Search CVE reports


Toggle filters

961 – 970 of 39983 results

Status is adjusted based on your filters.


CVE-2026-41636

Medium priority
Needs evaluation

Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

1 affected package

thrift

Package 20.04 LTS
thrift Needs evaluation
Show less packages

CVE-2026-41605

Medium priority
Needs evaluation

Integer Overflow or Wraparound vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

1 affected package

thrift

Package 20.04 LTS
thrift Needs evaluation
Show less packages

CVE-2026-41604

Medium priority
Needs evaluation

Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

1 affected package

thrift

Package 20.04 LTS
thrift Needs evaluation
Show less packages

CVE-2026-41411

Medium priority
Vulnerable

Vim is an open source, command line text editor. Prior to 9.2.0357, A command injection vulnerability exists in Vim's tag file processing. When resolving a tag, the filename field from the tags file is passed through wildcard...

1 affected package

vim

Package 20.04 LTS
vim Vulnerable
Show less packages

CVE-2026-40356

Medium priority
Needs evaluation

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An...

1 affected package

krb5

Package 20.04 LTS
krb5 Needs evaluation
Show less packages

CVE-2026-40355

Medium priority
Needs evaluation

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker...

1 affected package

krb5

Package 20.04 LTS
krb5 Needs evaluation
Show less packages

CVE-2026-23558

Medium priority
Needs evaluation

[Unknown description]

1 affected package

xen

Package 20.04 LTS
xen Needs evaluation
Show less packages

CVE-2026-23557

Medium priority
Needs evaluation

[Unknown description]

1 affected package

xen

Package 20.04 LTS
xen Needs evaluation
Show less packages

CVE-2026-23556

Medium priority
Needs evaluation

[Unknown description]

1 affected package

xen

Package 20.04 LTS
xen Needs evaluation
Show less packages

CVE-2026-22020

Medium priority
Needs evaluation

[updated libpng in Oracle Java]

11 affected packages

openjdk-8, openjdk-9, openjdk-lts, openjdk-13, openjdk-16...

Package 20.04 LTS
openjdk-8 Needs evaluation
openjdk-9
openjdk-lts Needs evaluation
openjdk-13 Ignored
openjdk-16 Ignored
openjdk-17 Needs evaluation
openjdk-17-crac
openjdk-18
openjdk-21 Needs evaluation
openjdk-21-crac
openjdk-25
Show all 11 packages Show less packages