Search CVE reports


Toggle filters

1041 – 1050 of 33231 results

Status is adjusted based on your filters.


CVE-2026-27025

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes and large memory consumption. This requires parsing the /ToUnicode entry...

2 affected packages

pypdf, pypdf2

Package 24.04 LTS
pypdf Needs evaluation
pypdf2 Needs evaluation
Show less packages

CVE-2026-27024

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires accessing the children of a TreeObject, for example as...

2 affected packages

pypdf, pypdf2

Package 24.04 LTS
pypdf Needs evaluation
pypdf2 Needs evaluation
Show less packages

CVE-2026-0797

Medium priority
Needs evaluation

GIMP ICO File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit...

1 affected package

gimp

Package 24.04 LTS
gimp Needs evaluation
Show less packages

CVE-2026-25896

Medium priority
Needs evaluation

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE entity name is treated as a regex...

1 affected package

node-webfont

Package 24.04 LTS
node-webfont Needs evaluation
Show less packages

CVE-2026-21620

Low priority
Needs evaluation

Relative Path Traversal, Improper Isolation or Compartmentalization vulnerability in erlang otp erlang/otp (tftp_file modules), erlang otp inets (tftp_file modules), erlang otp tftp (tftp_file modules) allows Relative Path...

1 affected package

erlang

Package 24.04 LTS
erlang Needs evaluation
Show less packages

CVE-2026-2739

Medium priority
Needs evaluation

This affects versions of the package bn.js before 5.2.3. Calling maskn(0) on any BN instance corrupts the internal state, causing toString(), divmod(), and other methods to enter an infinite loop, hanging the process indefinitely.

1 affected package

node-bn.js

Package 24.04 LTS
node-bn.js Needs evaluation
Show less packages

CVE-2026-27017

Medium priority
Needs evaluation

uTLS is a fork of crypto/tls, created to customize ClientHello for fingerprinting resistance while still using it for the handshake. Versions 1.6.0 through 1.8.0 contain a fingerprint mismatch with Chrome when using GREASE ECH,...

1 affected package

golang-refraction-networking-utls

Package 24.04 LTS
golang-refraction-networking-utls Needs evaluation
Show less packages

CVE-2026-26996

Medium priority
Needs evaluation

minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions 10.2.0 and below are vulnerable to Regular Expression Denial of Service (ReDoS) when a glob pattern contains many...

1 affected package

node-minimatch

Package 24.04 LTS
node-minimatch Needs evaluation
Show less packages

CVE-2026-26994

Medium priority
Needs evaluation

uTLS is a fork of crypto/tls, created to customize ClientHello for fingerprinting resistance while still using it for the handshake. In versions 1.6.7 and below, uTLS did not implement the TLS 1.3 downgrade protection mechanism...

1 affected package

golang-refraction-networking-utls

Package 24.04 LTS
golang-refraction-networking-utls Needs evaluation
Show less packages

CVE-2026-26960

Medium priority
Needs evaluation

node-tar is a full-featured Tar for Node.js. When using default options in versions 7.5.7 and below, an attacker-controlled archive can create a hardlink inside the extraction directory that points to a file outside the extraction...

1 affected package

node-tar

Package 24.04 LTS
node-tar Needs evaluation
Show less packages