Search CVE reports


Toggle filters

1 – 10 of 37654 results

Status is adjusted based on your filters.


CVE-2026-4115

Medium priority
Needs evaluation

A vulnerability was detected in PuTTY 0.83. Affected is the function eddsa_verify of the file crypto/ecc-ssh.c of the component Ed25519 Signature Handler. The manipulation results in improper verification of cryptographic...

1 affected package

putty

Package 20.04 LTS
putty Needs evaluation
Show less packages

CVE-2026-33550

Medium priority
Needs evaluation

SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits instead of the 20 recommended).

1 affected package

sogo

Package 20.04 LTS
sogo Needs evaluation
Show less packages

CVE-2026-33228

Medium priority
Needs evaluation

flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled string values from the parsed JSON as direct array index keys, without validating that they are numeric. Since...

1 affected package

node-flatted

Package 20.04 LTS
node-flatted Needs evaluation
Show less packages

CVE-2019-25585

Medium priority
Needs evaluation

Deluge 1.3.15 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Webseeds field. Attackers can paste a buffer of 5000 bytes into...

1 affected package

deluge

Package 20.04 LTS
deluge Needs evaluation
Show less packages

CVE-2026-29111

Medium priority
Fixed

Local unprivileged user can trigger an assert in systemd

1 affected package

systemd

Package 20.04 LTS
systemd Fixed
Show less packages

CVE-2026-25075

Medium priority
Needs evaluation

Integer Underflow When Handling EAP-TTLS AVP. A vulnerability in the eap-ttls plugin related to processing EAP-TTLS AVPs was discovered in strongSwan that can result in resource exhaustion or a crash. All versions since 4.5.0 are affected.

1 affected package

strongswan

Package 20.04 LTS
strongswan Needs evaluation
Show less packages

CVE-2026-4426

Medium priority
Needs evaluation

A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can...

1 affected package

libarchive

Package 20.04 LTS
libarchive Needs evaluation
Show less packages

CVE-2026-4424

Medium priority
Needs evaluation

A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A...

1 affected package

libarchive

Package 20.04 LTS
libarchive Needs evaluation
Show less packages

CVE-2026-4395

Medium priority
Needs evaluation

Heap-based buffer overflow in the KCAPI ECC code path of wc_ecc_import_x963_ex() in wolfSSL wolfcrypt allows a remote attacker to write attacker-controlled data past the bounds of the pubkey_raw buffer via a crafted oversized EC...

1 affected package

wolfssl

Package 20.04 LTS
wolfssl Needs evaluation
Show less packages

CVE-2026-4159

Medium priority
Needs evaluation

1-byte OOB heap read in wc_PKCS7_DecodeEnvelopedData via zero-length encrypted content. A vulnerability existed in wolfSSL 5.8.4 and earlier, where a 1-byte out-of-bounds heap read in wc_PKCS7_DecodeEnvelopedData could be...

1 affected package

wolfssl

Package 20.04 LTS
wolfssl Needs evaluation
Show less packages