Search CVE reports


Toggle filters

371 – 380 of 46705 results

Status is adjusted based on your filters.


CVE-2026-90576

Medium priority
Needs evaluation

A security vulnerability has been detected in GPAC up to f1219cde. Affected is the function gf_node_list_add_child of the file scenegraph/base_scenegraph.c of the component MP4Box. Such manipulation leads to null pointer...

1 affected package

gpac

Package 24.04 LTS
gpac Needs evaluation
Show less packages

CVE-2025-45480

Medium priority

Not in release

Floodlight 71fe8a7 allows disruption of host communication via link spoofing. A port is misclassified as a non-boundary.

1 affected package

floodlight

Package 24.04 LTS
floodlight Not in release
Show less packages

CVE-2026-90573

Medium priority
Needs evaluation

A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gf_sg_mfurl_del of the file scenegraph/vrml_tools.c of the component MP4Box. The manipulation leads to null pointer dereference....

1 affected package

gpac

Package 24.04 LTS
gpac Needs evaluation
Show less packages

CVE-2026-90783

Medium priority
Needs evaluation

MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI file with oversized entry counts...

1 affected package

mkvtoolnix

Package 24.04 LTS
mkvtoolnix Needs evaluation
Show less packages

CVE-2026-90781

Medium priority
Needs evaluation

alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a...

1 affected package

alsa-lib

Package 24.04 LTS
alsa-lib Needs evaluation
Show less packages

CVE-2026-90776

Medium priority
Needs evaluation

Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing email addresses with RFC 5322 comments. Attackers can craft malicious email headers with...

1 affected package

node-nodemailer

Package 24.04 LTS
node-nodemailer Needs evaluation
Show less packages

CVE-2026-90775

Medium priority

Not in release

PostGIS address_standardizer through 3.7.0 fails to validate the Weight parameter from caller-supplied rules tables before using it as an array index. Attackers can craft malicious rule rows with out-of-range Weight values to...

1 affected package

address-standardizer

Package 24.04 LTS
address-standardizer Not in release
Show less packages

CVE-2026-90773

Medium priority

Not in release

procs through 0.14.12 fails to sanitize escape sequences in process command lines before displaying them in the Command column. Local attackers can execute processes with malicious ANSI or OSC escape sequences in their command...

1 affected package

rust-procs

Package 24.04 LTS
rust-procs Not in release
Show less packages

CVE-2026-90678

Medium priority
Needs evaluation

An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 3.5-dev1 through 3.5-dev5. Exploitation requires an HTTP/3 frontend: HAProxy must be built with QUIC support and configured with a QUIC bind listener, and the affected...

1 affected package

haproxy

Package 24.04 LTS
haproxy Needs evaluation
Show less packages

CVE-2026-90648

Medium priority
Needs evaluation

wasm2c in WebAssembly wabt through 1.0.41 allows sandbox escape in some situations that primarily involve 32-bit platforms, aka a "table flip" attack. It does not check the return value of calloc()...

1 affected package

wabt

Package 24.04 LTS
wabt Needs evaluation
Show less packages