Search CVE reports


Toggle filters

411 – 420 of 36093 results

Status is adjusted based on your filters.


CVE-2026-24881

Medium priority
Not affected

In GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message carrying an oversized wrapped session key can cause a stack-based buffer overflow in gpg-agent during PKDECRYPT--kem=CMS handling. This can easily be leveraged...

1 affected package

gnupg2

Package 22.04 LTS
gnupg2 Not affected
Show less packages

CVE-2026-24116

Medium priority

Not in release

Wasmtime is a runtime for WebAssembly. Starting in version 29.0.0 and prior to version 36.0.5, 40.0.3, and 41.0.1, on x86-64 platforms with AVX, Wasmtime's compilation of the `f64.copysign` WebAssembly instruction with Cranelift...

1 affected package

rust-wasmtime

Package 22.04 LTS
rust-wasmtime Not in release
Show less packages

CVE-2026-22264

Medium priority
Needs evaluation

Suricata is a network IDS, IPS and NSM engine. Prior to version 8.0.3 and 7.0.14, an unsigned integer overflow can lead to a heap use-after-free condition when generating excessive amounts of alerts for a single packet. Versions...

1 affected package

suricata

Package 22.04 LTS
suricata Needs evaluation
Show less packages

CVE-2026-22263

Medium priority
Needs evaluation

Suricata is a network IDS, IPS and NSM engine. Starting in version 8.0.0 and prior to version 8.0.3, inefficiency in http1 headers parsing can lead to slowdown over multiple packets. Version 8.0.3 patches the issue. No known...

1 affected package

suricata

Package 22.04 LTS
suricata Needs evaluation
Show less packages

CVE-2026-22262

Medium priority
Needs evaluation

Suricata is a network IDS, IPS and NSM engine. While saving a dataset a stack buffer is used to prepare the data. Prior to versions 8.0.3 and 7.0.14, if the data in the dataset is too large, this can result in a stack overflow....

1 affected package

suricata

Package 22.04 LTS
suricata Needs evaluation
Show less packages

CVE-2026-22261

Medium priority
Needs evaluation

Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, various inefficiencies in xff handling, especially for alerts not triggered in a tx, can lead to severe slowdowns. Versions 8.0.3 and...

1 affected package

suricata

Package 22.04 LTS
suricata Needs evaluation
Show less packages

CVE-2026-22260

Medium priority
Needs evaluation

Suricata is a network IDS, IPS and NSM engine. Starting in version 8.0.0 and prior to version 8.0.3, Suricata can crash with a stack overflow. Version 8.0.3 patches the issue. As a workaround, use default values...

1 affected package

suricata

Package 22.04 LTS
suricata Needs evaluation
Show less packages

CVE-2025-14911

Medium priority

Not in release

User-controlled chunkSize metadata from MongoDB lacks appropriate validation allowing malformed GridFS metadata to overflow the bounding container.

1 affected package

mongodb

Package 22.04 LTS
mongodb Not in release
Show less packages

CVE-2026-22259

Medium priority
Needs evaluation

Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, specially crafted traffic can cause Suricata to consume large amounts of memory while parsing DNP3 traffic. This can lead to the process slowing...

1 affected package

suricata

Package 22.04 LTS
suricata Needs evaluation
Show less packages

CVE-2026-22258

Medium priority
Needs evaluation

Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, crafted DCERPC traffic can cause Suricata to expand a buffer w/o limits, leading to memory exhaustion and the process getting killed....

1 affected package

suricata

Package 22.04 LTS
suricata Needs evaluation
Show less packages