Search CVE reports


Toggle filters

51 – 60 of 46920 results

Status is adjusted based on your filters.


CVE-2026-82455

Medium priority
Needs evaluation

RubyGems fails to re-validate path containment after filesystem symlink resolution during gem extraction. When a pre-existing symlink inside the destination directory points outside the extraction root, extracted files that appear...

6 affected packages

rubygems, ruby2.3, ruby2.5, ruby2.7, ruby3.0, jruby

Package 20.04 LTS
rubygems
ruby2.3
ruby2.5
ruby2.7 Needs evaluation
ruby3.0
jruby Needs evaluation
Show less packages

CVE-2026-82417

Medium priority
Needs evaluation

### Summary `qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a truthy, non-callable `isBuffer` member. `utils.isBuffer` duck-types buffers by...

1 affected package

node-qs

Package 20.04 LTS
node-qs Needs evaluation
Show less packages

CVE-2026-82343

Medium priority
Needs evaluation

A flaw was found in the file-psd plugin in GIMP. When processing a specially crafted PSD image file, the plugin does not properly validate the channel-count parameter. This incorrect validation leads to improper memory bounds...

1 affected package

gimp

Package 20.04 LTS
gimp Needs evaluation
Show less packages

CVE-2026-82330

Medium priority
Needs evaluation

A flaw was found in the file-pvr plugin in GIMP. When processing a specially crafted PVR image file, the VQ (compressed) decoder does not properly perform memory bounds checking. This missing validation results in a heap...

1 affected package

gimp

Package 20.04 LTS
gimp Needs evaluation
Show less packages

CVE-2026-82328

Medium priority
Needs evaluation

A flaw was found in the file-ico plugin in GIMP. When processing a specially crafted ICO image file, the plugin does not properly validate the used_clrs (palette count) parameter. This incorrect validation leads to improper memory...

1 affected package

gimp

Package 20.04 LTS
gimp Needs evaluation
Show less packages

CVE-2026-82327

Medium priority
Needs evaluation

A flaw was found in libsolv, a dependency-resolution library used by RPM-based package managers such as dnf and zypper to work with .solv repository cache files. When libsolv rewrites a .solv cache file, it reads directory-id...

1 affected package

libsolv

Package 20.04 LTS
libsolv Needs evaluation
Show less packages

CVE-2026-82324

Medium priority
Needs evaluation

A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP. When processing a specially crafted IFF/ILBM image file, the plugin does not properly validate the HAM row size and improperly handles cases where the number of color...

1 affected package

gimp

Package 20.04 LTS
gimp Needs evaluation
Show less packages

CVE-2026-81934

Medium priority
Needs evaluation

Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute...

1 affected package

redis

Package 20.04 LTS
redis Needs evaluation
Show less packages

CVE-2026-81893

Medium priority
Needs evaluation

A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG image containing chunked ICC profile markers, an error during ICC profile parsing can leave stale size metadata after the profile buffer is freed. A subsequent...

1 affected package

gdk-pixbuf

Package 20.04 LTS
gdk-pixbuf Needs evaluation
Show less packages

CVE-2026-81727

Medium priority
Needs evaluation

NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloader.incr_download methods that allows attackers to overwrite files outside the install root through...

1 affected package

nltk

Package 20.04 LTS
nltk Needs evaluation
Show less packages