Search CVE reports


Toggle filters

71 – 80 of 58662 results

Status is adjusted based on your filters.


CVE-2026-94084

Medium priority
Needs evaluation

Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.

1 affected package

suricata

Package 16.04 LTS
suricata Needs evaluation
Show less packages

CVE-2026-94083

Medium priority
Needs evaluation

Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to...

1 affected package

suricata

Package 16.04 LTS
suricata Needs evaluation
Show less packages

CVE-2026-94057

Medium priority
Needs evaluation

Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent after a rejection during DATA processing.

1 affected package

exim4

Package 16.04 LTS
exim4 Needs evaluation
Show less packages

CVE-2026-94056

Medium priority
Needs evaluation

Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.

1 affected package

exim4

Package 16.04 LTS
exim4 Needs evaluation
Show less packages

CVE-2026-94055

Medium priority
Not affected

Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.

1 affected package

exim4

Package 16.04 LTS
exim4 Not affected
Show less packages

CVE-2026-94054

Medium priority
Needs evaluation

Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.

1 affected package

exim4

Package 16.04 LTS
exim4 Needs evaluation
Show less packages

CVE-2026-93990

Medium priority
Needs evaluation

Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume...

23 affected packages

expat, apache2, apr-util, cmake, ghostscript...

Package 16.04 LTS
expat Needs evaluation
apache2 Not affected
apr-util Not affected
cmake Not affected
ghostscript Not affected
texlive-bin Not affected
xmlrpc-c Needs evaluation
vnc4 Needs evaluation
wbxml2 Needs evaluation
swish-e Needs evaluation
insighttoolkit4 Needs evaluation
cadaver Needs evaluation
gdcm Needs evaluation
ayttm Needs evaluation
cableswig Needs evaluation
coin3 Needs evaluation
matanza Needs evaluation
tdom Needs evaluation
vtk Needs evaluation
smart Needs evaluation
firefox
thunderbird
libxmltok Needs evaluation
Show all 23 packages Show less packages

CVE-2026-82560

Medium priority
Needs evaluation

Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width. Each =over adds its indent to the margin, which wrap() subtracts from...

1 affected package

perl

Package 16.04 LTS
perl Needs evaluation
Show less packages

CVE-2026-78030

Medium priority
Needs evaluation

DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM. DBD::DBM passes the dbm_type and dbm_mldbm connect attributes to require without checking that the value...

1 affected package

libdbi-perl

Package 16.04 LTS
libdbi-perl Needs evaluation
Show less packages

CVE-2026-93894

Medium priority
Needs evaluation

In Vinyl Cache before 9.0,2, workspace buffer overflow vulnerability was found in the .upper() and .lower() string type methods of VCL. This can be used as a remote denial of service (DoS) vector to make the child process segfault...

2 affected packages

varnish, vinyl-cache

Package 16.04 LTS
varnish Needs evaluation
vinyl-cache
Show less packages