Search CVE reports


Toggle filters

721 – 730 of 38389 results

Status is adjusted based on your filters.


CVE-2026-5860

Medium priority
Not affected

Use after free in WebRTC in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

1 affected package

chromium-browser

Package 22.04 LTS
chromium-browser Not affected
Show less packages

CVE-2026-5859

Medium priority
Not affected

Integer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

1 affected package

chromium-browser

Package 22.04 LTS
chromium-browser Not affected
Show less packages

CVE-2026-5858

Medium priority
Not affected

Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

1 affected package

chromium-browser

Package 22.04 LTS
chromium-browser Not affected
Show less packages

CVE-2026-40026

Medium priority
Needs evaluation

The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the ISO9660 filesystem parser where the parse_susp() function trusts len_id, len_des, and len_src fields from the disk image to memcpy data into a stack...

1 affected package

sleuthkit

Package 22.04 LTS
sleuthkit Needs evaluation
Show less packages

CVE-2026-40025

Medium priority
Needs evaluation

The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the APFS filesystem keybag parser where the wrapped_key_parser class follows attacker-controlled length fields without bounds checking, causing heap...

1 affected package

sleuthkit

Package 22.04 LTS
sleuthkit Needs evaluation
Show less packages

CVE-2026-40024

Medium priority
Needs evaluation

The Sleuth Kit through 4.14.0 contains a path traversal vulnerability in tsk_recover that allows an attacker to write files to arbitrary locations outside the intended recovery directory via crafted filenames or directory paths...

1 affected package

sleuthkit

Package 22.04 LTS
sleuthkit Needs evaluation
Show less packages

CVE-2026-39892

Medium priority
Not affected

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g....

1 affected package

python-cryptography

Package 22.04 LTS
python-cryptography Not affected
Show less packages

CVE-2026-39883

Medium priority
Needs evaluation

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command using a bare name, allowing the...

1 affected package

golang-opentelemetry-otel

Package 22.04 LTS
golang-opentelemetry-otel Needs evaluation
Show less packages

CVE-2026-39882

Medium priority
Needs evaluation

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to 1.43.0, the otlp HTTP exporters (traces/metrics/logs) read the full HTTP response body into an in-memory bytes.Buffer without a size cap. This is exploitable for...

1 affected package

golang-opentelemetry-otel

Package 22.04 LTS
golang-opentelemetry-otel Needs evaluation
Show less packages

CVE-2026-39864

Medium priority
Needs evaluation

Kamailio is an open source implementation of a SIP Signaling Server. Prior to 6.0.5 and 5.8.7, an out-of-bounds read in the auth module of Kamailio (formerly OpenSER and SER) allows remote attackers to cause a denial of service...

1 affected package

kamailio

Package 22.04 LTS
kamailio Needs evaluation
Show less packages