Search CVE reports


Toggle filters

31 – 40 of 37797 results

Status is adjusted based on your filters.


CVE-2026-5188

Medium priority
Needs evaluation

An integer underflow issue exists in wolfSSL when parsing the Subject Alternative Name (SAN) extension of X.509 certificates. A malformed certificate can specify an entry length larger than the enclosing sequence, causing the...

1 affected package

wolfssl

Package 22.04 LTS
wolfssl Needs evaluation
Show less packages

CVE-2026-5187

Medium priority
Needs evaluation

Two potential heap out-of-bounds write locations existed in DecodeObjectId() in wolfcrypt/src/asn.c. First, a bounds check only validates one available slot before writing two OID arc values (out[0] and out[1]), enabling a 2-byte...

1 affected package

wolfssl

Package 22.04 LTS
wolfssl Needs evaluation
Show less packages

CVE-2026-4660

Medium priority
Needs evaluation

HashiCorp’s go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. This vulnerability, CVE-2026-4660, is fixed in go-getter v1.8.6. This...

1 affected package

golang-github-hashicorp-go-getter

Package 22.04 LTS
golang-github-hashicorp-go-getter Needs evaluation
Show less packages

CVE-2026-40046

Medium priority
Needs evaluation

Integer Overflow or Wraparound vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT. The fix for "CVE-2025-66168: MQTT control packet remaining length field is not properly validated" was only applied to...

1 affected package

activemq

Package 22.04 LTS
activemq Needs evaluation
Show less packages

CVE-2026-39983

Medium priority

Not in release

basic-ftp is an FTP client for Node.js. Prior to 5.2.1, basic-ftp allows FTP command injection via CRLF sequences (\r\n) in file path parameters passed to high-level path APIs such as cd(), remove(), rename(), uploadFrom(),...

1 affected package

node-proxy-agents

Package 22.04 LTS
node-proxy-agents Not in release
Show less packages

CVE-2026-39977

Medium priority
Needs evaluation

flatpak-builder is a tool to build flatpaks from source. From 1.4.5 to before 1.4.8, the license-files manifest key takes an array of paths to user defined licence files relative to the source directory of the module. The paths...

1 affected package

flatpak-builder

Package 22.04 LTS
flatpak-builder Needs evaluation
Show less packages

CVE-2026-39856

Medium priority
Needs evaluation

osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.13, an out-of-bounds read vulnerability exists in osslsigncode version 2.12 and earlier in the PE page-hash computation...

1 affected package

osslsigncode

Package 22.04 LTS
osslsigncode Needs evaluation
Show less packages

CVE-2026-39855

Medium priority
Needs evaluation

osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.13, an integer underflow vulnerability exists in osslsigncode version 2.12 and earlier in the PE page-hash computation...

1 affected package

osslsigncode

Package 22.04 LTS
osslsigncode Needs evaluation
Show less packages

CVE-2026-39853

Medium priority
Needs evaluation

osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.12, A stack buffer overflow vulnerability exists in osslsigncode in several signature verification paths. During verification of a PKCS#7...

1 affected package

osslsigncode

Package 22.04 LTS
osslsigncode Needs evaluation
Show less packages

CVE-2026-39304

Medium priority
Needs evaluation

[Unknown description]

1 affected package

activemq

Package 22.04 LTS
activemq Needs evaluation
Show less packages