Search CVE reports


Toggle filters

51 – 60 of 37501 results

Status is adjusted based on your filters.


CVE-2026-90610

Medium priority

Not in release

A vulnerability was found in GPAC up to f1219cde. This affects the function gf_svg_attributes_copy of the file scenegraph/svg_attributes.c of the component MP4Box. Performing a manipulation results in buffer over-read. The attack...

1 affected package

gpac

Package 26.04 LTS
gpac Not in release
Show less packages

CVE-2026-90609

Medium priority

Not in release

A vulnerability has been found in GPAC up to f1219cde. The impacted element is an unknown function of the file scenegraph/vrml_tools.c of the component MP4Box. Such manipulation leads to null pointer dereference. The attack...

1 affected package

gpac

Package 26.04 LTS
gpac Not in release
Show less packages

CVE-2026-90463

Medium priority
Needs evaluation

(A flaw was found in the sssd NSS responder. This input validation vuln ...)

1 affected package

sssd

Package 26.04 LTS
sssd Needs evaluation
Show less packages

CVE-2026-86320

Medium priority
Needs evaluation

[Unknown description]

1 affected package

flatpak-builder

Package 26.04 LTS
flatpak-builder Needs evaluation
Show less packages

CVE-2026-75883

Medium priority
Needs evaluation

security update

1 affected package

network-manager-l2tp

Package 26.04 LTS
network-manager-l2tp Needs evaluation
Show less packages

CVE-2026-75131

Medium priority
Needs evaluation

security update

1 affected package

network-manager-l2tp

Package 26.04 LTS
network-manager-l2tp Needs evaluation
Show less packages

CVE-2026-54559

Medium priority
Needs evaluation

PocketSphinx is a small speech recognizer. Prior to 5.1.1, the trie language-model loaders in src/lm/ngram_model_trie.c do not adequately validate boundary conditions in ARPA, DMP, and binary format headers, and the acoustic-model...

1 affected package

pocketsphinx

Package 26.04 LTS
pocketsphinx Needs evaluation
Show less packages

CVE-2026-19816

Medium priority
Needs evaluation

A flaw was found in PackageKit. PackageKit skips the polkit authorization check for transactions carrying the SIMULATE (dry-run) flag. In the dnf5 backend, the RepoRemove handler ignores that contract and always executes the real...

1 affected package

packagekit

Package 26.04 LTS
packagekit Needs evaluation
Show less packages

CVE-2026-19624

Medium priority
Needs evaluation

A flaw was found in NetworkManager-l2tp. The plugin writes attacker-controlled VPN connection properties (vpn.data and vpn.secrets values) unescaped into a generated ipsec.conf file that pluto loads as root. A local unprivileged...

1 affected package

network-manager-l2tp

Package 26.04 LTS
network-manager-l2tp Needs evaluation
Show less packages

CVE-2026-82049

Medium priority
Needs evaluation

In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or...

12 affected packages

pypy3, python2.7, python3.4, python3.5, python3.6...

Package 26.04 LTS
pypy3 Needs evaluation
python2.7 Not in release
python3.4 Not in release
python3.5 Not in release
python3.6 Not in release
python3.7 Not in release
python3.8 Not in release
python3.9 Not in release
python3.10 Not in release
python3.11 Not in release
python3.12 Not in release
python3.14 Needs evaluation
Show all 12 packages Show less packages