Search CVE reports


Toggle filters

1841 – 1850 of 37432 results

Status is adjusted based on your filters.


CVE-2026-54548

Medium priority
Needs evaluation

kas is a setup tool for bitbake based projects. Prior to 5.4, internal SSH key setup triggered by SSH_PRIVATE_KEY or SSH_PRIVATE_KEY_FILE creates ~/.ssh/config when no user-specific SSH configuration exists and adds a global Host...

1 affected package

kas

Package 26.04 LTS
kas Needs evaluation
Show less packages

CVE-2026-79902

Medium priority
Needs evaluation

A flaw was found in the Seattle FilmWorks plugin in GIMP. When processing a specially crafted SFW image file, the plugin allocates a Variable-Length Array (VLA) on the stack without integer overflow checks, causing an unbounded...

1 affected package

gimp

Package 26.04 LTS
gimp Needs evaluation
Show less packages

CVE-2026-77658

Medium priority
Needs evaluation

A stack-based buffer overflow vulnerability exists in the Dia diagram editor when processing Network Bus objects from Dia XML project files. In objects/network/bus.c, bus_load() reads the number of bus handles from the file...

1 affected package

dia

Package 26.04 LTS
dia Needs evaluation
Show less packages

CVE-2026-80206

Medium priority
Needs evaluation

NLTK before 3.10.3 contains a regular expression denial of service (ReDoS) vulnerability in the tgrep module. The _tgrep_node_action function compiles user-supplied regular expressions embedded in /regex/ pattern nodes...

1 affected package

nltk

Package 26.04 LTS
nltk Needs evaluation
Show less packages

CVE-2026-80205

Medium priority
Needs evaluation

NLTK versions before 3.10.0 contain a regular expression denial of service vulnerability in Text.findall() and TokenSearcher.findall() methods that accept user-supplied regular expressions without validation or timeout. Attackers...

1 affected package

nltk

Package 26.04 LTS
nltk Needs evaluation
Show less packages

CVE-2026-59683

Medium priority
Needs evaluation

The OpenRGB network protocol allows to write attacker controlled strings into arbitrary file system paths (extension of CVE-2026-59682). This allows either a full system compromise from local or remote (if the daemon is running as...

1 affected package

openrgb

Package 26.04 LTS
openrgb Needs evaluation
Show less packages

CVE-2026-59682

Medium priority
Needs evaluation

Arbitrary file overwrite via SAVE_PROFILE message in OpenRGB. This issue affects OpenRGB through 1.0rc3.

1 affected package

openrgb

Package 26.04 LTS
openrgb Needs evaluation
Show less packages

CVE-2026-18794

Medium priority
Needs evaluation

The OpenRGB network protocol allows attackers to cause memory exhaustion and out-of-bounds memory reads and writes by passing inconsistent data.

1 affected package

openrgb

Package 26.04 LTS
openrgb Needs evaluation
Show less packages

CVE-2026-19538

Medium priority
Needs evaluation

The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed completely when connecting over TCP or TLS and sending the query twice on connection that is kept open.

1 affected package

nsd

Package 26.04 LTS
nsd Needs evaluation
Show less packages

CVE-2026-19401

Medium priority
Needs evaluation

Any remote client can crash a (debugging/non-release build type) NSD serve child by sending it a special crafted message with a specially tuned number of DNS Cookie options (17 when UDP payload size is 512). By...

1 affected package

nsd

Package 26.04 LTS
nsd Needs evaluation
Show less packages