Search CVE reports


Toggle filters

111 – 120 of 58662 results

Status is adjusted based on your filters.


CVE-2026-58264

Medium priority
Needs evaluation

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 1.1.2 until 2.5.6, the FluidSynth command handler accepts a pitch_bend_range command whose channel argument is not bounds checked before the...

1 affected package

fluidsynth

Package 16.04 LTS
fluidsynth Needs evaluation
Show less packages

CVE-2026-57226

Medium priority
Needs evaluation

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, HTTP SWF decompression with the non-default swf-decompression feature and an unsafe...

1 affected package

suricata

Package 16.04 LTS
suricata Needs evaluation
Show less packages

CVE-2026-57224

Medium priority
Needs evaluation

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the DHCP parser in rust/src/dhcp/dhcp.rs creates stateless transactions...

1 affected package

suricata

Package 16.04 LTS
suricata Needs evaluation
Show less packages

CVE-2026-57222

Medium priority
Needs evaluation

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, crafted IPv4 and IPv6 address pairs can collide in the IPPair hash...

1 affected package

suricata

Package 16.04 LTS
suricata Needs evaluation
Show less packages

CVE-2026-84975

Medium priority
Needs evaluation

PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the OpenSSL and GnuTLS backends in pjlib/src/pj/ssl_sock_ossl.c and pjlib/src/pj/ssl_sock_gtls.c copy DNS SubjectAltName values...

2 affected packages

asterisk, pjproject

Package 16.04 LTS
asterisk Needs evaluation
pjproject Needs evaluation
Show less packages

CVE-2026-77396

Medium priority
Needs evaluation

PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the PJSIP AVI parser in pjmedia/src/pjmedia/avi_player.c uses an input-file video chunk length as the number of bytes copied into...

2 affected packages

asterisk, pjproject

Package 16.04 LTS
asterisk Needs evaluation
pjproject Needs evaluation
Show less packages

CVE-2026-69186

Medium priority
Needs evaluation

c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_parse() trusts the attacker-controlled ANCOUNT, NSCOUNT, and ARCOUNT fields before confirming that the DNS response contains enough bytes for the claimed...

1 affected package

c-ares

Package 16.04 LTS
c-ares Needs evaluation
Show less packages

CVE-2026-69184

Medium priority
Needs evaluation

c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_name_parse() enforces backward DNS compression pointers but does not bound the total pointer hops or assembled name length. A malicious DNS server can send a...

1 affected package

c-ares

Package 16.04 LTS
c-ares Needs evaluation
Show less packages

CVE-2026-61552

Medium priority
Needs evaluation

Icinga 2 is an open source monitoring system. From 2.4 until 2.14.9, 2.15.4, and 2.16.2, the /v1/objects API writes attacker-controlled template names into generated configuration without escaping them. An authenticated ApiUser...

1 affected package

icinga2

Package 16.04 LTS
icinga2 Needs evaluation
Show less packages

CVE-2026-61551

Medium priority
Needs evaluation

Icinga 2 is an open source monitoring system. Prior to 2.14.9, 2.15.4, and 2.16.2, parsing deeply nested JSON can exhaust the call stack because nesting depth is not bounded. The affected JSON parsing paths are reachable by...

1 affected package

icinga2

Package 16.04 LTS
icinga2 Needs evaluation
Show less packages