Search CVE reports


Toggle filters

301 – 310 of 53339 results

Status is adjusted based on your filters.


CVE-2026-75806

Low priority

Some fixes available 1 of 3

Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter than the mandatory explicit IV and authentication...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 22.04 LTS
openssl Fixed
openssl-fips Not in release
openssl1.0 Not in release
nodejs Vulnerable
edk2 Needs evaluation
edk2-hwe Not in release
Show less packages

CVE-2026-75805

Low priority

Some fixes available 1 of 2

Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response. Impact summary: The NULL pointer...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 22.04 LTS
openssl Fixed
openssl-fips Not in release
openssl1.0 Not in release
nodejs Vulnerable
edk2 Not affected
edk2-hwe Not in release
Show less packages

CVE-2026-75804

Low priority
Vulnerable

Issue summary: OpenSSL QUIC stack does not enforce connection level flow control for streams. Remote peers may send more bytes as long as they fit within the stream flow control limits. Impact summary: A malicious remote peer may...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 22.04 LTS
openssl Not affected
openssl-fips Not affected
openssl1.0 Not in release
nodejs Vulnerable
edk2 Not affected
edk2-hwe Not in release
Show less packages

CVE-2026-72897

Low priority
Vulnerable

Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a connection to a different SSL_CTX part way through a handshake may access memory beyond the end of an internal array if the replacement context knows about more...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 22.04 LTS
openssl Not affected
openssl-fips Not affected
openssl1.0 Not in release
nodejs Vulnerable
edk2 Not affected
edk2-hwe Not in release
Show less packages

CVE-2026-62439

Medium priority
Needs evaluation

[Unknown description]

1 affected package

gimp

Package 22.04 LTS
gimp Needs evaluation
Show less packages

CVE-2026-54875

Low priority
Vulnerable

Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 private key operations on ARM64 and RISC-V platforms. Impact summary: An attacker able to measure the time taken by, or...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 22.04 LTS
openssl Not affected
openssl-fips Not affected
openssl1.0 Not in release
nodejs Vulnerable
edk2 Not affected
edk2-hwe Not in release
Show less packages

CVE-2026-54872

Low priority

Some fixes available 1 of 3

Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret nonce through timing. Impact...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 22.04 LTS
openssl Fixed
openssl-fips Not in release
openssl1.0 Not in release
nodejs Vulnerable
edk2 Needs evaluation
edk2-hwe Not in release
Show less packages

CVE-2026-46675

Medium priority
Needs evaluation

[Use-after-free of zlib input in `png_read_end` after incomplete zTXt, iTXt or iCCP decompression]

5 affected packages

libpng, libpng1.6, firefox, thunderbird, chromium-browser

Package 22.04 LTS
libpng Not in release
libpng1.6 Needs evaluation
firefox Not affected
thunderbird Not affected
chromium-browser Not affected
Show less packages

CVE-2026-35191

Low priority
Vulnerable

Issue summary: The OpenSSL QUIC server, when configured to not preform address validation, can be forced to count incoming packets multiple times in its unvalidated credit computation, leading to a violation of the RFC...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 22.04 LTS
openssl Not affected
openssl-fips Not affected
openssl1.0 Not in release
nodejs Vulnerable
edk2 Not affected
edk2-hwe Not in release
Show less packages

CVE-2026-35189

Low priority

Some fixes available 1 of 3

Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions. Impact summary: Receiving a crafted certificate from a malicious peer...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 22.04 LTS
openssl Fixed
openssl-fips Not in release
openssl1.0 Not in release
nodejs Vulnerable
edk2 Needs evaluation
edk2-hwe Not in release
Show less packages