Search CVE reports


Toggle filters

1331 – 1340 of 47890 results

Status is adjusted based on your filters.


CVE-2026-62871

Medium priority
Ignored

Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.

5 affected packages

dotnet6, dotnet7, dotnet8, dotnet9, dotnet10

Package 22.04 LTS
dotnet6 Not affected
dotnet7 Ignored
dotnet8 Not affected
dotnet9 Not in release
dotnet10 Not in release
Show less packages

CVE-2026-6426

Medium priority
Needs evaluation

A type mismatch vulnerability was found in QEMU's vhost inflight migration VMState handling. The destination buffer size is stored as a uint64_t but read by the VMS_VBUFFER load path as a signed int32_t. On little-endian hosts, a...

1 affected package

qemu

Package 22.04 LTS
qemu Needs evaluation
Show less packages

CVE-2026-72913

Medium priority
Needs evaluation

Kitty is a cross-platform GPU based terminal. Prior to 0.48.2, the @kitty-echo and @kitty-ssh DCS handlers in kitty/window.py write unauthenticated data to the child shell's stdin, where handle_remote_echo accepts printable shell...

1 affected package

kitty

Package 22.04 LTS
kitty Needs evaluation
Show less packages

CVE-2026-63622

Medium priority
Vulnerable

A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnerability in the `virFileChownFiles()` function. By planting a symbolic link within...

1 affected package

libvirt

Package 22.04 LTS
libvirt Vulnerable
Show less packages

CVE-2026-19411

Medium priority
Needs evaluation

A NULL pointer vulnerability has been found in the the shim application of dp.c library. A missing NULL pointer could allow attackers to perform a denial of service attack on a system that uses shim application for UEFI bootloader.

3 affected packages

secureboot-db, shim-signed, shim

Package 22.04 LTS
secureboot-db Needs evaluation
shim-signed Needs evaluation
shim Needs evaluation
Show less packages

CVE-2026-71969

Medium priority

Not in release

OP-TEE OS through 4.10.0, fixed in commit 7b8b494, contains a buffer underwrite vulnerability in the RSA NOPAD encrypt and decrypt operations within the mbedTLS software backend and SE050 hardware driver that allows a malicious...

1 affected package

optee-os

Package 22.04 LTS
optee-os Not in release
Show less packages

CVE-2026-71968

Medium priority

Not in release

OP-TEE OS through 4.10.0, fixed in commit 8794043, contains a use-after-free vulnerability in the Trusted Application loader that allows attackers with the ability to load a signed Trusted Application to corrupt secure-world...

1 affected package

optee-os

Package 22.04 LTS
optee-os Not in release
Show less packages

CVE-2026-71967

Medium priority

Not in release

OP-TEE OS through 4.10.0, fixed in commit 0aadfc2, contains a null pointer dereference vulnerability in the Widevine pseudo-TA open_session handler that allows Normal World clients to cause a denial of service...

1 affected package

optee-os

Package 22.04 LTS
optee-os Not in release
Show less packages

CVE-2026-6791

Medium priority
Needs evaluation

When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory. The implementation allocates memory for this username...

2 affected packages

glibc, eglibc

Package 22.04 LTS
glibc Needs evaluation
eglibc Not in release
Show less packages

CVE-2026-6368

Medium priority
Needs evaluation

Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.

2 affected packages

glibc, eglibc

Package 22.04 LTS
glibc Needs evaluation
eglibc Not in release
Show less packages