Search CVE reports


Toggle filters

81 – 90 of 49226 results

Status is adjusted based on your filters.


CVE-2026-93453

Medium priority
Needs evaluation

SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing unauthenticated attackers to redirect recovery tokens to attacker-controlled domains. Attackers can submit...

1 affected package

sogo

Package 20.04 LTS
sogo Needs evaluation
Show less packages

CVE-2026-93452

Medium priority
Needs evaluation

snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of the destination buffer. Attackers can supply incompressible data that exceeds the...

1 affected package

snappy-java

Package 20.04 LTS
snappy-java Needs evaluation
Show less packages

CVE-2026-93451

Medium priority
Needs evaluation

snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in typed Snappy.uncompress*Array methods that allocate output arrays by dividing uncompressed length by element size but pass the undivided length to native...

1 affected package

snappy-java

Package 20.04 LTS
snappy-java Needs evaluation
Show less packages

CVE-2026-93395

Medium priority
Needs evaluation

A missing lower-bound validation in the bson_new_from_buffer() function of libbson allows an integer underflow when processing BSON data with a zero-length prefix. The function reads a 32-bit document length from the input buffer...

1 affected package

mongo-c-driver

Package 20.04 LTS
mongo-c-driver Needs evaluation
Show less packages

CVE-2026-93394

Medium priority
Needs evaluation

A flaw in libmongoc's SCRAM authentication implementation caused the client to continue the authentication handshake and transmit the client proof even when a nonce mismatch was detected in the server's first message....

1 affected package

mongo-c-driver

Package 20.04 LTS
mongo-c-driver Needs evaluation
Show less packages

CVE-2026-93393

Medium priority
Needs evaluation

A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A remote endpoint that the client connects to can cause the driver to write uncontrolled data...

1 affected package

mongo-c-driver

Package 20.04 LTS
mongo-c-driver Needs evaluation
Show less packages

CVE-2026-93331

Medium priority
Needs evaluation

A vulnerability was identified in GPAC 26.08-DEV. This vulnerability affects the function gf_rtp_parse_ttxt of the file src/ietf/rtp_depacketizer.c of the component RTP Depacketizer. Such manipulation of the argument size leads to...

1 affected package

gpac

Package 20.04 LTS
gpac Needs evaluation
Show less packages

CVE-2026-93314

Medium priority
Needs evaluation

A vulnerability was determined in Freedesktop Poppler 26.07.0. This affects the function FoFiTrueType::mapCodeToGID of the file fofi/FoFiTrueType.cc. Executing a manipulation of the argument segCnt can lead to integer overflow....

1 affected package

poppler

Package 20.04 LTS
poppler Needs evaluation
Show less packages

CVE-2026-93313

Medium priority
Needs evaluation

A vulnerability was found in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTableSeg of the file poppler/JBIG2Stream.cc. Performing a manipulation results in integer overflow. The attack can...

1 affected package

poppler

Package 20.04 LTS
poppler Needs evaluation
Show less packages

CVE-2026-93312

Medium priority
Needs evaluation

A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the function JBIG2Stream::rewind of the file poppler/JBIG2Stream.cc. This manipulation causes null pointer dereference. It is possible to initiate the attack...

1 affected package

poppler

Package 20.04 LTS
poppler Needs evaluation
Show less packages