Search CVE reports


Toggle filters

151 – 160 of 50807 results

Status is adjusted based on your filters.


CVE-2026-90825

Medium priority
Needs evaluation

A vulnerability was found in GPAC 26.07.0. Affected by this vulnerability is the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. The manipulation results in use after free. The attack...

1 affected package

gpac

Package 22.04 LTS
gpac Needs evaluation
Show less packages

CVE-2026-90824

Medium priority
Needs evaluation

A vulnerability has been found in GPAC 26.07.0. Affected is the function gf_sg_dom_event_bubble of the file src/scenegraph/dom_events.c of the component MP4Box. The manipulation leads to stack-based buffer overflow. The attack can...

1 affected package

gpac

Package 22.04 LTS
gpac Needs evaluation
Show less packages

CVE-2026-90816

Medium priority
Needs evaluation

A vulnerability was found in FFmpeg 8.0.x. This affects the function parse_playlist of the file libavformat/hlsproto.c of the component Duration Parser. Performing a manipulation of the argument duration/target_duration results in...

2 affected packages

ffmpeg, libav

Package 22.04 LTS
ffmpeg Needs evaluation
libav Not in release
Show less packages

CVE-2026-90815

Medium priority
Needs evaluation

A vulnerability has been found in FFmpeg up to 4.4.6/5.1.8/6.1.4/7.1.3/8.0.1. Affected by this issue is the function setup_3x3 of the file libavfilter/vf_convolution.c of the component Convolution Filter. Such manipulation leads...

2 affected packages

ffmpeg, libav

Package 22.04 LTS
ffmpeg Needs evaluation
libav Not in release
Show less packages

CVE-2026-54559

Medium priority
Needs evaluation

PocketSphinx is a small speech recognizer. Prior to 5.1.1, the trie language-model loaders in src/lm/ngram_model_trie.c do not adequately validate boundary conditions in ARPA, DMP, and binary format headers, and the acoustic-model...

1 affected package

pocketsphinx

Package 22.04 LTS
pocketsphinx Needs evaluation
Show less packages

CVE-2026-19816

Medium priority
Needs evaluation

A flaw was found in PackageKit. PackageKit skips the polkit authorization check for transactions carrying the SIMULATE (dry-run) flag. In the dnf5 backend, the RepoRemove handler ignores that contract and always executes the real...

1 affected package

packagekit

Package 22.04 LTS
packagekit Needs evaluation
Show less packages

CVE-2026-19624

Medium priority
Needs evaluation

A flaw was found in NetworkManager-l2tp. The plugin writes attacker-controlled VPN connection properties (vpn.data and vpn.secrets values) unescaped into a generated ipsec.conf file that pluto loads as root. A local unprivileged...

1 affected package

network-manager-l2tp

Package 22.04 LTS
network-manager-l2tp Needs evaluation
Show less packages

CVE-2026-82049

Medium priority
Needs evaluation

In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or...

12 affected packages

pypy3, python2.7, python3.4, python3.5, python3.6...

Package 22.04 LTS
pypy3 Needs evaluation
python2.7 Needs evaluation
python3.4 Not in release
python3.5 Not in release
python3.6 Not in release
python3.7 Not in release
python3.8 Not in release
python3.9 Not in release
python3.10 Needs evaluation
python3.11 Needs evaluation
python3.12 Not in release
python3.14 Not in release
Show all 12 packages Show less packages

CVE-2026-82035

Medium priority
Needs evaluation

PyMuPDF through 1.28.2, fixed in commit b2c8f3a, contains a path traversal vulnerability in the font branch of extract_objects() in src/__main__.py, where the output filename is constructed by joining a...

1 affected package

pymupdf

Package 22.04 LTS
pymupdf Needs evaluation
Show less packages

CVE-2026-55847

Medium priority
Needs evaluation

Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the ansi.js helper at allure-generator/src/main/javascript/helpers/ansi.js passes attacker-influenced statusMessage and...

1 affected package

allure

Package 22.04 LTS
allure Needs evaluation
Show less packages