Search CVE reports


Toggle filters

301 – 310 of 35777 results

Status is adjusted based on your filters.


CVE-2026-0989

Medium priority
Fixed

A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially crafted or...

1 affected package

libxml2

Package 22.04 LTS
libxml2 Fixed
Show less packages

CVE-2026-0897

Medium priority

Not in release

Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through 3.13.0 on all platforms allows a remote attacker to cause a Denial of Service (DoS) through memory exhaustion...

1 affected package

keras

Package 22.04 LTS
keras Not in release
Show less packages

CVE-2026-0962

Medium priority
Needs evaluation

SOME/IP-SD protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service

1 affected package

wireshark

Package 22.04 LTS
wireshark Needs evaluation
Show less packages

CVE-2026-0961

Medium priority
Needs evaluation

BLF file parser crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service

1 affected package

wireshark

Package 22.04 LTS
wireshark Needs evaluation
Show less packages

CVE-2026-0960

Medium priority
Needs evaluation

HTTP3 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.2 allows denial of service

1 affected package

wireshark

Package 22.04 LTS
wireshark Needs evaluation
Show less packages

CVE-2026-0959

Medium priority
Needs evaluation

IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service

1 affected package

wireshark

Package 22.04 LTS
wireshark Needs evaluation
Show less packages

CVE-2026-0861

Medium priority
Vulnerable

Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc) in the GNU C Library version 2.30 to 2.42 may result in an integer overflow, which could consequently result in a heap...

2 affected packages

eglibc, glibc

Package 22.04 LTS
eglibc Not in release
glibc Vulnerable
Show less packages

CVE-2026-22036

Medium priority

Not in release

Undici is an HTTP/1.1 client for Node.js. Prior to 7.18.0 and 6.23.0, the number of links in the decompression chain is unbounded and the default maxHeaderSize allows a malicious server to insert thousands compression steps...

1 affected package

node-undici

Package 22.04 LTS
node-undici Not in release
Show less packages

CVE-2025-11224

Medium priority

Not in release

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.10 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated user to execute stored cross-site...

1 affected package

gitlab

Package 22.04 LTS
gitlab Not in release
Show less packages

CVE-2026-22859

Medium priority
Needs evaluation

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, the URBDRC client does not perform bounds checking on server‑supplied MSUSB_INTERFACE_DESCRIPTOR values and uses them as indices in...

3 affected packages

freerdp, freerdp2, freerdp3

Package 22.04 LTS
freerdp Not in release
freerdp2 Needs evaluation
freerdp3 Not in release
Show less packages