Search CVE reports


Toggle filters

41 – 50 of 36547 results

Status is adjusted based on your filters.


CVE-2026-3284

Medium priority
Needs evaluation

A vulnerability was found in libvips 8.19.0. Impacted is the function vips_extract_area_build of the file libvips/conversion/extract.c. The manipulation of the argument extract_area results in integer overflow. The attack requires...

1 affected package

vips

Package 22.04 LTS
vips Needs evaluation
Show less packages

CVE-2026-3283

Medium priority
Needs evaluation

A vulnerability has been found in libvips 8.19.0. This issue affects the function vips_extract_band_build of the file libvips/conversion/extract.c. The manipulation of the argument extract_band leads to out-of-bounds read. The...

1 affected package

vips

Package 22.04 LTS
vips Needs evaluation
Show less packages

CVE-2026-3282

Medium priority
Needs evaluation

A flaw has been found in libvips 8.19.0. This vulnerability affects the function vips_unpremultiply_build of the file libvips/conversion/unpremultiply.c. Executing a manipulation of the argument alpha_band can lead to...

1 affected package

vips

Package 22.04 LTS
vips Needs evaluation
Show less packages

CVE-2026-3281

Medium priority
Needs evaluation

A vulnerability was detected in libvips 8.19.0. This affects the function vips_bandrank_build of the file libvips/conversion/bandrank.c. Performing a manipulation of the argument index results in heap-based buffer overflow. The...

1 affected package

vips

Package 22.04 LTS
vips Needs evaluation
Show less packages

CVE-2026-28372

Medium priority
Needs evaluation

telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service credentials support added to the login(1) implementation of util-linux in release 2.40. This is related to client...

1 affected package

inetutils

Package 22.04 LTS
inetutils Needs evaluation
Show less packages

CVE-2026-28370

Medium priority
Needs evaluation

In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage API may trigger code execution on the Vitrage service host as the user the Vitrage service runs under. This...

1 affected package

vitrage

Package 22.04 LTS
vitrage Needs evaluation
Show less packages

CVE-2026-28364

Medium priority
Needs evaluation

In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds validation...

1 affected package

ocaml

Package 22.04 LTS
ocaml Needs evaluation
Show less packages

CVE-2025-40932

Medium priority
Needs evaluation

Apache::SessionX versions through 2.01 for Perl create insecure session id. Apache::SessionX generates session ids insecurely. The default session id generator in Apache::SessionX::Generate::MD5 returns a MD5 hash seeded with the...

1 affected package

libapache-sessionx-perl

Package 22.04 LTS
libapache-sessionx-perl Needs evaluation
Show less packages

CVE-2021-4456

Medium priority
Needs evaluation

Net::CIDR versions before 0.24 for Perl mishandle leading zeros in IP CIDR addresses, which may have unspecified impact. The functions `addr2cidr` and `cidrlookup` may return leading zeros in a CIDR string, which may in turn be...

1 affected package

libnet-cidr-perl

Package 22.04 LTS
libnet-cidr-perl Needs evaluation
Show less packages

CVE-2026-22206

Medium priority
Needs evaluation

SPIP versions prior to 4.4.10 contain a SQL injection vulnerability that allows authenticated low-privilege users to execute arbitrary SQL queries by manipulating union-based injection techniques. Attackers can exploit this SQL...

1 affected package

spip

Package 22.04 LTS
spip Needs evaluation
Show less packages