Search CVE reports


Toggle filters

101 – 110 of 47232 results

Status is adjusted based on your filters.


CVE-2026-25636

Medium priority
Needs evaluation

calibre is an e-book manager. In 9.1.0 and earlier, a path traversal vulnerability in Calibre's EPUB conversion allows a malicious EPUB file to corrupt arbitrary existing files writable by the Calibre process. During conversion,...

1 affected package

calibre

Package 16.04 LTS
calibre Needs evaluation
Show less packages

CVE-2026-25635

Medium priority
Needs evaluation

calibre is an e-book manager. Prior to 9.2.0, Calibre's CHM reader contains a path traversal vulnerability that allows arbitrary file writes anywhere the user has write permissions. On Windows (haven't tested on other OS's), this...

1 affected package

calibre

Package 16.04 LTS
calibre Needs evaluation
Show less packages

CVE-2026-25556

Medium priority
Needs evaluation

MuPDF versions 1.23.0 through 1.27.0 contain a double-free vulnerability in fz_fill_pixmap_from_display_list() when an exception occurs during display list rendering. The function accepts a caller-owned fz_pixmap pointer...

1 affected package

mupdf

Package 16.04 LTS
mupdf Needs evaluation
Show less packages

CVE-2026-23741

Medium priority
Needs evaluation

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, the asterisk/contrib/scripts/ast_coredumper runs as root, as noted by the NOTES tag on...

1 affected package

asterisk

Package 16.04 LTS
asterisk Needs evaluation
Show less packages

CVE-2026-23740

Medium priority
Needs evaluation

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, when ast_coredumper writes its gdb init and output files to a directory that...

1 affected package

asterisk

Package 16.04 LTS
asterisk Needs evaluation
Show less packages

CVE-2026-23739

Medium priority
Needs evaluation

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, the ast_xml_open() function in xml.c parses XML documents using libxml with unsafe...

1 affected package

asterisk

Package 16.04 LTS
asterisk Needs evaluation
Show less packages

CVE-2026-23738

Medium priority
Needs evaluation

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, user supplied/control values for Cookies and any GET variable query Parameter are...

1 affected package

asterisk

Package 16.04 LTS
asterisk Needs evaluation
Show less packages

CVE-2026-1979

Medium priority
Needs evaluation

A flaw has been found in mruby up to 3.4.0. This affects the function mrb_vm_exec of the file src/vm.c of the component JMPNOT-to-JMPIF Optimization. Executing a manipulation can lead to use after free. The attack needs to be...

1 affected package

mruby

Package 16.04 LTS
mruby Needs evaluation
Show less packages

CVE-2025-68121

Medium priority
Needs evaluation

During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed....

16 affected packages

golang, golang-1.6, golang-1.8, golang-1.9, golang-1.10...

Package 16.04 LTS
golang
golang-1.6 Needs evaluation
golang-1.8
golang-1.9
golang-1.10 Needs evaluation
golang-1.13 Needs evaluation
golang-1.14
golang-1.16
golang-1.17
golang-1.18 Needs evaluation
golang-1.20
golang-1.21
golang-1.22
golang-1.23
golang-1.24
golang-1.25
Show all 16 packages Show less packages

CVE-2025-58190

Medium priority
Needs evaluation

The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.

7 affected packages

golang-golang-x-net, google-guest-agent, containerd, golang-golang-x-net-dev, adsys...

Package 16.04 LTS
golang-golang-x-net
google-guest-agent Not affected
containerd Not affected
golang-golang-x-net-dev Needs evaluation
adsys
juju-core Needs evaluation
lxd Needs evaluation
Show all 7 packages Show less packages