Search CVE reports


Toggle filters

591 – 600 of 41351 results

Status is adjusted based on your filters.


CVE-2026-21876

Medium priority
Needs evaluation

The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 4.22.0 and 3.3.8, the current rule 922110 has a bug when processing multipart requests...

1 affected package

modsecurity-crs

Package 18.04 LTS
modsecurity-crs Needs evaluation
Show less packages

CVE-2026-0719

Medium priority
Vulnerable

A flaw was identified in the NTLM authentication handling of the libsoup HTTP library, used by GNOME and other applications for network communication. When processing extremely long passwords, an internal size calculation can...

2 affected packages

libsoup2.4, libsoup3

Package 18.04 LTS
libsoup2.4 Vulnerable
libsoup3
Show less packages

CVE-2026-21441

Medium priority
Ignored

urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at...

2 affected packages

python-urllib3, python-pip

Package 18.04 LTS
python-urllib3 Ignored
python-pip Ignored
Show less packages

CVE-2025-14017

Medium priority
Needs evaluation

When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl, changing TLS options in one thread would inadvertently change them globally and therefore possibly also affect other concurrently setup transfers. Disabling...

1 affected package

curl

Package 18.04 LTS
curl Needs evaluation
Show less packages

CVE-2025-13151

Medium priority
Needs evaluation

Stack-based buffer overflow in libtasn1 version: v4.20.0. The function fails to validate the size of input data resulting in a buffer overflow in asn1_expend_octet_string.

1 affected package

libtasn1-6

Package 18.04 LTS
libtasn1-6 Needs evaluation
Show less packages

CVE-2026-22185

Medium priority
Vulnerable

OpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and including 0.9.14, prior to commit 8e1fda8, contain a heap buffer underflow in the readline() function of mdb_load. When processing malformed input containing an...

2 affected packages

openldap, lmdb

Package 18.04 LTS
openldap Not affected
lmdb Vulnerable
Show less packages

CVE-2026-22184

Medium priority
Needs evaluation

zlib versions up to and including 1.3.1.2 include a global buffer overflow in the untgz utility located under contrib/untgz. The vulnerability is limited to the standalone demonstration utility and does not affect the core zlib...

4 affected packages

zlib, rsync, zsync, klibc

Package 18.04 LTS
zlib Not affected
rsync Not affected
zsync Needs evaluation
klibc Not affected
Show less packages

CVE-2025-12543

High priority
Needs evaluation

A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result, requests...

1 affected package

undertow

Package 18.04 LTS
undertow Needs evaluation
Show less packages

CVE-2025-15224

Low priority
Vulnerable

When doing SSH-based transfers using either SCP or SFTP, and asked to do public key authentication, curl would wrongly still ask and authenticate using a locally running SSH agent.

1 affected package

curl

Package 18.04 LTS
curl Vulnerable
Show less packages

CVE-2025-15079

Low priority
Vulnerable

When doing SSH-based transfers using either SCP or SFTP, and setting the known_hosts file, libcurl could still mistakenly accept connecting to hosts *not present* in the specified file if they were added as recognized in...

1 affected package

curl

Package 18.04 LTS
curl Vulnerable
Show less packages