execute arbitrary Python code. When...

1 affected package

nltk

Package 20.04 LTS
nltk Needs evaluation
Show less packages

CVE-2026-66041

Medium priority
Not affected

FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc filter that allows an attacker to corrupt heap memory by supplying a crafted PGS/SUP subtitle file with...

2 affected packages

ffmpeg, libav

Package 20.04 LTS
ffmpeg Not affected
libav
Show less packages

CVE-2026-66040

Medium priority
Needs evaluation

FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a...

2 affected packages

ffmpeg, libav

Package 20.04 LTS
ffmpeg Needs evaluation
libav
Show less packages

CVE-2026-66039

Medium priority
Needs evaluation

FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a...

2 affected packages

ffmpeg, libav

Package 20.04 LTS
ffmpeg Needs evaluation
libav
Show less packages

CVE-2026-66038

Medium priority
Needs evaluation

FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates...

2 affected packages

ffmpeg, libav

Package 20.04 LTS
ffmpeg Needs evaluation
libav
Show less packages