Search CVE reports


Toggle filters

641 – 650 of 46580 results

Status is adjusted based on your filters.


CVE-2026-88264

Medium priority
Needs evaluation

A flaw was found in crun. When the container configuration does not give /dev a dedicated mount, terminal setup can redirect /dev/console onto an attacker-controlled path, including via the read-only-rootfs bind-mount fallback....

1 affected package

crun

Package 24.04 LTS
crun Needs evaluation
Show less packages

CVE-2026-84042

Medium priority
Needs evaluation

A flaw was found in crun. When crun is built with libkrun and a container is started rootful with passt networking (krun.use_passt), crun can execute attacker-controlled payload from the container image with host root privileges....

1 affected package

crun

Package 24.04 LTS
crun Needs evaluation
Show less packages

CVE-2026-59679

Medium priority
Needs evaluation

fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16 reply, but that array was allocated with a size derived from num_extents...

2 affected packages

libxfont, libxfont2

Package 24.04 LTS
libxfont Needs evaluation
libxfont2 Not in release
Show less packages

CVE-2026-44950

Medium priority
Needs evaluation

fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) copies each glyph's bitmap into a single buffer. Existing checks validates only that the source slice (position, length) lies within the source bitmap buffer....

2 affected packages

libxfont, libxfont2

Package 24.04 LTS
libxfont Needs evaluation
libxfont2 Not in release
Show less packages

CVE-2026-84939

Medium priority
Needs evaluation

Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can specify an arbitrary malformed locale identifier to FreeMarker, and the localized lookup configuration setting is enabled (it's by...

1 affected package

libfreemarker-java

Package 24.04 LTS
libfreemarker-java Needs evaluation
Show less packages

CVE-2026-87933

Medium priority
Needs evaluation

A vulnerability was found in DaveGamble cJSON up to 1.7.19. The affected element is the function cJSONUtils_MergePatch of the file cJSON_Utils.c. The manipulation results in use after free. The attack may be launched remotely. The...

1 affected package

cjson

Package 24.04 LTS
cjson Needs evaluation
Show less packages

CVE-2026-87658

Medium priority
Not affected

(Information leak in Extensions in Google Chrome prior to 153.0.8010.36 ...)

1 affected package

chromium-browser

Package 24.04 LTS
chromium-browser Not affected
Show less packages

CVE-2026-87657

Medium priority
Not affected

(Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a ...)

1 affected package

chromium-browser

Package 24.04 LTS
chromium-browser Not affected
Show less packages

CVE-2026-87656

Medium priority
Not affected

(Improper state validation in Safebrowsing in Google Chrome prior to 15 ...)

1 affected package

chromium-browser

Package 24.04 LTS
chromium-browser Not affected
Show less packages

CVE-2026-87655

Medium priority
Not affected

(Clickjacking in Downloads in Google Chrome prior to 153.0.8010.36 allo ...)

1 affected package

chromium-browser

Package 24.04 LTS
chromium-browser Not affected
Show less packages