Search CVE reports


Toggle filters

31 – 40 of 45282 results

Status is adjusted based on your filters.


CVE-2026-42495

Medium priority
Needs evaluation

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver derives several lengths...

1 affected package

xen

Package 22.04 LTS
xen Needs evaluation
Show less packages

CVE-2026-42494

Medium priority
Needs evaluation

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver derives several lengths...

1 affected package

xen

Package 22.04 LTS
xen Needs evaluation
Show less packages

CVE-2026-42493

Medium priority
Needs evaluation

Addressing certain issues, in particular related to operations which may take excessively long and therefore would need preemption, has turned out overly costly. Since alternatives (HVM/PVH: HAP, PV: shim) are commonly available,...

1 affected package

xen

Package 22.04 LTS
xen Needs evaluation
Show less packages

CVE-2026-42492

Medium priority
Needs evaluation

Xenstore, to have an up-to-date picture of the entire system, wants to know of domains appearing and disappearing. To make this more robust, a new XEN_DOMCTL_get_domain_state was introduced. The management of the bitmap...

1 affected package

xen

Package 22.04 LTS
xen Needs evaluation
Show less packages

CVE-2026-18047

Medium priority
Needs evaluation

A flaw was found in Dogtag PKI's ACME responder where the web.xml security constraints use exact URL pattern matching for admin-only enable/disable endpoints. By appending a trailing slash to the URL, an unauthenticated attacker...

1 affected package

dogtag-pki

Package 22.04 LTS
dogtag-pki Needs evaluation
Show less packages

CVE-2026-17072

Medium priority
Needs evaluation

A flaw was found in GStreamer's gst-plugins-good. A heap-based out-of-bounds read of 4 bytes can occur when parsing FLAC audio stream headers embedded in a Matroska or WebM container file. The vulnerability is triggered by a...

2 affected packages

gst-plugins-good0.10, gst-plugins-good1.0

Package 22.04 LTS
gst-plugins-good0.10 Not in release
gst-plugins-good1.0 Needs evaluation
Show less packages

CVE-2026-59248

Medium priority
Needs evaluation

Allocation of resources without limits vulnerability in ninenines cowlib allows an unauthenticated remote HTTP/2 or HTTP/3 peer to exhaust memory on the vulnerable server (or client) and cause a denial of service. The HPACK and...

2 affected packages

erlang-cowlib, rabbitmq-server

Package 22.04 LTS
erlang-cowlib Needs evaluation
rabbitmq-server Needs evaluation
Show less packages

CVE-2026-6949

Medium priority
Fixed

TSIG packet with name compression can crash DNS. Incorrect size calculations when a TSIG record contains compressed names can lead to a large out-of-bounds write causing the server to crash.

1 affected package

samba

Package 22.04 LTS
samba Fixed
Show less packages

CVE-2026-58224

Medium priority
Fixed

The CTDB protocol has bounds checking issues. CTDB fails to do integrity checking of received packets. This includes failure to check field lengths against packet lengths when unmarshalling packets.

1 affected package

samba

Package 22.04 LTS
samba Fixed
Show less packages

CVE-2026-58222

Medium priority
Fixed

A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Directory Domain Controller (AD DC). When processing LDAP Compare requests, Samba fails to properly validate user-supplied...

1 affected package

samba

Package 22.04 LTS
samba Fixed
Show less packages