Search CVE reports


Toggle filters

681 – 690 of 39943 results

Status is adjusted based on your filters.


CVE-2026-23918

High priority
Not affected

Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

1 affected package

apache2

Package 20.04 LTS
apache2 Not affected
Show less packages

CVE-2026-42151

Medium priority
Needs evaluation

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string...

1 affected package

prometheus

Package 20.04 LTS
prometheus Needs evaluation
Show less packages

CVE-2026-42146

Medium priority
Needs evaluation

CImg Library is a C++ library for image processing. Prior to commit c3aacf5, the nb_colors field read from the BMP file header is used directly to compute an allocation size without validating it against the remaining file size. A...

1 affected package

cimg

Package 20.04 LTS
cimg Needs evaluation
Show less packages

CVE-2026-42144

Medium priority
Needs evaluation

CImg Library is a C++ library for image processing. Prior to commit 4ca26bc, there is an integer overflow vulnerability in the W*H*D size computation inside _load_pnm() that can bypass the memory allocation guard. A crafted...

1 affected package

cimg

Package 20.04 LTS
cimg Needs evaluation
Show less packages

CVE-2026-42052

Medium priority
Needs evaluation

Beets is the media library management system. Prior to version 2.10.0, the bundled web UI uses Underscore template interpolation mode <%= ... %> for untrusted metadata fields. In this runtime, <%= ... %> is raw insertion and HTML...

1 affected package

beets

Package 20.04 LTS
beets Needs evaluation
Show less packages

CVE-2026-37459

Medium priority
Needs evaluation

An integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.

2 affected packages

frr, quagga

Package 20.04 LTS
frr Needs evaluation
quagga Needs evaluation
Show less packages

CVE-2026-29004

Medium priority
Needs evaluation

BusyBox before commit 42202bf contains a heap buffer overflow vulnerability in the DHCPv6 client (udhcpc6) DNS_SERVERS option handler in networking/udhcp/d6_dhcpc.c that allows network-adjacent attackers to trigger memory...

1 affected package

busybox

Package 20.04 LTS
busybox Needs evaluation
Show less packages

CVE-2026-42440

Medium priority
Needs evaluation

OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP AbstractModelReader Versions Affected: before 2.5.9 before 3.0.0-M3 Description: The AbstractModelReader methods getOutcomes(), getOutcomePatterns(),...

1 affected package

apache-opennlp

Package 20.04 LTS
apache-opennlp Needs evaluation
Show less packages

CVE-2026-40682

Medium priority
Needs evaluation

XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor Versions Affected: before 2.5.9, before 3.0.0-M3 Description: The DictionaryEntryPersistor class initializes a...

1 affected package

apache-opennlp

Package 20.04 LTS
apache-opennlp Needs evaluation
Show less packages

CVE-2026-37461

Medium priority
Needs evaluation

An out-of-bounds read in the ParseIP6Extended function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.

1 affected package

gobgp

Package 20.04 LTS
gobgp Needs evaluation
Show less packages