Search CVE reports


Toggle filters

371 – 380 of 38012 results

Status is adjusted based on your filters.


CVE-2026-33165

Medium priority
Needs evaluation

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a crafted HEVC bitstream causes an out-of-bounds heap write confirmed by AddressSanitizer. The trigger is a stale ctb_info.log2unitSize...

1 affected package

libde265

Package 20.04 LTS
libde265 Needs evaluation
Show less packages

CVE-2026-33164

Medium priority
Needs evaluation

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a malformed H.265 PPS NAL unit causes a segmentation fault in pic_parameter_set::set_derived_values(). This issue has been patched in...

1 affected package

libde265

Package 20.04 LTS
libde265 Needs evaluation
Show less packages

CVE-2026-33155

Medium priority
Needs evaluation

DeepDiff is a project focused on Deep Difference and search of any Python data. From version 5.0.0 to before version 8.6.2, the pickle unpickler _RestrictedUnpickler validates which classes can be loaded but does not limit their...

1 affected package

deepdiff

Package 20.04 LTS
deepdiff Needs evaluation
Show less packages

CVE-2026-33151

Medium priority
Needs evaluation

Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3.4.4, and 4.2.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary...

1 affected package

node-socket.io-parser

Package 20.04 LTS
node-socket.io-parser Needs evaluation
Show less packages

CVE-2026-33150

Medium priority
Not affected

libfuse is the reference implementation of the Linux FUSE. From version 3.18.0 to before version 3.18.2, a use-after-free vulnerability in the io_uring subsystem of libfuse allows a local attacker to crash FUSE filesystem...

2 affected packages

fuse, fuse3

Package 20.04 LTS
fuse Not affected
fuse3 Not affected
Show less packages

CVE-2026-33144

Medium priority
Needs evaluation

GPAC is an open-source multimedia framework. Prior to commit 86b0e36, a heap-based buffer overflow (write) vulnerability was discovered in GPAC MP4Box. The vulnerability exists in the gf_xml_parse_bit_sequence_bs function in...

1 affected package

gpac

Package 20.04 LTS
gpac Needs evaluation
Show less packages

CVE-2025-63261

Medium priority
Needs evaluation

AWStats 8.0 is vulnerable to Command Injection via the open function

1 affected package

awstats

Package 20.04 LTS
awstats Needs evaluation
Show less packages

CVE-2026-4438

Medium priority
Needs evaluation

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the...

2 affected packages

glibc, eglibc

Package 20.04 LTS
glibc Needs evaluation
eglibc
Show less packages

CVE-2026-4437

Medium priority
Needs evaluation

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response from the configured DNS server,...

2 affected packages

glibc, eglibc

Package 20.04 LTS
glibc Needs evaluation
eglibc
Show less packages

CVE-2026-4519

Medium priority
Needs evaluation

The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior rejects leading dashes. Users are recommended to sanitize URLs prior to passing...

14 affected packages

jython, pypy3, python2.7, python3.4, python3.5...

Package 20.04 LTS
jython Needs evaluation
pypy3 Needs evaluation
python2.7 Needs evaluation
python3.4
python3.5
python3.6
python3.7
python3.8 Needs evaluation
python3.9 Needs evaluation
python3.10
python3.11
python3.12
python3.13
python3.14
Show all 14 packages Show less packages