Search CVE reports


Toggle filters

131 – 140 of 49291 results

Status is adjusted based on your filters.


CVE-2026-75893

Medium priority
Needs evaluation

In osmo-bsc from 1.0.1 through 1.14.1 a heap based buffer overflow issue was found in the ipaccess_proxy_read_msg()  function via IPA frame lengths.

1 affected package

osmo-bsc

Package 20.04 LTS
osmo-bsc Needs evaluation
Show less packages

CVE-2026-75892

Medium priority
Needs evaluation

In osmo-ggsn 1.14.0 an out of bounds write issue was found in the gtp_decode_pdp_ctx() function through the PDP context GSN-Address sub-field, leading to memory corruption.

1 affected package

osmo-ggsn

Package 20.04 LTS
osmo-ggsn Needs evaluation
Show less packages

CVE-2026-93751

Medium priority
Needs evaluation

uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlong percent-encoded sequences into ASCII metacharacters. Attackers can craft percent-encoded payloads to bypass...

1 affected package

node-uri-js

Package 20.04 LTS
node-uri-js Needs evaluation
Show less packages

CVE-2026-93750

Medium priority
Needs evaluation

http-cache-semantics through 4.2.0 contains a cache validation vulnerability in the _varyMatches() function that fails to properly validate Vary header wildcards due to byte-for-byte string comparison. Attackers can request URLs...

1 affected package

node-got

Package 20.04 LTS
node-got Needs evaluation
Show less packages

CVE-2026-93749

Medium priority
Needs evaluation

source-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source maps, allowing attackers to specify arbitrary numeric values. Attackers can supply extremely large offset line values that cause...

1 affected package

node-postcss

Package 20.04 LTS
node-postcss Needs evaluation
Show less packages

CVE-2026-93748

Medium priority
Needs evaluation

http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other users....

1 affected package

node-got

Package 20.04 LTS
node-got Needs evaluation
Show less packages

CVE-2026-84975

Medium priority
Needs evaluation

PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the OpenSSL and GnuTLS backends in pjlib/src/pj/ssl_sock_ossl.c and pjlib/src/pj/ssl_sock_gtls.c copy DNS SubjectAltName values...

2 affected packages

asterisk, pjproject

Package 20.04 LTS
asterisk Needs evaluation
pjproject —
Show less packages

CVE-2026-77396

Medium priority
Needs evaluation

PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the PJSIP AVI parser in pjmedia/src/pjmedia/avi_player.c uses an input-file video chunk length as the number of bytes copied into...

2 affected packages

asterisk, pjproject

Package 20.04 LTS
asterisk Needs evaluation
pjproject —
Show less packages

CVE-2026-69186

Medium priority
Needs evaluation

c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_parse() trusts the attacker-controlled ANCOUNT, NSCOUNT, and ARCOUNT fields before confirming that the DNS response contains enough bytes for the claimed...

1 affected package

c-ares

Package 20.04 LTS
c-ares Needs evaluation
Show less packages

CVE-2026-69184

Medium priority
Needs evaluation

c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_name_parse() enforces backward DNS compression pointers but does not bound the total pointer hops or assembled name length. A malicious DNS server can send a...

1 affected package

c-ares

Package 20.04 LTS
c-ares Needs evaluation
Show less packages