Search CVE reports


Toggle filters

1 – 10 of 56449 results

Status is adjusted based on your filters.


CVE-2026-82608

Medium priority
Needs evaluation

A vulnerability was determined in Kamailio up to 5.5.0/6.0.7. This affects the function get_4bytes of the file src/modules/ims_registrar_scscf/cxdx_avp.c of the component AVP Handler. Executing a manipulation can lead to...

1 affected package

kamailio

Package 16.04 LTS
kamailio Needs evaluation
Show less packages

CVE-2026-82591

Medium priority
Needs evaluation

A security vulnerability has been detected in Open Asset Import Library Assimp up to 6.0.2. The impacted element is the function MD5Importer::MakeDataUnique of the file code/AssetLib/MD5/MD5Loader.cpp. The manipulation of the...

1 affected package

assimp

Package 16.04 LTS
assimp Needs evaluation
Show less packages

CVE-2026-82562

Medium priority
Needs evaluation

### Summary When `qs.parse` is called with `comma: true` and `throwOnLimitExceeded: true`, a comma-separated value under a bracket-push key (`a[]=1,2,3,4`) is split into an array without being compared against `arrayLimit`, while...

1 affected package

node-qs

Package 16.04 LTS
node-qs Needs evaluation
Show less packages

CVE-2026-82474

Medium priority
Needs evaluation

Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode. Users permitted to run specific commands can execute denied programs by calling execveat directly or through...

1 affected package

sudo

Package 16.04 LTS
sudo Needs evaluation
Show less packages

CVE-2026-82455

Medium priority
Needs evaluation

RubyGems fails to re-validate path containment after filesystem symlink resolution during gem extraction. When a pre-existing symlink inside the destination directory points outside the extraction root, extracted files that appear...

6 affected packages

rubygems, ruby2.3, ruby2.5, ruby2.7, ruby3.0, jruby

Package 16.04 LTS
rubygems
ruby2.3 Needs evaluation
ruby2.5
ruby2.7
ruby3.0
jruby Needs evaluation
Show less packages

CVE-2026-82417

Medium priority
Needs evaluation

### Summary `qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a truthy, non-callable `isBuffer` member. `utils.isBuffer` duck-types buffers by...

1 affected package

node-qs

Package 16.04 LTS
node-qs Needs evaluation
Show less packages

CVE-2026-82343

Medium priority
Needs evaluation

A flaw was found in the file-psd plugin in GIMP. When processing a specially crafted PSD image file, the plugin does not properly validate the channel-count parameter. This incorrect validation leads to improper memory bounds...

1 affected package

gimp

Package 16.04 LTS
gimp Needs evaluation
Show less packages

CVE-2026-82330

Medium priority
Needs evaluation

A flaw was found in the file-pvr plugin in GIMP. When processing a specially crafted PVR image file, the VQ (compressed) decoder does not properly perform memory bounds checking. This missing validation results in a heap...

1 affected package

gimp

Package 16.04 LTS
gimp Needs evaluation
Show less packages

CVE-2026-82328

Medium priority
Needs evaluation

A flaw was found in the file-ico plugin in GIMP. When processing a specially crafted ICO image file, the plugin does not properly validate the used_clrs (palette count) parameter. This incorrect validation leads to improper memory...

1 affected package

gimp

Package 16.04 LTS
gimp Needs evaluation
Show less packages

CVE-2026-82327

Medium priority
Needs evaluation

A flaw was found in libsolv, a dependency-resolution library used by RPM-based package managers such as dnf and zypper to work with .solv repository cache files. When libsolv rewrites a .solv cache file, it reads directory-id...

1 affected package

libsolv

Package 16.04 LTS
libsolv Needs evaluation
Show less packages