Search CVE reports


Toggle filters

131 – 140 of 50531 results

Status is adjusted based on your filters.


CVE-2026-103432

Medium priority
Needs evaluation

apcupsd through 3.14.14 has an sscanf stack-based buffer overflow in getupsvar() in src/cgi/upsfetch.c (used by upsstats.cgi, multimon.cgi, and upsfstats.cgi), a related issue to CVE-2026-15544.

1 affected package

apcupsd

Package 20.04 LTS
apcupsd Needs evaluation
Show less packages

CVE-2026-103431

Medium priority
Needs evaluation

colmux in collectl before 4.3.20.2 does not sanitize ANSI/VT100 terminal escape sequences in data received from remote collectl instances before displaying it, allowing a local user on a monitored host to inject escape sequences...

1 affected package

collectl

Package 20.04 LTS
collectl Needs evaluation
Show less packages

CVE-2026-103399

Medium priority
Needs evaluation

A flaw was found in SoupServer (libsoup). When an HTTP/1.x client sends a request with Expect: 100-continue and a request body, and SoupServer returns an early final (non-1xx) response before the body is read, the server neither...

2 affected packages

libsoup2.4, libsoup3

Package 20.04 LTS
libsoup2.4 Needs evaluation
libsoup3 —
Show less packages

CVE-2026-103387

Medium priority
Needs evaluation

A weakness has been identified in garycourt uri-js up to 4.4.1. This affects the function URI.parse of the file src/schemes/mailto.ts of the component Mailto Header Handler. This manipulation of the argument to causes uncaught...

1 affected package

node-uri-js

Package 20.04 LTS
node-uri-js Needs evaluation
Show less packages

CVE-2026-103263

Medium priority
Needs evaluation

Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within it. When a symlink pointing outside the...

1 affected package

python-tornado

Package 20.04 LTS
python-tornado Needs evaluation
Show less packages

CVE-2026-103262

Medium priority
Needs evaluation

Tornado versions before 6.5.9 contain an unbounded memory accumulation vulnerability in CurlAsyncHTTPClient that allows remote attackers to cause denial of service by sending a compressed response. Attackers can send...

1 affected package

python-tornado

Package 20.04 LTS
python-tornado Needs evaluation
Show less packages

CVE-2026-103261

Medium priority
Needs evaluation

Tornado before 6.5.9 fails to limit the number of query string fields in HTTPServerRequest.__init__, allowing remote attackers to cause event-loop stalling by sending requests with thousands of query parameters. Attackers can send...

1 affected package

python-tornado

Package 20.04 LTS
python-tornado Needs evaluation
Show less packages

CVE-2026-103242

Medium priority
Needs evaluation

A heap-based buffer overflow flaw was found in rpm. RPMTAG_FILESIGNATURES in a crafted, unsigned RPM package's main header is declared with the wrong header type, causing hex2binv() to allocate a one-byte buffer and then write the...

1 affected package

rpm

Package 20.04 LTS
rpm Needs evaluation
Show less packages

CVE-2026-103227

Medium priority
Needs evaluation

A weakness has been identified in GPAC up to 26.07.0. Affected by this issue is the function gf_dash_resolve_url of the file src/media_tools/dash_client.c of the component DASH Client. This manipulation causes buffer overflow. The...

1 affected package

gpac

Package 20.04 LTS
gpac Needs evaluation
Show less packages

CVE-2026-103226

Medium priority
Needs evaluation

A vulnerability was identified in Artifex Ghostscript up to 10.09.0. Affected is the function type1_callsubr of the file devices/vector/gdevpsfx.c of the component Pdfwrite. The manipulation leads to stack-based buffer overflow....

1 affected package

ghostscript

Package 20.04 LTS
ghostscript Needs evaluation
Show less packages