Search CVE reports


Toggle filters

391 – 400 of 49237 results

Status is adjusted based on your filters.


CVE-2026-100888

Medium priority
Needs evaluation

A weakness has been identified in Trusted Domain Project OpenDKIM up to 2.11.0. This affects the function dkim_canon_selecthdrs of the file libopendkim/dkim-canon.c of the component DKIM Signature Header Selection. Executing a...

1 affected package

opendkim

Package 24.04 LTS
opendkim Needs evaluation
Show less packages

CVE-2026-96284

Medium priority
Needs evaluation

A malicious user can get read-access to files in the flatpak-system-helper context if a system OCI repository is configured, because the OCI code paths in the system helper follow symlinks when importing OCI images that are under...

1 affected package

flatpak

Package 24.04 LTS
flatpak Needs evaluation
Show less packages

CVE-2026-96283

Medium priority
Needs evaluation

By calling org.freedesktop.Flatpak.SystemHelper.CancelPull on another user's pull, the pull is not actually cancelled but removed from internal tracking, making it impossible for the owning user to stop it. Ongoing pulls cannot be stopped.

1 affected package

flatpak

Package 24.04 LTS
flatpak Needs evaluation
Show less packages

CVE-2026-96282

Medium priority
Needs evaluation

A malicious Flatpak extension can probe the host filesystem to determine what files and directories exist at arbitrary paths, and host directory listings can be disclosed to sandboxed applications using the...

1 affected package

flatpak

Package 24.04 LTS
flatpak Needs evaluation
Show less packages

CVE-2026-96281

Medium priority
Needs evaluation

On a multi-user system, a user with an active local login session could downgrade a system-wide Flatpak app to an older version by removing the app's remote ref via the unprivileged system-helper RemoveLocalRef method, causing the...

1 affected package

flatpak

Package 24.04 LTS
flatpak Needs evaluation
Show less packages

CVE-2026-96280

Medium priority
Needs evaluation

The OCI delta stream parser read sizes as guint64 but passed them to GLib I/O and allocation functions expecting gsize (32 bits on 32-bit systems), causing undersized allocations while subsequent operations use the original 64-bit...

1 affected package

flatpak

Package 24.04 LTS
flatpak Needs evaluation
Show less packages

CVE-2026-96279

Medium priority
Needs evaluation

A malicious OCI registry can hardlink arbitrary host files into the extraction directory when a user installs or updates a Flatpak application from an OCI remote, allowing disclosure of arbitrary host file contents. For...

1 affected package

flatpak

Package 24.04 LTS
flatpak Needs evaluation
Show less packages

CVE-2026-94417

Medium priority
Needs evaluation

When an application enables both OCSP and CRL revocation checking on one WOLFSSL_CTX or certificate manager, wolfSSL skips the CRL check for any peer certificate that carries no Authority Information Access OCSP URL, and accepts a...

1 affected package

wolfssl

Package 24.04 LTS
wolfssl Needs evaluation
Show less packages

CVE-2026-93304

Medium priority
Needs evaluation

A (D)TLS 1.2 client can accept a ChangeCipherSpec message before it has sent its ClientKeyExchange. No master secret has been derived at that point, so the client installs read keys derived from a known (deterministic) key and...

1 affected package

wolfssl

Package 24.04 LTS
wolfssl Needs evaluation
Show less packages

CVE-2026-93302

Medium priority
Needs evaluation

MatchTrustedPeer ignores the public key used, leading to forged CA clones passing verification. Affected builds are any that enable the macro WOLFSSL_TRUST_PEER_CERT and load CA certificates with wolfSSL_CTX_trust_peer_cert() or...

1 affected package

wolfssl

Package 24.04 LTS
wolfssl Needs evaluation
Show less packages