Search CVE reports


Toggle filters

1 – 10 of 38395 results

Status is adjusted based on your filters.


CVE-2026-8286

Low priority
Vulnerable

A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.

1 affected package

curl

Package 24.04 LTS
curl Vulnerable
Show less packages

CVE-2026-48785

Medium priority

Not in release

[Unknown description]

1 affected package

apptainer

Package 24.04 LTS
apptainer Not in release
Show less packages

CVE-2026-47215

Medium priority
Needs evaluation

[Unknown description]

1 affected package

singularity-container

Package 24.04 LTS
singularity-container Needs evaluation
Show less packages

CVE-2026-12490

Medium priority
Not affected

When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate with that name. However, no client certificate is needed when the request comes in over TLS over the regular...

1 affected package

nsd

Package 24.04 LTS
nsd Not affected
Show less packages

CVE-2026-12246

Medium priority
Fixed

NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the address family will overwrite the stack when the zone is written to disk, with a maximum of 111...

1 affected package

nsd

Package 24.04 LTS
nsd Fixed
Show less packages

CVE-2026-12245

Medium priority
Not affected

NSD from version 4.13.0 has a heap use-after-free bug in logging errors on TLS connections, causing a crash of the server process, which can be triggered trivially by sending a DNS query over a DoT connection, and closing the...

1 affected package

nsd

Package 24.04 LTS
nsd Not affected
Show less packages

CVE-2026-12244

Medium priority
Not affected

If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used...

1 affected package

nsd

Package 24.04 LTS
nsd Not affected
Show less packages

CVE-2026-2050

Medium priority
Needs evaluation

GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit...

1 affected package

gegl

Package 24.04 LTS
gegl Needs evaluation
Show less packages

CVE-2026-49980

Medium priority
Needs evaluation

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.46.0 until 1.74.3, rclone rcd --rc-serve accepts unauthenticated GET and HEAD requests to paths of the form:...

1 affected package

rclone

Package 24.04 LTS
rclone Needs evaluation
Show less packages

CVE-2026-49851

Medium priority
Needs evaluation

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Mistune is vulnerable to a CPU exhaustion DoS due to superlinear (approximately O(n²)) behavior in parse_link_text. When parsing Markdown containing...

1 affected package

mistune

Package 24.04 LTS
mistune Needs evaluation
Show less packages