Search CVE reports


Toggle filters

2641 – 2650 of 34709 results

Status is adjusted based on your filters.


CVE-2026-65624

Medium priority
Needs evaluation

Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows an unauthenticated remote attacker to exhaust connection process memory over HTTP/1.1. The HTTP/1.1 handler in cowboy_http enforces the...

2 affected packages

erlang-cowboy, rabbitmq-server

Package 26.04 LTS
erlang-cowboy Needs evaluation
rabbitmq-server Needs evaluation
Show less packages

CVE-2026-59248

Medium priority
Needs evaluation

Allocation of resources without limits vulnerability in ninenines cowlib allows an unauthenticated remote HTTP/2 or HTTP/3 peer to exhaust memory on the vulnerable server (or client) and cause a denial of service. The HPACK and...

2 affected packages

erlang-cowlib, rabbitmq-server

Package 26.04 LTS
erlang-cowlib Needs evaluation
rabbitmq-server Needs evaluation
Show less packages

CVE-2026-6949

Medium priority
Fixed

TSIG packet with name compression can crash DNS. Incorrect size calculations when a TSIG record contains compressed names can lead to a large out-of-bounds write causing the server to crash.

1 affected package

samba

Package 26.04 LTS
samba Fixed
Show less packages

CVE-2026-58224

Medium priority
Fixed

A flaw was found in Samba's CTDB, the clustered database service used by Samba. Insufficient integrity validation of received CTDB protocol packets allows malformed packets containing invalid field lengths, improperly terminated...

1 affected package

samba

Package 26.04 LTS
samba Fixed
Show less packages

CVE-2026-58222

Medium priority
Fixed

A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Directory Domain Controller (AD DC). When processing LDAP Compare requests, Samba fails to properly validate user-supplied...

1 affected package

samba

Package 26.04 LTS
samba Fixed
Show less packages

CVE-2026-58221

Medium priority
Fixed

Samba AD authenticated LDAP access domain takeover. Samba AD low-privilege authenticated LDAP access allows modifications to internal LDB special DNs, which permits a domain takeover.

1 affected package

samba

Package 26.04 LTS
samba Fixed
Show less packages

CVE-2026-58218

Medium priority
Fixed

A flaw was found in Samba's internal DNS server where unauthenticated TKEY registration requests were added to the TKEY name cache before being rejected. A remote, unauthenticated attacker can exploit this behavior by sending a...

1 affected package

samba

Package 26.04 LTS
samba Fixed
Show less packages

CVE-2026-58216

Medium priority
Fixed

An out-of-bounds read flaw was found in Samba's Kerberos Key Distribution Center's (KDC) password change (kpasswd) service. When processing malformed ASN.1-encoded Kerberos password change request, Samba server miscalculates the...

1 affected package

samba

Package 26.04 LTS
samba Fixed
Show less packages

CVE-2024-14041

Medium priority
Not affected

In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polynomial coefficients by the modulus q: Poly.toMsg, which decodes the decrypted message, and the ciphertext...

1 affected package

bouncycastle

Package 26.04 LTS
bouncycastle Not affected
Show less packages

CVE-2025-63913

Medium priority
Needs evaluation

An issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial of service via crafted request to the SBI function #2 or the 'Find and configure a matching counter' function of SBI PMU extension.

1 affected package

opensbi

Package 26.04 LTS
opensbi Needs evaluation
Show less packages