Search CVE reports


Toggle filters

101 – 110 of 39947 results

Status is adjusted based on your filters.


CVE-2026-42245

Medium priority
Needs evaluation

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, Net::IMAP::ResponseReader has quadratic time complexity when reading large responses...

7 affected packages

ruby2.3, ruby2.5, ruby2.7, ruby3.0, ruby3.2...

Package 20.04 LTS
ruby2.3
ruby2.5
ruby2.7 Needs evaluation
ruby3.0
ruby3.2
ruby3.3
jruby Needs evaluation
Show all 7 packages Show less packages

CVE-2026-42311

Medium priority
Needs evaluation

Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution. This issue has been...

2 affected packages

pillow, pillow-python2

Package 20.04 LTS
pillow Needs evaluation
pillow-python2 Needs evaluation
Show less packages

CVE-2026-42310

Medium priority
Needs evaluation

Pillow is a Python imaging library. From version 4.2.0 to before version 12.2.0, an attacker can supply a malicious PDF that causes the process to hang indefinitely, consuming 100% CPU and making the application unresponsive. This...

2 affected packages

pillow, pillow-python2

Package 20.04 LTS
pillow Needs evaluation
pillow-python2 Needs evaluation
Show less packages

CVE-2026-42309

Medium priority
Needs evaluation

Pillow is a Python imaging library. From version 11.2.1 to before version 12.2.0, passing nested lists as coordinates to APIs that accept coordinates such as ImagePath.Path, ImageDraw.ImageDraw.polygon and ImageDraw.ImageDraw.line...

2 affected packages

pillow, pillow-python2

Package 20.04 LTS
pillow Needs evaluation
pillow-python2 Needs evaluation
Show less packages

CVE-2026-42308

Medium priority
Needs evaluation

Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been...

2 affected packages

pillow, pillow-python2

Package 20.04 LTS
pillow Needs evaluation
pillow-python2 Needs evaluation
Show less packages

CVE-2026-6667

Medium priority
Needs evaluation

PgBouncer before 1.25.2 did not perform an appropriate authorization check for the KILL_CLIENT admin command. All users with access to the administration console (which itself requires authorization) could run this command. It...

1 affected package

pgbouncer

Package 20.04 LTS
pgbouncer Needs evaluation
Show less packages

CVE-2026-6666

Medium priority
Needs evaluation

A possible null pointer reference in PgBouncer before 1.25.2 could lead to a crash, if a server sends an error response without SQLSTATE field.

1 affected package

pgbouncer

Package 20.04 LTS
pgbouncer Needs evaluation
Show less packages

CVE-2026-6665

Medium priority
Needs evaluation

The SCRAM code in PgBouncer before 1.25.2 did not check the return value of strlcat() correctly when building the contents of the SCRAM client-final-message. A malicious backend that sends a SCRAM server-final-message with a long...

1 affected package

pgbouncer

Package 20.04 LTS
pgbouncer Needs evaluation
Show less packages

CVE-2026-6664

Medium priority
Needs evaluation

An integer overflow in network packet parsing code in PgBouncer before 1.25.2 bypasses a boundary check and can lead to a crash. An unauthenticated remote attacker can crash PgBouncer with a malformed SCRAM authentication packet.

1 affected package

pgbouncer

Package 20.04 LTS
pgbouncer Needs evaluation
Show less packages

CVE-2026-45130

Medium priority
Needs evaluation

Vim is an open source, command line text editor. Prior to version 9.2.0450, a heap buffer overflow exists in read_compound() in src/spellfile.c when loading a crafted spell file (.spl) with UTF-8 encoding active....

1 affected package

vim

Package 20.04 LTS
vim Needs evaluation
Show less packages