Search CVE reports


Toggle filters

981 – 990 of 49237 results

Status is adjusted based on your filters.


CVE-2026-97149

Medium priority
Needs evaluation

In OpenStack Swift before 2.38.2, the tempurl middleware does not reject the X-Copy-From header on PUT requests. A TempURL signature only covers the method, expiry, and path, and thus the list of disallowed headers is the only...

1 affected package

swift

Package 24.04 LTS
swift Needs evaluation
Show less packages

CVE-2026-97059

Medium priority
Needs evaluation

DCMTK through 3.7.0 contains a heap over-read vulnerability in ConcatenationLoader that copies pixel data frames without validating the PixelData buffer length against the declared NumberOfFrames. Attackers can craft malicious...

1 affected package

dcmtk

Package 24.04 LTS
dcmtk Needs evaluation
Show less packages

CVE-2026-97058

Medium priority
Needs evaluation

sprintf-js through 1.1.3 passes unbounded precision specifiers to toFixed, toExponential, and toPrecision methods without validation, causing uncaught RangeError exceptions. Attackers who control format strings can...

1 affected package

node-sprintf-js

Package 24.04 LTS
node-sprintf-js Needs evaluation
Show less packages

CVE-2026-96749

Medium priority
Needs evaluation

An integer overflow in the BSON document encoding component of the MongoDB Python Driver's bundled native extension may occur when a single document is built from an unusually large amount of caller-supplied data. Size arithmetic...

1 affected package

pymongo

Package 24.04 LTS
pymongo Needs evaluation
Show less packages

CVE-2026-96748

Medium priority
Needs evaluation

PyMongo's connection string parsing decodes percent-encoded characters in the host portion before the host list is separated on its delimiters. When an application places a hostname value supplied by an unauthenticated party into...

1 affected package

pymongo

Package 24.04 LTS
pymongo Needs evaluation
Show less packages

CVE-2026-96747

Medium priority
Needs evaluation

The client-side field level encryption support in the MongoDB Python Driver can treat a key management endpoint value ending in ".sock" as a local Unix domain socket path rather than a remote host. A user with write access to the...

1 affected package

pymongo

Package 24.04 LTS
pymongo Needs evaluation
Show less packages

CVE-2026-96746

Medium priority
Needs evaluation

An out-of-bounds write in the connection-monitoring logic of the MongoDB C Driver may allow an unauthenticated party who controls name resolution and the responses of the hosts named in a client's connection string to write beyond...

1 affected package

pymongo

Package 24.04 LTS
pymongo Needs evaluation
Show less packages

CVE-2026-96745

Medium priority
Needs evaluation

Deserialization of untrusted data in the command monitoring support of the MongoDB PHP Driver can cause class names embedded in document content to be honored when the driver builds monitoring event objects. When an application...

1 affected package

pymongo

Package 24.04 LTS
pymongo Needs evaluation
Show less packages

CVE-2026-95521

Medium priority
Needs evaluation

A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames contain a %() macro construct causes rpm to execute an attacker-controlled shell command via popen() while...

1 affected package

rpm

Package 24.04 LTS
rpm Needs evaluation
Show less packages

CVE-2026-95519

Medium priority
Needs evaluation

A flaw was found in rpm. An attacker can supply a crafted manifest file that, when processed by a user or automation using `rpm -q -p` or similar manifest-processing flows, leads to arbitrary code execution. This occurs because...

1 affected package

rpm

Package 24.04 LTS
rpm Needs evaluation
Show less packages