Search CVE reports


Toggle filters

421 – 430 of 40627 results

Status is adjusted based on your filters.


CVE-2026-41069

Medium priority
Needs evaluation

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a malformed HEIF sequence file can trigger an out-of-bounds read in core sequence parsing logic, causing DoS. A malformed file can have...

1 affected package

libheif

Package 22.04 LTS
libheif Needs evaluation
Show less packages

CVE-2026-40864

Medium priority
Needs evaluation

JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. In versions 4.1.0 through 5.4.4, XSRF protection (updated in 4.1.0) inappropriately treated requests with Sec-Fetch-Mode: no-cors as...

1 affected package

jupyterhub

Package 22.04 LTS
jupyterhub Needs evaluation
Show less packages

CVE-2026-40295

Medium priority
Needs evaluation

Devise is an authentication solution for Rails based on Warden. In versions 5.0.3 and below, when the Timeoutable module is enabled in Devise, the FailureApp#redirect_url method returns request.referrer — the HTTP Referer header,...

1 affected package

ruby-devise

Package 22.04 LTS
ruby-devise Needs evaluation
Show less packages

CVE-2026-39824

Medium priority
Needs evaluation

NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum size of a NTUnicodeString (a 16-bit number of bytes), it returns a truncated string rather than an error.

2 affected packages

golang-golang-x-sys, google-guest-agent

Package 22.04 LTS
golang-golang-x-sys Needs evaluation
google-guest-agent Needs evaluation
Show less packages

CVE-2026-48700

Medium priority
Needs evaluation

An issue was discovered in all versions of PCManFM-Qt starting from 1.1.0. When a regular file's path is passed as a URI in an org.freedesktop.FileManager1.ShowFolders D-Bus method call, PCManFM-Qt delegates to a different program...

1 affected package

pcmanfm-qt

Package 22.04 LTS
pcmanfm-qt Needs evaluation
Show less packages

CVE-2026-46727

Medium priority
Needs evaluation

An issue was discovered in Ruby 4 before 4.0.5. A race condition leading to a use-after-free in the pthread-based getaddrinfo timeout handler (rb_getaddrinfo in ext/socket/raddrinfo.c) allows a remote attacker who can delay DNS...

7 affected packages

ruby2.3, ruby2.5, ruby2.7, ruby3.0, ruby3.2...

Package 22.04 LTS
ruby2.3 Not in release
ruby2.5 Not in release
ruby2.7 Not in release
ruby3.0 Needs evaluation
ruby3.2 Not in release
ruby3.3 Not in release
jruby Not in release
Show all 7 packages Show less packages

CVE-2026-42627

Medium priority
Needs evaluation

In Arm ArmNN through 2026-03-27, an integer overflow in TensorShape::GetNumElements() in armnn/Tensor.cpp allows a crafted TFLite model file to bypass buffer size validation and trigger a heap-based buffer over-read during model...

1 affected package

armnn

Package 22.04 LTS
armnn Needs evaluation
Show less packages

CVE-2026-42506

Medium priority

Not in release

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

1 affected package

golang-golang-x-net-dev

Package 22.04 LTS
golang-golang-x-net-dev Not in release
Show less packages

CVE-2026-42502

Medium priority

Not in release

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

1 affected package

golang-golang-x-net-dev

Package 22.04 LTS
golang-golang-x-net-dev Not in release
Show less packages

CVE-2026-39821

Medium priority

Not in release

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This...

1 affected package

golang-golang-x-net-dev

Package 22.04 LTS
golang-golang-x-net-dev Not in release
Show less packages