Search CVE reports


Toggle filters

341 – 350 of 60208 results

Status is adjusted based on your filters.


CVE-2026-104037

Medium priority
Needs evaluation

A flaw was found in SSSD. A local attacker can exploit this issue by sending a specially crafted request with an invalid packet length to the autofs responder UNIX socket. This causes an integer underflow and an out-of-bounds...

1 affected package

sssd

Package 16.04 LTS
sssd Needs evaluation
Show less packages

CVE-2026-104036

Medium priority
Needs evaluation

A flaw was found in SSSD's NFS idmap plugin. When retrieving cached user or group names, the plugin detects if an entry exceeds the destination buffer size but fails to abort before copying data. A local attacker can trigger this...

1 affected package

sssd

Package 16.04 LTS
sssd Needs evaluation
Show less packages

CVE-2026-104035

Medium priority
Needs evaluation

A flaw was found in SSSD. An issue in the Kerberos Credential Manager (KCM) responder allows a local user to cause a Denial of Service (DoS) by maintaining a persistent connection and repeatedly storing and destroying credentials....

1 affected package

sssd

Package 16.04 LTS
sssd Needs evaluation
Show less packages

CVE-2026-104034

Medium priority
Needs evaluation

A flaw was found in SSSD. A use-after-free vulnerability exists in the Kerberos Credential Manager (KCM) responder during Kerberos ticket-granting ticket (TGT) renewal, where a deferred callback accesses memory that has already...

1 affected package

sssd

Package 16.04 LTS
sssd Needs evaluation
Show less packages

CVE-2026-104033

Medium priority
Needs evaluation

A flaw was found in SSSD. When configured to enforce account expiration using LDAP (Lightweight Directory Access Protocol) shadow attributes, SSSD fails to treat an expiration value of zero as an expired account. A user with valid...

1 affected package

sssd

Package 16.04 LTS
sssd Needs evaluation
Show less packages

CVE-2026-104032

Medium priority
Needs evaluation

A flaw was found in SSSD. An unprivileged local user can repeatedly request master automount map updates through the autofs responder due to missing authorization checks. This triggers global cache invalidation and forces repeated...

1 affected package

sssd

Package 16.04 LTS
sssd Needs evaluation
Show less packages

CVE-2026-104031

Medium priority
Needs evaluation

A flaw was found in SSSD. In configurations where the autofs responder service is enabled, memory allocated during successful request processing is not released until the client connection terminates. A local attacker can exploit...

1 affected package

sssd

Package 16.04 LTS
sssd Needs evaluation
Show less packages

CVE-2026-105782

Medium priority
Needs evaluation

Scrapy is a high-level web crawling and scraping framework for Python. From 1.4.0 until 2.14.2, RefererMiddleware in scrapy/spidermiddlewares/referer.py treated a Referrer-Policy response-header value that resembled a Python...

1 affected package

python-scrapy

Package 16.04 LTS
python-scrapy Needs evaluation
Show less packages

CVE-2026-93323

Medium priority
Needs evaluation

(The Dockerfile frontend loaded the Dockerfile and .dockerignore files ...)

2 affected packages

docker.io, docker.io-app

Package 16.04 LTS
docker.io Needs evaluation
docker.io-app —
Show less packages

CVE-2026-93322

Medium priority
Needs evaluation

(A malicious frontend can submit an LLB definition that causes buildkit ...)

2 affected packages

docker.io, docker.io-app

Package 16.04 LTS
docker.io Needs evaluation
docker.io-app —
Show less packages