Search CVE reports


Toggle filters

711 – 720 of 42759 results

Status is adjusted based on your filters.


CVE-2026-20345

Medium priority
Needs evaluation

A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This...

1 affected package

clamav

Package 24.04 LTS
clamav Needs evaluation
Show less packages

CVE-2026-20339

Medium priority
Needs evaluation

A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an...

1 affected package

clamav

Package 24.04 LTS
clamav Needs evaluation
Show less packages

CVE-2026-20338

Medium priority
Needs evaluation

A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper memory handling when processing content in...

1 affected package

clamav

Package 24.04 LTS
clamav Needs evaluation
Show less packages

CVE-2026-20337

Medium priority
Needs evaluation

A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper boundary checks for content in zip files...

1 affected package

clamav

Package 24.04 LTS
clamav Needs evaluation
Show less packages

CVE-2026-62996

Medium priority
Needs evaluation

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. From 5.0.0 until 5.8.4, Smarty's stream: resource-name handling does not adequately restrict which PHP stream...

2 affected packages

smarty3, smarty4

Package 24.04 LTS
smarty3 Needs evaluation
smarty4 Needs evaluation
Show less packages

CVE-2026-62992

Medium priority
Needs evaluation

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to 5.8.2 (and 4.5.7 on the 4.x line), Security::_checkDir() does not fully resolve symbolic links before...

2 affected packages

smarty3, smarty4

Package 24.04 LTS
smarty3 Needs evaluation
smarty4 Needs evaluation
Show less packages

CVE-2026-18497

Medium priority
Needs evaluation

A heap-buffer-overflow vulnerability exists in the nothings stb TrueType library, up to version 1.26, that is used for parsing TrueType font files. The vulnerability exists in the stbtt__GetGlyphShapeTT() function within the...

1 affected package

libstb

Package 24.04 LTS
libstb Needs evaluation
Show less packages

CVE-2026-15816

Medium priority
Needs evaluation

A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the...

1 affected package

dracut

Package 24.04 LTS
dracut Needs evaluation
Show less packages

CVE-2026-64638

Medium priority
Needs evaluation

WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE...

1 affected package

wordpress

Package 24.04 LTS
wordpress Needs evaluation
Show less packages

CVE-2026-61477

Medium priority
Vulnerable

An injection vulnerability was found in libvirt's virtual network driver. The network XML parser does not strip newline characters from DNS TXT record value attributes and SRV record domain/target attributes. These values are...

1 affected package

libvirt

Package 24.04 LTS
libvirt Vulnerable
Show less packages