Search CVE reports


Toggle filters

561 – 570 of 53354 results

Status is adjusted based on your filters.


CVE-2026-72568

Medium priority
Needs evaluation

An out-of-bounds read vulnerability in Redis through 8.8.1 allows an adjacent unauthenticated attacker to cause denial of service or information disclosure by sending a specially crafted PING message to the Redis Cluster Bus port.

1 affected package

redis

Package 16.04 LTS
redis Needs evaluation
Show less packages

CVE-2026-71394

Medium priority
Needs evaluation

GNU Emacs for Android improperly validates the table header input in sfnt_read_table_directory() in src/sfnt.c. Due to an incorrect comparison variable in the read-length check, a crafted font file that claims to contain more...

5 affected packages

emacs, xemacs21, xemacs21-packages, emacs24, emacs25

Package 16.04 LTS
emacs
xemacs21 Needs evaluation
xemacs21-packages Needs evaluation
emacs24 Needs evaluation
emacs25
Show less packages

CVE-2026-71393

Medium priority
Needs evaluation

GNU Emacs for Android is vulnerable to an integer overflow in sfnt_read_name_table() in src/sfnt.c. The function computes an allocation size using a 32-bit length value from a TrueType font file without overflow checking. On...

5 affected packages

emacs, xemacs21, xemacs21-packages, emacs24, emacs25

Package 16.04 LTS
emacs
xemacs21 Needs evaluation
xemacs21-packages Needs evaluation
emacs24 Needs evaluation
emacs25
Show less packages

CVE-2026-71392

Medium priority
Needs evaluation

GNU Emacs for Android is vulnerable to an integer overflow in the sfnt_read_cmap_format_12() function in src/sfnt.c. When processing a crafted TrueType font file, an unguarded addition in the xmalloc allocation call wraps around...

5 affected packages

emacs, xemacs21, xemacs21-packages, emacs24, emacs25

Package 16.04 LTS
emacs
xemacs21 Needs evaluation
xemacs21-packages Needs evaluation
emacs24 Needs evaluation
emacs25
Show less packages

CVE-2026-71391

Medium priority
Needs evaluation

GNU Emacs for Android contains an off-by-one error in the gvar table parser in src/sfnt.c. The shared-coordinate index boundary check in sfnt_vary_simple_glyph() and sfnt_vary_compound_glyph() uses a strict greater-than comparison...

5 affected packages

emacs, xemacs21, xemacs21-packages, emacs24, emacs25

Package 16.04 LTS
emacs
xemacs21 Needs evaluation
xemacs21-packages Needs evaluation
emacs24 Needs evaluation
emacs25
Show less packages

CVE-2026-66486

Medium priority
Needs evaluation

GNU cpio is vulnerable to improper encoding or escaping of output in its archive member listing functionality. When listing archive members via cpio -it, member names are printed directly to output without quoting or escaping. An...

1 affected package

cpio

Package 16.04 LTS
cpio Needs evaluation
Show less packages

CVE-2026-66485

Medium priority
Needs evaluation

GNU cpio is vulnerable to an uncontrolled memory allocation in the make_path function at src/makepath.c. The function uses alloca to allocate stack memory based on the length of argpath, which is derived from an archive-controlled...

1 affected package

cpio

Package 16.04 LTS
cpio Needs evaluation
Show less packages

CVE-2026-66484

Medium priority
Needs evaluation

GNU cpio contains a Path Traversal vulnerability in its tar archive extraction functionality. When extracting a tar archive in copy-in mode with the --no-absolute-filenames option, the extracted file name is normalized but the tar...

1 affected package

cpio

Package 16.04 LTS
cpio Needs evaluation
Show less packages

CVE-2026-72522

Medium priority
Needs evaluation

libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.

23 affected packages

expat, apache2, apr-util, cmake, ghostscript...

Package 16.04 LTS
expat Needs evaluation
apache2 Not affected
apr-util Not affected
cmake Not affected
ghostscript Not affected
texlive-bin Not affected
xmlrpc-c Needs evaluation
vnc4 Needs evaluation
wbxml2 Needs evaluation
swish-e Needs evaluation
insighttoolkit4 Needs evaluation
cadaver Needs evaluation
gdcm Needs evaluation
ayttm Needs evaluation
cableswig Needs evaluation
coin3 Needs evaluation
matanza Needs evaluation
tdom Needs evaluation
vtk Needs evaluation
smart Needs evaluation
firefox
thunderbird
libxmltok Needs evaluation
Show all 23 packages Show less packages

CVE-2026-16742

Medium priority
Not affected

systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user

1 affected package

systemd

Package 16.04 LTS
systemd Not affected
Show less packages