Search CVE reports


Toggle filters

301 – 310 of 32653 results

Status is adjusted based on your filters.


CVE-2026-3203

Medium priority
Needs evaluation

RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service

1 affected package

wireshark

Package 24.04 LTS
wireshark Needs evaluation
Show less packages

CVE-2026-3202

Medium priority
Needs evaluation

NTS-KE protocol dissector crash in Wireshark 4.6.0 to 4.6.3 allows denial of service

1 affected package

wireshark

Package 24.04 LTS
wireshark Needs evaluation
Show less packages

CVE-2026-3201

Medium priority
Needs evaluation

USB HID protocol dissector memory exhaustion in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service

1 affected package

wireshark

Package 24.04 LTS
wireshark Needs evaluation
Show less packages

CVE-2026-27699

Medium priority
Needs evaluation

The `basic-ftp` FTP client library for Node.js contains a path traversal vulnerability (CWE-22) in versions prior to 5.2.0 in the `downloadToDir()` method. A malicious FTP server can send directory listings with filenames...

1 affected package

node-proxy-agents

Package 24.04 LTS
node-proxy-agents Needs evaluation
Show less packages

CVE-2026-21725

Medium priority

Not in release

A time-of-create-to-time-of-use (TOCTOU) vulnerability lets recently deleted-then-recreated data sources be re-deleted without permission to do so. This requires several very stringent conditions to be met: - The attacker must...

1 affected package

grafana

Package 24.04 LTS
grafana Not in release
Show less packages

CVE-2026-26104

Medium priority
Not affected

A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization. The issue occurs because a privileged D-Bus method responsible for exporting...

1 affected package

udisks2

Package 24.04 LTS
udisks2 Not affected
Show less packages

CVE-2026-26103

Medium priority
Not affected

A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper authorization checks. The issue allows a local unprivileged user to instruct the...

1 affected package

udisks2

Package 24.04 LTS
udisks2 Not affected
Show less packages

CVE-2025-11563

Medium priority
Not affected

URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking for it. This flaw only affects the wcurl command line tool.

1 affected package

curl

Package 24.04 LTS
curl Not affected
Show less packages

CVE-2026-27624

Medium priority
Needs evaluation

Coturn is a free open source implementation of TURN and STUN Server. Coturn is commonly configured to block loopback and internal ranges using "denied-peer-ip" and/or default loopback restrictions. CVE-2020-26262 addressed...

1 affected package

coturn

Package 24.04 LTS
coturn Needs evaluation
Show less packages

CVE-2026-3147

Medium priority
Needs evaluation

A vulnerability was found in libvips up to 8.18.0. This affects the function vips_foreign_load_csv_build of the file libvips/foreign/csvload.c. The manipulation results in heap-based buffer overflow. The attack requires a local...

1 affected package

vips

Package 24.04 LTS
vips Needs evaluation
Show less packages