Search CVE reports


Toggle filters

1221 – 1230 of 46017 results

Status is adjusted based on your filters.


CVE-2026-73076

Medium priority
Vulnerable

Vim is an open source, command line text editor. Prior to 9.2.0847, runtime/autoload/vimball.vim allows a crafted vimball member named .VimballRecord to overwrite the installation record with attacker-chosen commands. When...

1 affected package

vim

Package 20.04 LTS
vim Vulnerable
Show less packages

CVE-2026-73075

Medium priority
Not affected

Vim is an open source, command line text editor. From 9.2.0469 until 9.2.0843, popup_mark_opacity_zindex() in src/popupwin.c can use a negative w_winrow for a text-property-anchored popup with clipwindow and opacity, indexing...

1 affected package

vim

Package 20.04 LTS
vim Not affected
Show less packages

CVE-2026-73074

Medium priority
Not affected

Vim is an open source, command line text editor. Prior to 9.2.0841, prop_add_one() in src/textprop.c uses the proplen value from get_text_props() to increment a uint16_t property count beyond 0xffff, wrapping the count to zero and...

1 affected package

vim

Package 20.04 LTS
vim Not affected
Show less packages

CVE-2026-73072

Medium priority
Vulnerable

Vim is an open source, command line text editor. Prior to 9.2.0846, set_sofo() in src/spellfile.c reuses sl_sal_first[] without resetting values left by set_sal_first(), so a crafted spell file containing an SN_SAL section before...

1 affected package

vim

Package 20.04 LTS
vim Vulnerable
Show less packages

CVE-2026-73071

Medium priority
Not affected

Vim is an open source, command line text editor. From 9.2.0511 until 9.2.0844, json_decode_item() in src/json.c can retain a stale pointer after json_decode_string() invokes channel_fill() to refill and free the current buffer,...

1 affected package

vim

Package 20.04 LTS
vim Not affected
Show less packages

CVE-2026-73070

Medium priority
Not affected

Vim is an open source, command line text editor. Prior to 9.2.0842, the socket server backend in src/socketserver.c accepts unbounded client connections in socketserver_accept(), causing descriptors to overflow fd_set structures...

1 affected package

vim

Package 20.04 LTS
vim Not affected
Show less packages

CVE-2026-19546

Medium priority
Needs evaluation

A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.z. For a detailed Statement, Description and Mitigation please reffer to the original...

1 affected package

libdbi-perl

Package 20.04 LTS
libdbi-perl Needs evaluation
Show less packages

CVE-2026-14180

Medium priority
Needs evaluation

A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to handle chunked transfer encoding. The issue occurs because the parser uses a single internal variable to store...

1 affected package

undertow

Package 20.04 LTS
undertow Needs evaluation
Show less packages

CVE-2026-73067

Medium priority
Needs evaluation

Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata model loaded through TessBaseAPI::Init can cause SquishedDawg::read_squished_dawg in src/dict/dawg.cpp to accept an unterminated forward-edge run,...

1 affected package

tesseract

Package 20.04 LTS
tesseract Needs evaluation
Show less packages

CVE-2026-73066

Medium priority
Needs evaluation

Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata LSTM model component loaded through Tesseract's deserializer can cause an unchecked signed integer multiplication in Convolve::DeSerialize in...

1 affected package

tesseract

Package 20.04 LTS
tesseract Needs evaluation
Show less packages