Search CVE reports


Toggle filters

531 – 540 of 42506 results

Status is adjusted based on your filters.


CVE-2026-23942

Medium priority
Needs evaluation

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP (ssh_sftpd module) allows Path Traversal. This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl and...

1 affected package

erlang

Package 18.04 LTS
erlang Needs evaluation
Show less packages

CVE-2026-23941

Medium priority
Needs evaluation

Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling. This vulnerability is associated with program...

1 affected package

erlang

Package 18.04 LTS
erlang Needs evaluation
Show less packages

CVE-2026-32597

Medium priority
Fixed

PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 ยง4.1.11. When a JWS token contains a crit array listing extensions that PyJWT...

1 affected package

pyjwt

Package 18.04 LTS
pyjwt Fixed
Show less packages

CVE-2026-32259

Medium priority
Needs evaluation

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-16 and 6.9.13-41, when a memory allocation fails in the sixel encoder it would be possible to write past the end of a...

1 affected package

imagemagick

Package 18.04 LTS
imagemagick Needs evaluation
Show less packages

CVE-2026-32249

Medium priority
Not affected

Vim is an open source, command line text editor. From 9.1.0011 to before 9.2.0137, Vim's NFA regex compiler, when encountering a collection containing a combining character as the endpoint of a character range (e.g. [0-0\u05bb]),...

1 affected package

vim

Package 18.04 LTS
vim Not affected
Show less packages

CVE-2026-32240

Medium priority
Needs evaluation

Cap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, when using Transfer-Encoding: chunked, if a chunk's size parsed to a value of 2^64 or larger, it would be truncated to a 64-bit integer. In...

1 affected package

capnproto

Package 18.04 LTS
capnproto Needs evaluation
Show less packages

CVE-2026-32239

Medium priority
Needs evaluation

Cap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, a negative Content-Length value was converted to unsigned, treating it as an impossibly large length instead. In theory, this bug could...

1 affected package

capnproto

Package 18.04 LTS
capnproto Needs evaluation
Show less packages

CVE-2025-70873

Medium priority
Not affected

An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.

2 affected packages

sqlite, sqlite3

Package 18.04 LTS
sqlite Not affected
sqlite3 Not affected
Show less packages

CVE-2026-32116

Medium priority
Needs evaluation

Magic Wormhole makes it possible to get arbitrary-sized files and directories from one computer to another. From 0.21.0 to before 0.23.0, receiving a file (wormhole receive) from a malicious party could result in overwriting...

1 affected package

magic-wormhole

Package 18.04 LTS
magic-wormhole Needs evaluation
Show less packages

CVE-2025-13462

Medium priority
Needs evaluation

The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being...

12 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7...

Package 18.04 LTS
python2.7 Needs evaluation
python3.4
python3.5
python3.6 Needs evaluation
python3.7 Needs evaluation
python3.8 Needs evaluation
python3.9
python3.10
python3.11
python3.12
python3.13
python3.14
Show all 12 packages Show less packages