Search CVE reports


Toggle filters

491 – 500 of 35777 results

Status is adjusted based on your filters.


CVE-2025-71063

Medium priority

Not in release

Errands before 46.2.10 does not verify TLS certificates for CalDAV servers.

1 affected package

errands

Package 22.04 LTS
errands Not in release
Show less packages

CVE-2025-15506

Medium priority
Needs evaluation

A vulnerability was found in AcademySoftwareFoundation OpenColorIO up to 2.5.0. This issue affects the function ConvertToRegularExpression of the file src/OpenColorIO/FileRules.cpp. Performing a manipulation results...

1 affected package

opencolorio

Package 22.04 LTS
opencolorio Needs evaluation
Show less packages

CVE-2026-0822

Medium priority

Not in release

A vulnerability was identified in quickjs-ng quickjs up to 0.11.0. This issue affects the function js_typed_array_sort of the file quickjs.c. The manipulation leads to heap-based buffer overflow. Remote exploitation of the attack...

1 affected package

quickjs

Package 22.04 LTS
quickjs Not in release
Show less packages

CVE-2026-0821

Medium priority

Not in release

A vulnerability was determined in quickjs-ng quickjs up to 0.11.0. This vulnerability affects the function js_typed_array_constructor of the file quickjs.c. Executing a manipulation can lead to heap-based buffer overflow. The...

1 affected package

quickjs

Package 22.04 LTS
quickjs Not in release
Show less packages

CVE-2026-22703

Medium priority

Not in release

Cosign provides code signing and transparency for containers and binaries. Prior to versions 2.6.2 and 3.0.4, Cosign bundle can be crafted to successfully verify an artifact even if the embedded Rekor entry does not reference the...

1 affected package

cosign

Package 22.04 LTS
cosign Not in release
Show less packages

CVE-2026-22702

Medium priority
Needs evaluation

virtualenv is a tool for creating isolated virtual python environments. Prior to version 20.36.1, TOCTOU (Time-of-Check-Time-of-Use) vulnerabilities in virtualenv allow local attackers to perform symlink-based attacks on directory...

1 affected package

python-virtualenv

Package 22.04 LTS
python-virtualenv Needs evaluation
Show less packages

CVE-2026-22701

Medium priority
Needs evaluation

filelock is a platform-independent file lock for Python. Prior to version 3.20.3, a TOCTOU race condition vulnerability exists in the SoftFileLock implementation of the filelock package. An attacker with local filesystem access...

1 affected package

python-filelock

Package 22.04 LTS
python-filelock Needs evaluation
Show less packages

CVE-2026-22693

Low priority
Not affected

HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer dereference vulnerability exists in the SubtableUnicodesCache::create function located in src/hb-ot-cmap-table.hh. The function fails to check if hb_malloc...

1 affected package

harfbuzz

Package 22.04 LTS
harfbuzz Not affected
Show less packages

CVE-2026-22691

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to version 6.6.0, pypdf has possible long runtimes for malformed startxref. An attacker who uses this vulnerability can craft a PDF which leads to possibly long...

2 affected packages

pypdf, pypdf2

Package 22.04 LTS
pypdf Not in release
pypdf2 Needs evaluation
Show less packages

CVE-2026-22690

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to version 6.6.0, pypdf has possible long runtimes for missing /Root object with large /Size values. An attacker who uses this vulnerability can craft a PDF...

2 affected packages

pypdf, pypdf2

Package 22.04 LTS
pypdf Not in release
pypdf2 Needs evaluation
Show less packages