Search CVE reports


Toggle filters

681 – 690 of 41446 results

Status is adjusted based on your filters.


CVE-2025-14505

Medium priority
Needs evaluation

The ECDSA implementation of the Elliptic package generates incorrect signatures if an interim value of 'k' (as computed based on step 3.2 of RFC 6979 https://datatracker.ietf.org/doc/html/rfc6979 ) has leading zeros and is...

1 affected package

node-elliptic

Package 18.04 LTS
node-elliptic Needs evaluation
Show less packages

CVE-2026-21860

Medium priority
Not affected

Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.5, Werkzeug's safe_join function allows path segments with Windows device names that have file extensions or trailing spaces. On Windows, there are...

1 affected package

python-werkzeug

Package 18.04 LTS
python-werkzeug Not affected
Show less packages

CVE-2026-22028

Medium priority
Needs evaluation

Preact, a lightweight web development framework, JSON serialization protection to prevent Virtual DOM elements from being constructed from arbitrary JSON. A regression introduced in Preact 10.26.5 caused this protection to be...

1 affected package

node-preact

Package 18.04 LTS
node-preact Needs evaluation
Show less packages

CVE-2025-66003

Medium priority
Needs evaluation

An External Control of File Name or Path vulnerability in smb4k allowsl ocal users to perform a local root exploit via smb4k mounthelper if they can access and control the contents of a Samba shareThis issue affects smb4k: from ?...

1 affected package

smb4k

Package 18.04 LTS
smb4k Needs evaluation
Show less packages

CVE-2025-66002

Medium priority
Needs evaluation

An Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability allows local users ton perform arbitrary unmounts via smb4k mount helper

1 affected package

smb4k

Package 18.04 LTS
smb4k Needs evaluation
Show less packages

CVE-2026-21876

Medium priority
Needs evaluation

The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 4.22.0 and 3.3.8, the current rule 922110 has a bug when processing multipart requests...

1 affected package

modsecurity-crs

Package 18.04 LTS
modsecurity-crs Needs evaluation
Show less packages

CVE-2026-0719

Medium priority
Vulnerable

A flaw was identified in the NTLM authentication handling of the libsoup HTTP library, used by GNOME and other applications for network communication. When processing extremely long passwords, an internal size calculation can...

2 affected packages

libsoup2.4, libsoup3

Package 18.04 LTS
libsoup2.4 Vulnerable
libsoup3
Show less packages

CVE-2026-21441

Medium priority
Ignored

urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at...

2 affected packages

python-urllib3, python-pip

Package 18.04 LTS
python-urllib3 Ignored
python-pip Ignored
Show less packages

CVE-2025-14017

Medium priority
Needs evaluation

When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl, changing TLS options in one thread would inadvertently change them globally and therefore possibly also affect other concurrently setup transfers. Disabling...

1 affected package

curl

Package 18.04 LTS
curl Needs evaluation
Show less packages

CVE-2025-13151

Medium priority
Needs evaluation

Stack-based buffer overflow in libtasn1 version: v4.20.0. The function fails to validate the size of input data resulting in a buffer overflow in asn1_expend_octet_string.

1 affected package

libtasn1-6

Package 18.04 LTS
libtasn1-6 Needs evaluation
Show less packages