Search CVE reports


Toggle filters

61 – 70 of 49291 results

Status is adjusted based on your filters.


CVE-2026-63273

Medium priority
Needs evaluation

LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing an encrypted document. The length of the decryption key was taken from the document's own encryption dictionary and was used to fill a fixed...

1 affected package

libreoffice

Package 20.04 LTS
libreoffice Needs evaluation
Show less packages

CVE-2026-63272

Medium priority
Needs evaluation

LibreOffice can import WMF graphics, which may be embedded in documents. A heap buffer overflow existed when importing a text record that carries its own character advance widths. The count of advance values and the length of the...

1 affected package

libreoffice

Package 20.04 LTS
libreoffice Needs evaluation
Show less packages

CVE-2026-95508

Medium priority
Needs evaluation

A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured with a small interface MTU, a guest-supplied DHCPv6 CLIENTID option or TFTP blksize option can overflow the...

1 affected package

libslirp

Package 20.04 LTS
libslirp Needs evaluation
Show less packages

CVE-2026-94640

Medium priority
Needs evaluation

A flaw was found in rpcbind. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a large number of unique requests. The rpcbind service records previously unseen RPC (Remote...

1 affected package

rpcbind

Package 20.04 LTS
rpcbind Needs evaluation
Show less packages

CVE-2026-93712

Medium priority
Needs evaluation

Dancer2 versions from 2.1.0 before 2.2.0 for Perl serve files from outside public_dir via relative path segments in the File route handler. The handler joins the request path onto public_dir without collapsing relative segments,...

1 affected package

libdancer2-perl

Package 20.04 LTS
libdancer2-perl Needs evaluation
Show less packages

CVE-2026-93711

Medium priority
Needs evaluation

Dancer2 versions before 2.2.0 for Perl do not strip CR and LF from response header names in headers_to_array. The routine removes CR and LF from each header value but not from the name. A name carrying them therefore reaches the...

1 affected package

libdancer2-perl

Package 20.04 LTS
libdancer2-perl Needs evaluation
Show less packages

CVE-2026-93710

Medium priority
Needs evaluation

Dancer2 versions from 2.0.0 before 2.2.0 for Perl dispatch a route that a dying hook refused when the exception handler halts the response in compile_hooks. A hook that dies fires core.app.hook_exception, then calls cleanup...

1 affected package

libdancer2-perl

Package 20.04 LTS
libdancer2-perl Needs evaluation
Show less packages

CVE-2026-93709

Medium priority
Needs evaluation

Dancer2 versions before 2.2.0 for Perl serve a layout as a page when an equivalent spelling of its path misses the guard in the AutoPage handler. The handler compares the request path against the layout directory name as text,...

1 affected package

libdancer2-perl

Package 20.04 LTS
libdancer2-perl Needs evaluation
Show less packages

CVE-2026-92162

Medium priority
Needs evaluation

security update

1 affected package

flatpak

Package 20.04 LTS
flatpak Needs evaluation
Show less packages

CVE-2026-89422

Medium priority
Needs evaluation

Key Exchange without Entity Authentication vulnerability in Erlang/OTP ssl allows a peer that answers a TLS 1.3 client connection to impersonate the intended server. A pre_shared_key extension in the ServerHello that the client...

1 affected package

erlang

Package 20.04 LTS
erlang Needs evaluation
Show less packages