Search CVE reports


Toggle filters

301 – 310 of 42759 results

Status is adjusted based on your filters.


CVE-2026-71969

Medium priority

Not in release

OP-TEE OS through 4.10.0, fixed in commit 7b8b494, contains a buffer underwrite vulnerability in the RSA NOPAD encrypt and decrypt operations within the mbedTLS software backend and SE050 hardware driver that allows a malicious...

1 affected package

optee-os

Package 24.04 LTS
optee-os Not in release
Show less packages

CVE-2026-71968

Medium priority

Not in release

OP-TEE OS through 4.10.0, fixed in commit 8794043, contains a use-after-free vulnerability in the Trusted Application loader that allows attackers with the ability to load a signed Trusted Application to corrupt secure-world...

1 affected package

optee-os

Package 24.04 LTS
optee-os Not in release
Show less packages

CVE-2026-71967

Medium priority

Not in release

OP-TEE OS through 4.10.0, fixed in commit 0aadfc2, contains a null pointer dereference vulnerability in the Widevine pseudo-TA open_session handler that allows Normal World clients to cause a denial of service...

1 affected package

optee-os

Package 24.04 LTS
optee-os Not in release
Show less packages

CVE-2026-6791

Medium priority
Needs evaluation

When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory. The implementation allocates memory for this username...

2 affected packages

glibc, eglibc

Package 24.04 LTS
glibc Needs evaluation
eglibc Not in release
Show less packages

CVE-2026-6368

Medium priority
Needs evaluation

Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.

2 affected packages

glibc, eglibc

Package 24.04 LTS
glibc Needs evaluation
eglibc Not in release
Show less packages

CVE-2026-59091

Medium priority
Needs evaluation

A flaw was found in GIMP's file format plugins, including those for PSD and PAA files. A remote attacker could exploit these vulnerabilities by tricking a user into opening a specially crafted image file. This could lead to...

1 affected package

gimp

Package 24.04 LTS
gimp Needs evaluation
Show less packages

CVE-2026-70622

Medium priority
Needs evaluation

tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnerability in the Builder::append_dir_all() function that allows attackers to read files outside the intended source root directory by planting symlinks in an...

1 affected package

rust-tar

Package 24.04 LTS
rust-tar Needs evaluation
Show less packages

CVE-2026-16626

Medium priority

Not in release

Improper restriction of XML external entity reference vulnerability (unauthenticated) in Jaspersoft JasperReports Server. This issue affects JasperReports Server: from 9.0.0 before HF-9 and from 10.0.0 before HF-10.

1 affected package

jasperreports

Package 24.04 LTS
jasperreports Not in release
Show less packages

CVE-2026-63623

Medium priority
Vulnerable

A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was caused by the `qemu-img` utility running with overly permissive file creation...

1 affected package

libvirt

Package 24.04 LTS
libvirt Vulnerable
Show less packages

CVE-2026-66738

Medium priority
Needs evaluation

SPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed installations. The navigation menu endpoint improperly handles array-typed user input, which bypasses input sanitization and allows the value to break out...

1 affected package

spip

Package 24.04 LTS
spip Needs evaluation
Show less packages