Search CVE reports


Toggle filters

621 – 630 of 36525 results

Status is adjusted based on your filters.


CVE-2026-32740

Medium priority
Needs evaluation

libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap-buffer-overflow (write) vulnerability in the grid tile compositing, allowing an attacker to write 64 bytes of...

1 affected package

libheif

Package 24.04 LTS
libheif Needs evaluation
Show less packages

CVE-2026-32739

Medium priority
Needs evaluation

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 800-byte HEIF sequence file causes an infinite loop in Box_stts::get_sample_duration(), consuming 100% CPU indefinitely with zero...

1 affected package

libheif

Package 24.04 LTS
libheif Needs evaluation
Show less packages

CVE-2026-41470

Medium priority

Not in release

LIVE555 before 2026.04.22 contains an authorization bypass vulnerability in RTSP session command handling that allows attackers to replay valid Session tokens from unauthenticated connections. Attackers who obtain a valid Session...

1 affected package

liblivemedia

Package 24.04 LTS
liblivemedia Not in release
Show less packages

CVE-2026-33642

Medium priority
Needs evaluation

Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kitty/graphics.c performs bounds validation on composition offsets using unsigned 32-bit arithmetic that...

1 affected package

kitty

Package 24.04 LTS
kitty Needs evaluation
Show less packages

CVE-2026-33637

Medium priority
Needs evaluation

Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Versions 2.0.0 through 2.14.1 still allow protocol-relative host override when the request target is passed as a URI object...

1 affected package

ruby-faraday

Package 24.04 LTS
ruby-faraday Needs evaluation
Show less packages

CVE-2026-32738

Medium priority
Needs evaluation

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 792-byte HEIF sequence file with samples_per_chunk=0 in the stsc box causes an unsigned integer underflow in the Chunk constructor...

1 affected package

libheif

Package 24.04 LTS
libheif Needs evaluation
Show less packages

CVE-2026-33633

Medium priority
Needs evaluation

Kitty is a cross-platform GPU based terminal. Versions 0.46.2 and below contain a heap buffer overflow in load_image_data() that allows any process which can write to the terminal's stdin to crash kitty immediately....

1 affected package

kitty

Package 24.04 LTS
kitty Needs evaluation
Show less packages

CVE-2026-8706

Medium priority
Ignored

Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-in user's cookies....

9 affected packages

mozjs68, firefox, thunderbird, mozjs38, mozjs52...

Package 24.04 LTS
mozjs68 Not in release
firefox Not affected
thunderbird Not affected
mozjs38 Not in release
mozjs52 Not in release
mozjs78 Not in release
mozjs91 Not in release
mozjs102 Ignored
mozjs115 Ignored
Show all 9 packages Show less packages

CVE-2026-31072

Medium priority
Needs evaluation

The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are vulnerable to Remote Code Execution (RCE) via Insecure Deserialization. The unmarshal_object function allows for arbitrary class...

1 affected package

apscheduler

Package 24.04 LTS
apscheduler Needs evaluation
Show less packages

CVE-2026-8711

Medium priority
Needs evaluation

NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled NGINX variable (for example, $http_*, $arg_*, $cookie_*) and a location invoking the ngx.fetch() operation...

1 affected package

libnginx-mod-js

Package 24.04 LTS
libnginx-mod-js Needs evaluation
Show less packages