Search CVE reports


Toggle filters

631 – 640 of 46580 results

Status is adjusted based on your filters.


CVE-2026-88013

Medium priority
Needs evaluation

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.49.0 until 1.75.1, the HTTP backend attaches headers configured through --http-headers or headers= to requests in...

1 affected package

rclone

Package 24.04 LTS
rclone Needs evaluation
Show less packages

CVE-2026-88924

Medium priority
Needs evaluation

A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled...

1 affected package

gvfs

Package 24.04 LTS
gvfs Needs evaluation
Show less packages

CVE-2026-46387

Medium priority
Needs evaluation

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, Suricata's HTTP/2 decompression path could grow the...

1 affected package

suricata

Package 24.04 LTS
suricata Needs evaluation
Show less packages

CVE-2026-45747

Medium priority
Needs evaluation

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.16, the Lua TLS certificate information helper could dereference NULL certificate fields...

1 affected package

suricata

Package 24.04 LTS
suricata Needs evaluation
Show less packages

CVE-2026-45763

Medium priority
Needs evaluation

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, when Lua rule execution is enabled, the Lua sandbox memory...

1 affected package

suricata

Package 24.04 LTS
suricata Needs evaluation
Show less packages

CVE-2026-88038

Medium priority
Needs evaluation

cookies is a Node.js library for reading and writing HTTP cookies, used by Koa via ctx.cookies. In versions before 0.9.2 the library validates the cookie name and value against character sets that reject the semicolon separator,...

1 affected package

node-cookies

Package 24.04 LTS
node-cookies Needs evaluation
Show less packages

CVE-2026-88859

Medium priority
Needs evaluation

A flaw was found in Evolution. A remote attacker can exploit this vulnerability by sending a specially crafted HTML email containing a spoofed vCard control. When a victim clicks on this control, Evolution's trusted JavaScript...

1 affected package

evolution

Package 24.04 LTS
evolution Needs evaluation
Show less packages

CVE-2026-84828

Medium priority
Vulnerable

A flaw was found in PCS (Pacemaker Configuration System). A local attacker with membership in the 'haclient' group can exploit the 'pcs host auth --token' command to read the contents of arbitrary files on the filesystem, provided...

1 affected package

pcs

Package 24.04 LTS
pcs Vulnerable
Show less packages

CVE-2026-87962

Medium priority
Needs evaluation

t-digest versions 3.1 through 3.3 contain a denial of service vulnerability in MergingDigest.fromBytes that fails to validate length and capacity fields from serialized data. Attackers can supply crafted serialized digests with...

1 affected package

t-digest

Package 24.04 LTS
t-digest Needs evaluation
Show less packages

CVE-2026-88265

Medium priority
Needs evaluation

A flaw was found in crun. After pivot_root, reopening /dev/null for stdio can follow a symlink and attach a host file to container stdio, then change that file's ownership. Affected versions are crun 1.29.1 and earlier. Default...

1 affected package

crun

Package 24.04 LTS
crun Needs evaluation
Show less packages