Search CVE reports


Toggle filters

41 – 50 of 50365 results

Status is adjusted based on your filters.


CVE-2026-12345

Medium priority
Needs evaluation

The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be...

11 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7...

Package 20.04 LTS
python2.7 Needs evaluation
python3.4 —
python3.5 —
python3.6 —
python3.7 —
python3.8 Needs evaluation
python3.9 Needs evaluation
python3.10 —
python3.11 —
python3.12 —
python3.14 —
Show all 11 packages Show less packages

CVE-2026-102560

Medium priority
Needs evaluation

A flaw was found in libsoup. When the permessage-deflate WebSocket extension compresses a very large outgoing message, truncated size calculations used for GByteArray growth could wrap, causing zlib to write past the allocated...

2 affected packages

libsoup2.4, libsoup3

Package 20.04 LTS
libsoup2.4 Needs evaluation
libsoup3 —
Show less packages

CVE-2026-102559

Medium priority
Needs evaluation

A flaw was found in libsoup. When constructing a masked WebSocket client frame for a very large outgoing payload, size values passed to GByteArray allocation APIs could be truncated while the masking routine still used the full...

2 affected packages

libsoup2.4, libsoup3

Package 20.04 LTS
libsoup2.4 Needs evaluation
libsoup3 —
Show less packages

CVE-2026-102558

Medium priority
Needs evaluation

A flaw was found in libsoup. When max-incoming-payload-size is unlimited (0), SoupWebsocketConnection could grow its incoming GByteArray based on an attacker-controlled frame length until the length wrapped, causing a heap buffer...

2 affected packages

libsoup2.4, libsoup3

Package 20.04 LTS
libsoup2.4 Needs evaluation
libsoup3 —
Show less packages

CVE-2026-102555

Medium priority
Needs evaluation

A flaw was found in libsoup. The soup_uri_decode_data_uri() function incorrectly treated base64 data-URI payloads as NUL-terminated strings when calling g_base64_decode_inplace(). If the percent-decoded payload contained embedded...

2 affected packages

libsoup2.4, libsoup3

Package 20.04 LTS
libsoup2.4 Needs evaluation
libsoup3 —
Show less packages

CVE-2026-102635

Medium priority
Needs evaluation

ImageMagick versions before 7.1.2-32 and 6.9.13-57 contain uninitialized heap memory disclosure in the GIF decoder's application extension handler in coders/gif.c. Attackers can craft malicious GIF files that cause the number...

1 affected package

imagemagick

Package 20.04 LTS
imagemagick Needs evaluation
Show less packages

CVE-2026-102633

Medium priority
Needs evaluation

libexpat versions 2.7.2 through 2.8.5 contain an integer overflow vulnerability in expat_realloc() function on 32-bit platforms when computing allocation sizes. Attackers supplying malicious XML to applications parsing with...

23 affected packages

expat, apache2, apr-util, cmake, ghostscript...

Package 20.04 LTS
expat Needs evaluation
apache2 Not affected
apr-util Not affected
cmake Not affected
ghostscript Not affected
texlive-bin Not affected
xmlrpc-c Needs evaluation
vnc4 —
wbxml2 Needs evaluation
swish-e Needs evaluation
insighttoolkit4 Needs evaluation
cadaver Needs evaluation
gdcm Not affected
ayttm —
cableswig —
coin3 Not affected
matanza Ignored
tdom Needs evaluation
vtk —
smart —
firefox —
thunderbird —
libxmltok Needs evaluation
Show all 23 packages Show less packages

CVE-2026-102557

Medium priority
Needs evaluation

A flaw was found in libsoup. When reassembling fragmented WebSocket messages into a GByteArray, libsoup did not adequately cap total message size against the limits of the underlying buffer type. A remote peer could send fragments...

2 affected packages

libsoup2.4, libsoup3

Package 20.04 LTS
libsoup2.4 Needs evaluation
libsoup3 —
Show less packages

CVE-2026-102556

Medium priority
Needs evaluation

A flaw was found in libsoup. When handling an incoming WebSocket Pong frame, SoupWebsocketConnection emitted the ::pong signal with a GByteArray pointer even though the signal is declared to pass a GBytes. Applications connecting...

2 affected packages

libsoup2.4, libsoup3

Package 20.04 LTS
libsoup2.4 Needs evaluation
libsoup3 —
Show less packages

CVE-2026-97689

Medium priority
Needs evaluation

urllib3 is an HTTP client library for Python. From 1.10.3 until 2.8.0, the HTTPResponse.read_chunked and HTTPResponse.stream methods can allocate unbounded memory because the streaming chunk parser buffers the chunk-size field...

2 affected packages

python-urllib3, python-pip

Package 20.04 LTS
python-urllib3 Needs evaluation
python-pip Needs evaluation
Show less packages