Search CVE reports


Toggle filters

81 – 90 of 49194 results

Status is adjusted based on your filters.


CVE-2026-84446

Medium priority
Needs evaluation

libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, crafted HEIF sequence timing and edit-list data can make Track::init_sample_timing_table() compute a logical m_num_output_samples value that exceeds the...

1 affected package

libheif

Package 20.04 LTS
libheif Needs evaluation
Show less packages

CVE-2026-84444

Medium priority
Needs evaluation

libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, when WITH_UNCOMPRESSED_CODEC is enabled, heif_context_add_image_tile() accepts an independently constructed tile whose component-plane dimensions do not...

1 affected package

libheif

Package 20.04 LTS
libheif Needs evaluation
Show less packages

CVE-2026-84384

Medium priority
Needs evaluation

libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.2, crafted HEIF or AVIF mime metadata and unci image data can cause decompress_brotli() and do_inflate() to grow accumulated output without an...

1 affected package

libheif

Package 20.04 LTS
libheif Needs evaluation
Show less packages

CVE-2026-82560

Medium priority
Needs evaluation

Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width. Each =over adds its indent to the margin, which wrap() subtracts from...

1 affected package

perl

Package 20.04 LTS
perl Needs evaluation
Show less packages

CVE-2026-81627

Medium priority
Needs evaluation

A flaw was found in QEMU. The VAPIC setup hypercall in hw/i386/vapic.c does not validate that the writable RAM alias remains within the option ROM window. A privileged guest user on a Q35/KVM machine can position this alias over...

2 affected packages

qemu, qemu-hwe

Package 20.04 LTS
qemu Needs evaluation
qemu-hwe
Show less packages

CVE-2026-77568

Medium priority
Needs evaluation

Mojolicious is a real-time web framework for Perl. Prior to 9.48, the Mojolicious CSRF helpers csrf_field, csrf_token, and csrf_protect reuse an unchanged per-session token in rendered HTML. When response compression is enabled...

1 affected package

perl

Package 20.04 LTS
perl Needs evaluation
Show less packages

CVE-2026-77528

Medium priority
Needs evaluation

Autobahn Python is a WebSocket and WAMP implementation for Python that supports Twisted and asyncio. Prior to 26.7.1, WebSocket endpoints that accept permessage-deflate and rely on maxMessagePayloadSize enforce that limit against...

1 affected package

python-autobahn

Package 20.04 LTS
python-autobahn Needs evaluation
Show less packages

CVE-2026-77396

Medium priority
Needs evaluation

PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the PJSIP AVI parser in pjmedia/src/pjmedia/avi_player.c uses an input-file video chunk length as the number of bytes copied into...

2 affected packages

asterisk, pjproject

Package 20.04 LTS
asterisk Needs evaluation
pjproject
Show less packages

CVE-2026-75895

Medium priority
Needs evaluation

In libsmpp35 from 0.1.0 through 1.8.0 out of bound read issue was found in the at smpp34_unpack() function via attacker controlled SMPP PDUs, leading to memory corruption.

1 affected package

libsmpp34

Package 20.04 LTS
libsmpp34 Needs evaluation
Show less packages

CVE-2026-75894

Medium priority
Needs evaluation

In osmo-iuh from 0.1.0 through 1.8.0 a reachable assertion was found in the ranap_handle_co_dt() function via a arbitrarily sized NAS-PDU that leads to process crash and remote denial of service.

1 affected package

osmo-iuh

Package 20.04 LTS
osmo-iuh Needs evaluation
Show less packages