Search CVE reports


Toggle filters

131 – 140 of 48501 results

Status is adjusted based on your filters.


CVE-2026-5704

Medium priority
Needs evaluation

A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction...

1 affected package

tar

Package 16.04 LTS
tar Needs evaluation
Show less packages

CVE-2026-34982

Medium priority
Not affected

Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader`...

1 affected package

vim

Package 16.04 LTS
vim Not affected
Show less packages

CVE-2026-34589

Medium priority
Needs evaluation

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9, and 3.4.9, the DWA lossy decoder...

1 affected package

openexr

Package 16.04 LTS
openexr Needs evaluation
Show less packages

CVE-2026-34588

Medium priority
Needs evaluation

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.1.0 to before 3.2.7, 3.3.9, and 3.4.9, internal_exr_undo_piz() advances the...

1 affected package

openexr

Package 16.04 LTS
openexr Needs evaluation
Show less packages

CVE-2026-34380

Medium priority
Needs evaluation

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9, and 3.4.9, a signed integer overflow exists in...

1 affected package

openexr

Package 16.04 LTS
openexr Needs evaluation
Show less packages

CVE-2026-34379

Medium priority
Needs evaluation

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9, and 3.4.9, a misaligned memory write vulnerability...

1 affected package

openexr

Package 16.04 LTS
openexr Needs evaluation
Show less packages

CVE-2026-34378

Medium priority
Needs evaluation

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.4.0 to before 3.4.9, a missing bounds check on the dataWindow attribute in EXR...

1 affected package

openexr

Package 16.04 LTS
openexr Needs evaluation
Show less packages

CVE-2026-5663

Medium priority
Needs evaluation

A security flaw has been discovered in OFFIS DCMTK up to 3.7.0. This impacts the function executeOnReception/executeOnEndOfStudy of the file dcmnet/apps/storescp.cc of the component storescp. Performing a manipulation results in...

1 affected package

dcmtk

Package 16.04 LTS
dcmtk Needs evaluation
Show less packages

CVE-2026-33540

Medium priority
Needs evaluation

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, in pull-through cache mode, distribution discovers token auth endpoints by parsing WWW-Authenticate challenges returned by...

1 affected package

docker-registry

Package 16.04 LTS
docker-registry Needs evaluation
Show less packages

CVE-2026-29047

Medium priority
Needs evaluation

GLPI is a free asset and IT management software package. From 10.0.0 to before 10.0.24 and 11.0.6, an authenticated user can perform a SQL injection via the logs export feature. This vulnerability is fixed in 10.0.24 and 11.0.6.

1 affected package

glpi

Package 16.04 LTS
glpi Needs evaluation
Show less packages