Search CVE reports


Toggle filters

581 – 590 of 27411 results

Status is adjusted based on your filters.


CVE-2026-29518

High priority
Fixed

Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components...

1 affected package

rsync

Package 26.04 LTS
rsync Fixed
Show less packages

CVE-2026-5090

Medium priority
Needs evaluation

Template::Plugin::HTML versions through 3.102 for Perl allows HTML and JavaScript to be injected. The html_filter function did not escape single quotes. HTML attributes inside of single quotes could be have code injected. For...

1 affected package

libtemplate-perl

Package 26.04 LTS
libtemplate-perl Needs evaluation
Show less packages

CVE-2026-32882

Medium priority
Needs evaluation

libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap buffer over-read in HeifPixelImage::overlay() in libheif/pixelimage.cc. When compositing an overlay image (iovl) whose...

1 affected package

libheif

Package 26.04 LTS
libheif Needs evaluation
Show less packages

CVE-2026-32814

Medium priority
Needs evaluation

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, when decoding a HEIF grid image with strict_decoding=false (the default), a corrupted tile silently fails to decode and the library returns...

1 affected package

libheif

Package 26.04 LTS
libheif Needs evaluation
Show less packages

CVE-2026-32741

Medium priority
Needs evaluation

libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and below contain a heap buffer overflow in MaskImageCodec::decode_mask_image(). When decoding a HEIF file containing a mask image (mski), the function...

1 affected package

libheif

Package 26.04 LTS
libheif Needs evaluation
Show less packages

CVE-2026-32740

Medium priority
Needs evaluation

libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap-buffer-overflow (write) vulnerability in the grid tile compositing, allowing an attacker to write 64 bytes of...

1 affected package

libheif

Package 26.04 LTS
libheif Needs evaluation
Show less packages

CVE-2026-32739

Medium priority
Needs evaluation

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 800-byte HEIF sequence file causes an infinite loop in Box_stts::get_sample_duration(), consuming 100% CPU indefinitely with zero...

1 affected package

libheif

Package 26.04 LTS
libheif Needs evaluation
Show less packages

CVE-2026-41470

Medium priority

Not in release

LIVE555 before 2026.04.22 contains an authorization bypass vulnerability in RTSP session command handling that allows attackers to replay valid Session tokens from unauthenticated connections. Attackers who obtain a valid Session...

1 affected package

liblivemedia

Package 26.04 LTS
liblivemedia Not in release
Show less packages

CVE-2026-33642

Medium priority
Needs evaluation

Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kitty/graphics.c performs bounds validation on composition offsets using unsigned 32-bit arithmetic that...

1 affected package

kitty

Package 26.04 LTS
kitty Needs evaluation
Show less packages

CVE-2026-33637

Medium priority
Needs evaluation

Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Versions 2.0.0 through 2.14.1 still allow protocol-relative host override when the request target is passed as a URI object...

1 affected package

ruby-faraday

Package 26.04 LTS
ruby-faraday Needs evaluation
Show less packages