Search CVE reports


Toggle filters

211 – 220 of 47944 results

Status is adjusted based on your filters.


CVE-2026-77396

Medium priority
Needs evaluation

PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the PJSIP AVI parser in pjmedia/src/pjmedia/avi_player.c uses an input-file video chunk length as the number of bytes copied into...

2 affected packages

asterisk, pjproject

Package 24.04 LTS
asterisk Needs evaluation
pjproject Not in release
Show less packages

CVE-2026-69186

Medium priority
Needs evaluation

c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_parse() trusts the attacker-controlled ANCOUNT, NSCOUNT, and ARCOUNT fields before confirming that the DNS response contains enough bytes for the claimed...

1 affected package

c-ares

Package 24.04 LTS
c-ares Needs evaluation
Show less packages

CVE-2026-69184

Medium priority
Needs evaluation

c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_name_parse() enforces backward DNS compression pointers but does not bound the total pointer hops or assembled name length. A malicious DNS server can send a...

1 affected package

c-ares

Package 24.04 LTS
c-ares Needs evaluation
Show less packages

CVE-2026-64847

Medium priority
Needs evaluation

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Prior to 4.14.2, AnyIO starts process-pool workers with standard error connected to a pipe that the parent never...

1 affected package

python-anyio

Package 24.04 LTS
python-anyio Needs evaluation
Show less packages

CVE-2026-61552

Medium priority
Needs evaluation

Icinga 2 is an open source monitoring system. From 2.4 until 2.14.9, 2.15.4, and 2.16.2, the /v1/objects API writes attacker-controlled template names into generated configuration without escaping them. An authenticated ApiUser...

1 affected package

icinga2

Package 24.04 LTS
icinga2 Needs evaluation
Show less packages

CVE-2026-61551

Medium priority
Needs evaluation

Icinga 2 is an open source monitoring system. Prior to 2.14.9, 2.15.4, and 2.16.2, parsing deeply nested JSON can exhaust the call stack because nesting depth is not bounded. The affected JSON parsing paths are reachable by...

1 affected package

icinga2

Package 24.04 LTS
icinga2 Needs evaluation
Show less packages

CVE-2026-61550

Medium priority
Needs evaluation

Icinga 2 is an open source monitoring system. From 2.8 until 2.14.9, 2.15.4, and 2.16.2, certificate update JSON-RPC message handling does not validate that the sender is a trusted endpoint. An unauthenticated network attacker...

1 affected package

icinga2

Package 24.04 LTS
icinga2 Needs evaluation
Show less packages

CVE-2026-63349

Medium priority
Needs evaluation

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. In 4.14.0, AnyIO accepts the POSIX extra_groups argument in anyio.run_process() and anyio.open_process(), but...

1 affected package

python-anyio

Package 24.04 LTS
python-anyio Needs evaluation
Show less packages

CVE-2026-62943

Medium priority
Needs evaluation

btrbk is a tool for creating snapshots and remote backups of Btrfs subvolumes. From 0.29.0 until 0.32.7, btrbk's ssh_filter_btrbk.sh constructs allow_stream_match with a start anchor but without an end-of-string anchor for the...

1 affected package

btrbk

Package 24.04 LTS
btrbk Needs evaluation
Show less packages

CVE-2026-75883

Medium priority
Needs evaluation

The code in pppd that formats a response to a PEAP Request packet in peap_response() copies an entire TLS record of up to 16384 bytes into the fixed global buffer outpacket_buf without checking the available space and without...

1 affected package

network-manager-l2tp

Package 24.04 LTS
network-manager-l2tp Needs evaluation
Show less packages