Search CVE reports


Toggle filters

611 – 620 of 36525 results

Status is adjusted based on your filters.


CVE-2026-3593

Medium priority
Not affected

A use-after-free vulnerability exists within the DNS-over-HTTPS implementation. This issue affects BIND 9 versions 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, and 9.20.9-S1 through 9.20.22-S1. BIND 9 versions 9.18.0 through...

3 affected packages

isc-dhcp, bind9, bind9-libs

Package 24.04 LTS
isc-dhcp Not affected
bind9 Not affected
bind9-libs Not in release
Show less packages

CVE-2026-3592

Medium priority

Some fixes available 1 of 2

BIND resolvers are vulnerable to an amplified resource consumption/exhaustion attack. If a victim resolver makes a query to a specially crafted zone, the resolver will consume disproportionate resources. This issue affects BIND 9...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 24.04 LTS
bind9 Fixed
isc-dhcp Needs evaluation
bind9-libs Not in release
Show less packages

CVE-2026-33278

High priority
Fixed

NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables denial of service and possible remote code execution as a result of deep copying a data structure and...

1 affected package

unbound

Package 24.04 LTS
unbound Fixed
Show less packages

CVE-2026-32792

Medium priority
Fixed

NLnet Labs Unbound 1.6.2 up to and including version 1.25.0 has a denial of service vulnerability when compiled with DNSCrypt support ('--enable-dnscrypt'). A bad DNSCrypt query could underflow Unbound's DNSCrypt packet reading...

1 affected package

unbound

Package 24.04 LTS
unbound Fixed
Show less packages

CVE-2026-3039

Medium priority
Fixed

BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption when receiving and processing maliciously-constructed packets. Typically these servers will be...

3 affected packages

isc-dhcp, bind9, bind9-libs

Package 24.04 LTS
isc-dhcp Not affected
bind9 Fixed
bind9-libs Not in release
Show less packages

CVE-2026-29518

High priority
Fixed

Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components...

1 affected package

rsync

Package 24.04 LTS
rsync Fixed
Show less packages

CVE-2026-5090

Medium priority
Needs evaluation

Template::Plugin::HTML versions through 3.102 for Perl allows HTML and JavaScript to be injected. The html_filter function did not escape single quotes. HTML attributes inside of single quotes could be have code injected. For...

1 affected package

libtemplate-perl

Package 24.04 LTS
libtemplate-perl Needs evaluation
Show less packages

CVE-2026-32882

Medium priority
Needs evaluation

libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap buffer over-read in HeifPixelImage::overlay() in libheif/pixelimage.cc. When compositing an overlay image (iovl) whose...

1 affected package

libheif

Package 24.04 LTS
libheif Needs evaluation
Show less packages

CVE-2026-32814

Medium priority
Needs evaluation

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, when decoding a HEIF grid image with strict_decoding=false (the default), a corrupted tile silently fails to decode and the library returns...

1 affected package

libheif

Package 24.04 LTS
libheif Needs evaluation
Show less packages

CVE-2026-32741

Medium priority
Needs evaluation

libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and below contain a heap buffer overflow in MaskImageCodec::decode_mask_image(). When decoding a HEIF file containing a mask image (mski), the function...

1 affected package

libheif

Package 24.04 LTS
libheif Needs evaluation
Show less packages