Search CVE reports


Toggle filters

1251 – 1260 of 43788 results

Status is adjusted based on your filters.


CVE-2026-19557

Medium priority
Not affected

Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security...

1 affected package

chromium-browser

Package 24.04 LTS
chromium-browser Not affected
Show less packages

CVE-2026-19556

Medium priority
Not affected

Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

1 affected package

chromium-browser

Package 24.04 LTS
chromium-browser Not affected
Show less packages

CVE-2026-18710

Medium priority
Needs evaluation

A MongoDB driver component could write sensitive configuration information, including a credential used for outbound network connectivity, to application log output in cleartext during routine client initialization. This occurs...

1 affected package

mongo-java-driver

Package 24.04 LTS
mongo-java-driver Needs evaluation
Show less packages

CVE-2026-71290

Medium priority
Needs evaluation

Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept...

1 affected package

httpcomponents-core5

Package 24.04 LTS
httpcomponents-core5 Needs evaluation
Show less packages

CVE-2026-29035

Medium priority
Needs evaluation

CivetWeb (commit 4a4f0c95) contains a heap and stack buffer overflow vulnerability in the read_websocket() function that allows unauthenticated remote attackers to corrupt memory by sending compressed WebSocket frames when both...

1 affected package

civetweb

Package 24.04 LTS
civetweb Needs evaluation
Show less packages

CVE-2026-19550

Medium priority
Needs evaluation

A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rather than a trust-administration permission, allowing an authenticated, non-privileged IPA user to trigger...

1 affected package

freeipa

Package 24.04 LTS
freeipa Needs evaluation
Show less packages

CVE-2026-73283

Medium priority
Needs evaluation

In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.

2 affected packages

openssh, openssh-ssh1

Package 24.04 LTS
openssh Needs evaluation
openssh-ssh1 Ignored
Show less packages

CVE-2026-73282

Medium priority
Needs evaluation

In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.

2 affected packages

openssh, openssh-ssh1

Package 24.04 LTS
openssh Needs evaluation
openssh-ssh1 Ignored
Show less packages

CVE-2026-73281

Medium priority
Needs evaluation

In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and...

2 affected packages

openssh, openssh-ssh1

Package 24.04 LTS
openssh Needs evaluation
openssh-ssh1 Ignored
Show less packages

CVE-2026-73242

Medium priority

Some fixes available 1 of 2

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP's winpr/libwinpr/sspi/Kerberos/kerberos.c kerberos_DecryptMessage function fails to bound the peer-controlled GSS Wrap-token EC field before...

3 affected packages

freerdp, freerdp2, freerdp3

Package 24.04 LTS
freerdp Not in release
freerdp2 Needs evaluation
freerdp3 Fixed
Show less packages