Search CVE reports


Toggle filters

691 – 700 of 48358 results

Status is adjusted based on your filters.


CVE-2026-1182

Medium priority
Ignored

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.14 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to gain unauthorized access to confidential...

1 affected package

gitlab

Package 16.04 LTS
gitlab Ignored
Show less packages

CVE-2023-43010

Medium priority
Ignored

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2, Safari 17.2, iOS 16.7.15 and iPadOS 16.7.15, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted...

5 affected packages

webkitgtk, webkit2gtk, qtwebkit-source, qtwebkit-opensource-src, wpewebkit

Package 16.04 LTS
webkitgtk Ignored
webkit2gtk Ignored
qtwebkit-source Ignored
qtwebkit-opensource-src Ignored
wpewebkit
Show less packages

CVE-2026-28384

Medium priority
Not affected

An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an authenticated, unprivileged user to execute commands as the LXD daemon on the LXD server via API calls to the image and backup endpoints....

1 affected package

lxd

Package 16.04 LTS
lxd Not affected
Show less packages

CVE-2026-31988

Medium priority
Needs evaluation

yauzl (aka Yet Another Unzip Library) version 3.2.0 for Node.js contains an off-by-one error in the NTFS extended timestamp extra field parser within the getLastModDate() function. The while loop condition checks cursor...

1 affected package

node-yauzl

Package 16.04 LTS
node-yauzl Needs evaluation
Show less packages

CVE-2026-31958

Medium priority
Needs evaluation

Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts in multipart/form-data is the max_body_size setting (default 100MB). Since parsing...

1 affected package

python-tornado

Package 16.04 LTS
python-tornado Needs evaluation
Show less packages

CVE-2026-3805

Medium priority
Not affected

When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory.

1 affected package

curl

Package 16.04 LTS
curl Not affected
Show less packages

CVE-2026-3784

Low priority
Not affected

curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a server, even if the new request uses different credentials for the HTTP proxy. The proper behavior is to create or use a separate connection.

1 affected package

curl

Package 16.04 LTS
curl Not affected
Show less packages

CVE-2026-3783

Medium priority
Not affected

When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl could leak that token to the second hostname under some circumstances. If the hostname that the first request...

1 affected package

curl

Package 16.04 LTS
curl Not affected
Show less packages

CVE-2026-1965

Medium priority
Not affected

libcurl can in some circumstances reuse the wrong connection when asked to do an Negotiate-authenticated HTTP or HTTPS request. libcurl features a pool of recent connections so that subsequent requests can reuse an existing...

1 affected package

curl

Package 16.04 LTS
curl Not affected
Show less packages

CVE-2026-31853

Medium priority
Needs evaluation

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-16 and 6.9.13-41, an overflow on 32-bit systems can cause a crash in the SFW decoder when processing extremely large...

1 affected package

imagemagick

Package 16.04 LTS
imagemagick Needs evaluation
Show less packages