Search CVE reports


Toggle filters

921 – 930 of 45011 results

Status is adjusted based on your filters.


CVE-2026-16530

Medium priority
Needs evaluation

A flaw was found in the PCP (Performance Co-Pilot) `pmproxy` service. A remote attacker can exploit a vulnerability in the `pmLogLoadInDom()` function by sending a specially crafted request. This bypasses a critical bounds check,...

1 affected package

pcp

Package 20.04 LTS
pcp Needs evaluation
Show less packages

CVE-2026-16529

Medium priority
Needs evaluation

A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network packets during PDU processing or SASL negotiation. This permanently blinds the affected daemon, resulting in a total denial of service...

1 affected package

pcp

Package 20.04 LTS
pcp Needs evaluation
Show less packages

CVE-2026-16527

Medium priority
Needs evaluation

An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.

1 affected package

pcp

Package 20.04 LTS
pcp Needs evaluation
Show less packages

CVE-2026-16526

Medium priority
Needs evaluation

A flaw in the PCP linux_sockets module exposes an unsecured internal connection. An attacker with initial code execution can exploit this to escalate privileges and execute arbitrary commands as root.

1 affected package

pcp

Package 20.04 LTS
pcp Needs evaluation
Show less packages

CVE-2026-16524

Medium priority
Needs evaluation

A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric. This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh.

1 affected package

pcp

Package 20.04 LTS
pcp Needs evaluation
Show less packages

CVE-2026-64685

Medium priority
Needs evaluation

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, the BGR decoder does not check for an end-of-file in every location so a crafted image could result in...

1 affected package

imagemagick

Package 20.04 LTS
imagemagick Needs evaluation
Show less packages

CVE-2026-62946

Medium priority
Needs evaluation

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to both 6.9.13-52 and 7.1.2-27, processing an extremely large JNX file on 32-bit platforms can cause an integer...

1 affected package

imagemagick

Package 20.04 LTS
imagemagick Needs evaluation
Show less packages

CVE-2026-62363

Medium priority
Needs evaluation

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, a heap buffer over-write can occur in the fx operation by passing a crafted argument. This issue has...

1 affected package

imagemagick

Package 20.04 LTS
imagemagick Needs evaluation
Show less packages

CVE-2026-62343

Medium priority
Needs evaluation

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 6.9.13-51 and 7.0.1-0 and above prior to 7.1.2-26, an invalid kernel can cause a heap buffer over-write when...

1 affected package

imagemagick

Package 20.04 LTS
imagemagick Needs evaluation
Show less packages

CVE-2026-59898

Medium priority
Needs evaluation

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ab attacker can force WebSocket upgrade via the lax V07 (or V08) handshaker by sending `Sec-WebSocket-Version:...

1 affected package

netty

Package 20.04 LTS
netty Needs evaluation
Show less packages