Search CVE reports


Toggle filters

1301 – 1310 of 47890 results

Status is adjusted based on your filters.


CVE-2026-73072

Medium priority
Vulnerable

Vim is an open source, command line text editor. Prior to 9.2.0846, set_sofo() in src/spellfile.c reuses sl_sal_first[] without resetting values left by set_sal_first(), so a crafted spell file containing an SN_SAL section before...

1 affected package

vim

Package 22.04 LTS
vim Vulnerable
Show less packages

CVE-2026-73071

Medium priority
Vulnerable

Vim is an open source, command line text editor. From 9.2.0511 until 9.2.0844, json_decode_item() in src/json.c can retain a stale pointer after json_decode_string() invokes channel_fill() to refill and free the current buffer,...

1 affected package

vim

Package 22.04 LTS
vim Vulnerable
Show less packages

CVE-2026-73070

Medium priority
Not affected

Vim is an open source, command line text editor. Prior to 9.2.0842, the socket server backend in src/socketserver.c accepts unbounded client connections in socketserver_accept(), causing descriptors to overflow fd_set structures...

1 affected package

vim

Package 22.04 LTS
vim Not affected
Show less packages

CVE-2026-6727

Medium priority
Needs evaluation

A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with access to the TPM command interface may be able to exploit timing differences to recover information that could...

1 affected package

libtpms

Package 22.04 LTS
libtpms Needs evaluation
Show less packages

CVE-2026-6726

Medium priority
Needs evaluation

An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an...

1 affected package

libtpms

Package 22.04 LTS
libtpms Needs evaluation
Show less packages

CVE-2026-19546

Medium priority
Needs evaluation

A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.z. For a detailed Statement, Description and Mitigation please reffer to the original...

1 affected package

libdbi-perl

Package 22.04 LTS
libdbi-perl Needs evaluation
Show less packages

CVE-2026-14180

Medium priority
Needs evaluation

A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to handle chunked transfer encoding. The issue occurs because the parser uses a single internal variable to store...

1 affected package

undertow

Package 22.04 LTS
undertow Needs evaluation
Show less packages

CVE-2026-73067

Medium priority
Needs evaluation

Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata model loaded through TessBaseAPI::Init can cause SquishedDawg::read_squished_dawg in src/dict/dawg.cpp to accept an unterminated forward-edge run,...

1 affected package

tesseract

Package 22.04 LTS
tesseract Needs evaluation
Show less packages

CVE-2026-73066

Medium priority
Needs evaluation

Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata LSTM model component loaded through Tesseract's deserializer can cause an unchecked signed integer multiplication in Convolve::DeSerialize in...

1 affected package

tesseract

Package 22.04 LTS
tesseract Needs evaluation
Show less packages

CVE-2026-72746

Medium priority
Not affected

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it's a duplicate of CVE-2026-73241.

3 affected packages

freerdp, freerdp2, freerdp3

Package 22.04 LTS
freerdp Not in release
freerdp2 Not affected
freerdp3 Not in release
Show less packages