Search CVE reports


Toggle filters

1081 – 1090 of 51201 results

Status is adjusted based on your filters.


CVE-2026-89147

Medium priority
Needs evaluation

Net-SNMP through 5.9.5.2 contains a denial of service vulnerability in the SMUX module where smux_accept() performs an unauthenticated blocking read without timeout on newly accepted connections. An unauthenticated remote client...

1 affected package

net-snmp

Package 22.04 LTS
net-snmp Needs evaluation
Show less packages

CVE-2026-77159

Medium priority
Needs evaluation

A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost() function. The function uses a path-based chown() on the swtpm logfile without checking for symbolic links. A local attacker with access to the swtpm...

2 affected packages

libvirt, libvirt-hwe

Package 22.04 LTS
libvirt Needs evaluation
libvirt-hwe Not in release
Show less packages

CVE-2026-87859

Medium priority
Needs evaluation

morgan is an HTTP request logger middleware for Node.js. In versions before 1.12.1, its escapeLogField() function does not escape the double quote character, which delimits the quoted fields of the Apache combined log format that...

1 affected package

node-morgan

Package 22.04 LTS
node-morgan Needs evaluation
Show less packages

CVE-2026-87908

Medium priority
Needs evaluation

multiparty is a Node.js library for parsing multipart/form-data request bodies. In versions from 2.1.0 up to but not including 4.3.1, the parser does not bound the amount of memory used while accumulating the headers of a single...

1 affected package

node-multiparty

Package 22.04 LTS
node-multiparty Needs evaluation
Show less packages

CVE-2026-89169

Medium priority
Needs evaluation

live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .verity file is missing.

1 affected package

live-boot

Package 22.04 LTS
live-boot Needs evaluation
Show less packages

CVE-2026-89162

Medium priority
Needs evaluation

In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe.

1 affected package

pcre2

Package 22.04 LTS
pcre2 Needs evaluation
Show less packages

CVE-2026-89161

Medium priority
Needs evaluation

In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur.

1 affected package

pcre2

Package 22.04 LTS
pcre2 Needs evaluation
Show less packages

CVE-2026-89160

Medium priority
Needs evaluation

PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject.

1 affected package

pcre2

Package 22.04 LTS
pcre2 Needs evaluation
Show less packages

CVE-2026-89158

Medium priority
Needs evaluation

PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write.

1 affected package

pcre2

Package 22.04 LTS
pcre2 Needs evaluation
Show less packages

CVE-2026-89157

Medium priority
Needs evaluation

PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern.

1 affected package

pcre2

Package 22.04 LTS
pcre2 Needs evaluation
Show less packages