Search CVE reports


Toggle filters

21 – 30 of 59608 results

Status is adjusted based on your filters.


CVE-2026-102930

Medium priority
Needs evaluation

virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.12, download_wheel() accepts pip and setuptools seed wheels fetched for periodic updates or the --download option without checking their bytes...

1 affected package

python-virtualenv

Package 16.04 LTS
python-virtualenv Needs evaluation
Show less packages

CVE-2026-102925

Medium priority
Needs evaluation

virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.13, the generated activate (bash and zsh) and activate.fish scripts place values already escaped by shlex.quote inside an additional quoted...

1 affected package

python-virtualenv

Package 16.04 LTS
python-virtualenv Needs evaluation
Show less packages

CVE-2026-102620

Medium priority
Needs evaluation

A vulnerability was determined in Freedesktop Poppler 26.06.0/26.07.0/26.08.0. This impacts the function FoFiTrueType::cvtSfnts of the file fofi/FoFiTrueType.cc. This manipulation causes integer overflow. The attack can only be...

1 affected package

poppler

Package 16.04 LTS
poppler Needs evaluation
Show less packages

CVE-2026-102253

Medium priority
Needs evaluation

iperf3 versions prior to 3.22 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash-loop the server's UDP receive worker into an unrecoverable infinite loop by sending a single crafted...

1 affected package

iperf3

Package 16.04 LTS
iperf3 Needs evaluation
Show less packages

CVE-2026-102875

Medium priority
Needs evaluation

VLC media player before 3.0.24 contains a path traversal vulnerability in the skins2 ThemeLoader that fails to validate member names in .vlt skin archives. Attackers can craft malicious skin files with path traversal sequences to...

1 affected package

vlc

Package 16.04 LTS
vlc Needs evaluation
Show less packages

CVE-2026-12345

Medium priority
Needs evaluation

The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be...

11 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7...

Package 16.04 LTS
python2.7 Needs evaluation
python3.4 —
python3.5 Needs evaluation
python3.6 —
python3.7 —
python3.8 —
python3.9 —
python3.10 —
python3.11 —
python3.12 —
python3.14 —
Show all 11 packages Show less packages

CVE-2026-102560

Medium priority
Needs evaluation

A flaw was found in libsoup. When the permessage-deflate WebSocket extension compresses a very large outgoing message, truncated size calculations used for GByteArray growth could wrap, causing zlib to write past the allocated...

2 affected packages

libsoup2.4, libsoup3

Package 16.04 LTS
libsoup2.4 Needs evaluation
libsoup3 —
Show less packages

CVE-2026-102559

Medium priority
Needs evaluation

A flaw was found in libsoup. When constructing a masked WebSocket client frame for a very large outgoing payload, size values passed to GByteArray allocation APIs could be truncated while the masking routine still used the full...

2 affected packages

libsoup2.4, libsoup3

Package 16.04 LTS
libsoup2.4 Needs evaluation
libsoup3 —
Show less packages

CVE-2026-102558

Medium priority
Needs evaluation

A flaw was found in libsoup. When max-incoming-payload-size is unlimited (0), SoupWebsocketConnection could grow its incoming GByteArray based on an attacker-controlled frame length until the length wrapped, causing a heap buffer...

2 affected packages

libsoup2.4, libsoup3

Package 16.04 LTS
libsoup2.4 Needs evaluation
libsoup3 —
Show less packages

CVE-2026-102555

Medium priority
Needs evaluation

A flaw was found in libsoup. The soup_uri_decode_data_uri() function incorrectly treated base64 data-URI payloads as NUL-terminated strings when calling g_base64_decode_inplace(). If the percent-decoded payload contained embedded...

2 affected packages

libsoup2.4, libsoup3

Package 16.04 LTS
libsoup2.4 Needs evaluation
libsoup3 —
Show less packages