Search CVE reports


Toggle filters

121 – 130 of 59781 results

Status is adjusted based on your filters.


CVE-2026-103680

Medium priority
Needs evaluation

A flaw was found in tnef. A heap-based buffer overflow can occur in the find_free_number() function when generating numbered backup suffixes for duplicate filenames. When numbered backups are enabled and file overwriting is...

1 affected package

tnef

Package 16.04 LTS
tnef Needs evaluation
Show less packages

CVE-2026-103679

Medium priority
Needs evaluation

A flaw was found in tnef. A remote attacker could exploit this vulnerability by providing a specially crafted Transport Neutral Encapsulation Format (TNEF) file containing multiple message bodies. During extraction, improper...

1 affected package

tnef

Package 16.04 LTS
tnef Needs evaluation
Show less packages

CVE-2026-103678

Medium priority
Needs evaluation

A flaw was found in tnef. An attacker can exploit this vulnerability by providing a specially crafted file containing uncompressed Rich Text Format (RTF) data. Because the application fails to properly validate input...

1 affected package

tnef

Package 16.04 LTS
tnef Needs evaluation
Show less packages

CVE-2026-103641

Medium priority
Needs evaluation

A flaw was found in GEGL. The Radiance HDR loader reads past the end of a memory-mapped image when an uncompressed scanline is shorter than the width declared in the file header. Opening a crafted HDR file crashes the application...

1 affected package

gegl

Package 16.04 LTS
gegl Needs evaluation
Show less packages

CVE-2026-103531

Medium priority
Needs evaluation

A flaw has been found in OpenSC up to 0.27.1. The impacted element is the function setcos_construct_fci_44 of the file src/libopensc/card-setcos.c. Executing a manipulation of the argument type_attr can lead to stack-based buffer...

1 affected package

opensc

Package 16.04 LTS
opensc Needs evaluation
Show less packages

CVE-2026-103436

Medium priority
Needs evaluation

apcupsd through 3.14.14 discloses uninitialized stack memory in getupsvar() in src/cgi/upsfetch.c (used by upsstats.cgi, multimon.cgi, and upsfstats.cgi. On the single-field path, when the matched STATUS line has fewer than three...

1 affected package

apcupsd

Package 16.04 LTS
apcupsd Needs evaluation
Show less packages

CVE-2026-103432

Medium priority
Needs evaluation

apcupsd through 3.14.14 has an sscanf stack-based buffer overflow in getupsvar() in src/cgi/upsfetch.c (used by upsstats.cgi, multimon.cgi, and upsfstats.cgi), a related issue to CVE-2026-15544.

1 affected package

apcupsd

Package 16.04 LTS
apcupsd Needs evaluation
Show less packages

CVE-2026-103431

Medium priority
Needs evaluation

colmux in collectl before 4.3.20.2 does not sanitize ANSI/VT100 terminal escape sequences in data received from remote collectl instances before displaying it, allowing a local user on a monitored host to inject escape sequences...

1 affected package

collectl

Package 16.04 LTS
collectl Needs evaluation
Show less packages

CVE-2026-103399

Medium priority
Needs evaluation

A flaw was found in SoupServer (libsoup). When an HTTP/1.x client sends a request with Expect: 100-continue and a request body, and SoupServer returns an early final (non-1xx) response before the body is read, the server neither...

2 affected packages

libsoup2.4, libsoup3

Package 16.04 LTS
libsoup2.4 Needs evaluation
libsoup3 —
Show less packages

CVE-2026-103263

Medium priority
Needs evaluation

Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within it. When a symlink pointing outside the...

1 affected package

python-tornado

Package 16.04 LTS
python-tornado Needs evaluation
Show less packages