Search CVE reports


Toggle filters

1 – 10 of 58627 results

Status is adjusted based on your filters.


CVE-2026-94640

Medium priority
Needs evaluation

[Unknown description]

1 affected package

rpcbind

Package 16.04 LTS
rpcbind Needs evaluation
Show less packages

CVE-2026-94184

Medium priority
Needs evaluation

A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support. A malicious or compromised mail server advertising NTLM authentication can send a crafted Type 2 challenge that causes fetchmail to write past...

1 affected package

fetchmail

Package 16.04 LTS
fetchmail Needs evaluation
Show less packages

CVE-2026-93712

Medium priority
Needs evaluation

Dancer2 versions from 2.1.0 before 2.2.0 for Perl serve files from outside public_dir via relative path segments in the File route handler. The handler joins the request path onto public_dir without collapsing relative segments,...

1 affected package

libdancer2-perl

Package 16.04 LTS
libdancer2-perl Needs evaluation
Show less packages

CVE-2026-93711

Medium priority
Needs evaluation

Dancer2 versions before 2.2.0 for Perl do not strip CR and LF from response header names in headers_to_array. The routine removes CR and LF from each header value but not from the name. A name carrying them therefore reaches the...

1 affected package

libdancer2-perl

Package 16.04 LTS
libdancer2-perl Needs evaluation
Show less packages

CVE-2026-93710

Medium priority
Needs evaluation

Dancer2 versions from 2.0.0 before 2.2.0 for Perl dispatch a route that a dying hook refused when the exception handler halts the response in compile_hooks. A hook that dies fires core.app.hook_exception, then calls cleanup...

1 affected package

libdancer2-perl

Package 16.04 LTS
libdancer2-perl Needs evaluation
Show less packages

CVE-2026-93709

Medium priority
Needs evaluation

Dancer2 versions before 2.2.0 for Perl serve a layout as a page when an equivalent spelling of its path misses the guard in the AutoPage handler. The handler compares the request path against the layout directory name as text,...

1 affected package

libdancer2-perl

Package 16.04 LTS
libdancer2-perl Needs evaluation
Show less packages

CVE-2026-93012

Medium priority
Needs evaluation

Email::Sender::Transport::Sendmail versions before 2.602 for Perl allow arbitrary command execution on Windows sending a message whose envelope address reaches the shell in _sendmail_pipe. On MSWin32 the envelope sender and every...

1 affected package

libemail-sender-perl

Package 16.04 LTS
libemail-sender-perl Needs evaluation
Show less packages

CVE-2026-89422

Medium priority
Needs evaluation

Key Exchange without Entity Authentication vulnerability in Erlang/OTP ssl allows a peer that answers a TLS 1.3 client connection to impersonate the intended server. A pre_shared_key extension in the ServerHello that the client...

1 affected package

erlang

Package 16.04 LTS
erlang Needs evaluation
Show less packages

CVE-2026-88807

Medium priority
Needs evaluation

A heap overflow in libXrender before 0.9.13 in RenderQueryPictFormats could be used by malicious X servers to inject code into attached X clients.

1 affected package

libxrender

Package 16.04 LTS
libxrender Needs evaluation
Show less packages

CVE-2026-88806

Medium priority
Needs evaluation

A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing the key_sym_map.

1 affected package

libx11

Package 16.04 LTS
libx11 Needs evaluation
Show less packages