Search CVE reports


Toggle filters

81 – 90 of 31404 results

Status is adjusted based on your filters.


CVE-2026-16349

Medium priority
Not affected

Same-origin policy bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 26.04 LTS
firefox Not affected
thunderbird Not affected
mozjs38 Not in release
mozjs52 Not in release
mozjs68 Not in release
mozjs78 Not in release
mozjs91 Not in release
mozjs102 Not in release
mozjs115 Not in release
Show all 9 packages Show less packages

CVE-2026-59845

Medium priority
Needs evaluation

A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service.

1 affected package

libssh

Package 26.04 LTS
libssh Needs evaluation
Show less packages

CVE-2026-59844

Medium priority
Needs evaluation

A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests.

1 affected package

libssh

Package 26.04 LTS
libssh Needs evaluation
Show less packages

CVE-2026-59843

Medium priority
Needs evaluation

A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service.

1 affected package

libssh

Package 26.04 LTS
libssh Needs evaluation
Show less packages

CVE-2026-59842

Medium priority
Not affected

A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. This...

1 affected package

libssh

Package 26.04 LTS
libssh Not affected
Show less packages

CVE-2026-16461

Medium priority
Needs evaluation

A stack-based buffer overflow was found in rpcbind's rpcinfo utility. In rpcbdump() short mode (used by `rpcinfo -s`), version numbers from a remote RPCBPROC_DUMP reply are written into a fixed-size stack buffer without bounds...

1 affected package

rpcbind

Package 26.04 LTS
rpcbind Needs evaluation
Show less packages

CVE-2026-15370

Medium priority
Needs evaluation

A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes the server to list attacker-controlled filenames,...

1 affected package

libssh

Package 26.04 LTS
libssh Needs evaluation
Show less packages

CVE-2026-8593

Medium priority

Not in release

Improper permission enforcement in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL) allows users without permissions to view and modify BI packs and rules

1 affected package

check-mk

Package 26.04 LTS
check-mk Not in release
Show less packages

CVE-2026-15812

Medium priority
Needs evaluation

A vulnerability was found in the internal Access Control List (ACL) subsystem of kronosnet (Version affected: <= 1.34). When the framework is explicitly configured to manage dynamic links (accepting network traffic from any IP...

1 affected package

kronosnet

Package 26.04 LTS
kronosnet Needs evaluation
Show less packages

CVE-2026-63729

Medium priority
Needs evaluation

The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince contains a heap use-after-free vulnerability that allows attackers to crash applications or potentially execute...

1 affected package

texlive-bin

Package 26.04 LTS
texlive-bin Needs evaluation
Show less packages