Search CVE reports


Toggle filters

251 – 260 of 42078 results

Status is adjusted based on your filters.


CVE-2026-44894

Medium priority
Needs evaluation

Netty is a network application framework for development of protocol servers and clients. NoQuicTokenHandler is the tokenHandler used when the application does not set one. Prior to version 4.2.15.Final, its writeToken() returns...

1 affected package

netty

Package 22.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-44893

Medium priority
Needs evaluation

Netty is a network application framework for development of protocol servers and clients. In netty-codec-haproxy prior to versions 4.1.135.Final and 4.2.15.Final, when decoding a PP2_TYPE_SSL TLV, HAProxyMessage.readNextTLV()...

1 affected package

netty

Package 22.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-1836

Medium priority

Not in release

The system stores the username and password from the login form after submitting the request. This could allow an attacker with access to the platform to return to the browser and view the login credentials.

1 affected package

redmine

Package 22.04 LTS
redmine Not in release
Show less packages

CVE-2017-20240

Medium priority
Needs evaluation

Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks. These versions use Perl's built-in eq comparison. Discrepancies in timing could be used to guess the underlying derived-key.

1 affected package

libcrypt-pbkdf2-perl

Package 22.04 LTS
libcrypt-pbkdf2-perl Needs evaluation
Show less packages

CVE-2026-48914

Medium priority
Needs evaluation

A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit...

1 affected package

qemu

Package 22.04 LTS
qemu Needs evaluation
Show less packages

CVE-2026-44892

Medium priority
Needs evaluation

Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final, the default configuration of the `Http3ConnectionHandler` in the Netty HTTP/3 codec lacks an enforced maximum...

1 affected package

netty

Package 22.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-11933

Medium priority

Not in release

A use-after-free vulnerability exists in MongoDB Server's server-side JavaScript engine when converting BSON documents to JavaScript arrays. An authenticated user with read privileges who is able to run server-side JavaScript (for...

1 affected package

mongodb

Package 22.04 LTS
mongodb Not in release
Show less packages

CVE-2026-50012

Medium priority
Fixed

Heap-based Buffer Overflow attack against cache digests

2 affected packages

squid, squid3

Package 22.04 LTS
squid Fixed
squid3 Not in release
Show less packages

CVE-2026-47729

Medium priority
Fixed

Out-of-bounds Read attack against the FTP gateway

2 affected packages

squid, squid3

Package 22.04 LTS
squid Fixed
squid3 Not in release
Show less packages

CVE-2026-44890

Medium priority
Needs evaluation

Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can cause DoS by sending crafted Redis payloads across...

1 affected package

netty

Package 22.04 LTS
netty Needs evaluation
Show less packages