Search CVE reports


Toggle filters

91 – 100 of 48565 results

Status is adjusted based on your filters.


CVE-2026-5264

Medium priority
Needs evaluation

Heap buffer overflow in DTLS 1.3 ACK message processing. A remote attacker can send a crafted DTLS 1.3 ACK message that triggers a heap buffer overflow.

1 affected package

wolfssl

Package 16.04 LTS
wolfssl Needs evaluation
Show less packages

CVE-2026-5263

Medium priority
Needs evaluation

URI nameConstraints from constrained intermediate CAs are parsed but not enforced during certificate chain verification in wolfcrypt/src/asn.c. A compromised or malicious sub-CA could issue leaf certificates with URI SAN entries...

1 affected package

wolfssl

Package 16.04 LTS
wolfssl Needs evaluation
Show less packages

CVE-2026-5194

Medium priority
Needs evaluation

Missing hash/digest size and OID checks allow digests smaller than allowed when verifying ECDSA certificates, or smaller than is appropriate for the relevant key type, to be accepted by signature verification functions. This could...

1 affected package

wolfssl

Package 16.04 LTS
wolfssl Needs evaluation
Show less packages

CVE-2026-5188

Medium priority
Needs evaluation

An integer underflow issue exists in wolfSSL when parsing the Subject Alternative Name (SAN) extension of X.509 certificates. A malformed certificate can specify an entry length larger than the enclosing sequence, causing the...

1 affected package

wolfssl

Package 16.04 LTS
wolfssl Needs evaluation
Show less packages

CVE-2026-5187

Medium priority
Needs evaluation

Two potential heap out-of-bounds write locations existed in DecodeObjectId() in wolfcrypt/src/asn.c. First, a bounds check only validates one available slot before writing two OID arc values (out[0] and out[1]), enabling a 2-byte...

1 affected package

wolfssl

Package 16.04 LTS
wolfssl Needs evaluation
Show less packages

CVE-2026-40046

Medium priority
Needs evaluation

Integer Overflow or Wraparound vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT. The fix for "CVE-2025-66168: MQTT control packet remaining length field is not properly validated" was only applied to...

1 affected package

activemq

Package 16.04 LTS
activemq Needs evaluation
Show less packages

CVE-2026-39856

Medium priority
Needs evaluation

osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.13, an out-of-bounds read vulnerability exists in osslsigncode version 2.12 and earlier in the PE page-hash computation...

1 affected package

osslsigncode

Package 16.04 LTS
osslsigncode Needs evaluation
Show less packages

CVE-2026-39855

Medium priority
Needs evaluation

osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.13, an integer underflow vulnerability exists in osslsigncode version 2.12 and earlier in the PE page-hash computation...

1 affected package

osslsigncode

Package 16.04 LTS
osslsigncode Needs evaluation
Show less packages

CVE-2026-39853

Medium priority
Needs evaluation

osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.12, A stack buffer overflow vulnerability exists in osslsigncode in several signature verification paths. During verification of a PKCS#7...

1 affected package

osslsigncode

Package 16.04 LTS
osslsigncode Needs evaluation
Show less packages

CVE-2026-39304

Medium priority
Needs evaluation

[Unknown description]

1 affected package

activemq

Package 16.04 LTS
activemq Needs evaluation
Show less packages