Search CVE reports


Toggle filters

831 – 840 of 45011 results

Status is adjusted based on your filters.


CVE-2026-59638

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA)...

1 affected package

bouncycastle

Package 20.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-15055

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips...

1 affected package

bouncycastle

Package 20.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-12185

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before integrity check. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

1 affected package

bouncycastle

Package 20.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-68580

Medium priority
Needs evaluation

FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers....

3 affected packages

freerdp, freerdp2, freerdp3

Package 20.04 LTS
freerdp
freerdp2 Needs evaluation
freerdp3
Show less packages

CVE-2026-68579

Medium priority
Needs evaluation

FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_Read function (client/Windows/wf_cliprdr.c). When an OLE paste consumer (e.g. explorer.exe) calls...

3 affected packages

freerdp, freerdp2, freerdp3

Package 20.04 LTS
freerdp
freerdp2 Needs evaluation
freerdp3
Show less packages

CVE-2026-9335

Medium priority
Needs evaluation

A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improper handling of HDF5 ExternalLinks. The `KerasFileEditor` and `keras.saving.load_weights` functions bypass the...

1 affected package

keras

Package 20.04 LTS
keras Needs evaluation
Show less packages

CVE-2026-67326

Medium priority
Needs evaluation

GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary section headers into .git/config. Attackers can inject newlines to create a forged...

1 affected package

python-git

Package 20.04 LTS
python-git Needs evaluation
Show less packages

CVE-2026-67325

Medium priority
Needs evaluation

GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by using abbreviated option names...

1 affected package

python-git

Package 20.04 LTS
python-git Needs evaluation
Show less packages

CVE-2026-67324

Medium priority
Needs evaluation

GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default unsafe-option gate. When an application passes attacker-influenced clone options...

1 affected package

python-git

Package 20.04 LTS
python-git Needs evaluation
Show less packages

CVE-2026-67323

Medium priority
Needs evaluation

GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to arbitrary...

1 affected package

python-git

Package 20.04 LTS
python-git Needs evaluation
Show less packages