Search CVE reports


Toggle filters

1481 – 1490 of 35261 results

Status is adjusted based on your filters.


CVE-2026-6100

Medium priority
Needs evaluation

Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used. This scenario can be...

13 affected packages

pypy3, python2.7, python3.4, python3.5, python3.6...

Package 24.04 LTS
pypy3 Needs evaluation
python2.7 Not in release
python3.4 Not in release
python3.5 Not in release
python3.6 Not in release
python3.7 Not in release
python3.8 Not in release
python3.9 Not in release
python3.10 Not in release
python3.11 Not in release
python3.12 Needs evaluation
python3.13 Not in release
python3.14 Not in release
Show all 13 packages Show less packages

CVE-2026-32316

Medium priority
Fixed

jq is a command-line JSON processor. An integer overflow vulnerability exists through version 1.8.1 within the jvp_string_append() and jvp_string_copy_replace_bad functions, where concatenating strings with a combined length...

1 affected package

jq

Package 24.04 LTS
jq Fixed
Show less packages

CVE-2026-6192

Medium priority
Needs evaluation

A vulnerability was identified in uclouvain openjpeg up to 2.5.4. This impacts the function opj_pi_initialise_encode in the library src/lib/openjp2/pi.c. The manipulation leads to integer overflow. The attack must be carried out...

7 affected packages

openjpeg2, insighttoolkit4, qtwebengine-opensource-src, blender, texmaker...

Package 24.04 LTS
openjpeg2 Needs evaluation
insighttoolkit4 Not in release
qtwebengine-opensource-src Needs evaluation
blender Needs evaluation
texmaker Needs evaluation
ghostscript Not affected
openjpeg Not in release
Show all 7 packages Show less packages

CVE-2026-33555

Medium priority
Fixed

An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can...

1 affected package

haproxy

Package 24.04 LTS
haproxy Fixed
Show less packages

CVE-2026-6231

Medium priority
Needs evaluation

The bson_validate function may return early on specific inputs and incorrectly report success. This behavior could result in skipping validation for BSON data, allowing malformed or invalid UTF-8 sequences to bypass validation and...

1 affected package

mongo-c-driver

Package 24.04 LTS
mongo-c-driver Needs evaluation
Show less packages

CVE-2026-30999

Medium priority
Needs evaluation

A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.

2 affected packages

ffmpeg, libav

Package 24.04 LTS
ffmpeg Needs evaluation
libav Not in release
Show less packages

CVE-2026-30998

Medium priority
Needs evaluation

An improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input file.

2 affected packages

ffmpeg, libav

Package 24.04 LTS
ffmpeg Needs evaluation
libav Not in release
Show less packages

CVE-2026-30997

Medium priority
Needs evaluation

An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.

2 affected packages

ffmpeg, libav

Package 24.04 LTS
ffmpeg Needs evaluation
libav Not in release
Show less packages

CVE-2026-29628

Medium priority
Needs evaluation

A stack overflow in the experimental/tinyobj_loader_opt.h file of tinyobjloader commit d56555b allows attackers to cause a Denial of Service (DoS) via supplying a crafted .mtl file.

1 affected package

tinyobjloader

Package 24.04 LTS
tinyobjloader Needs evaluation
Show less packages

CVE-2026-1462

Medium priority

Not in release

A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization of `.keras` models, even when `safe_mode=True`. This bypasses...

1 affected package

keras

Package 24.04 LTS
keras Not in release
Show less packages