Search CVE reports


Toggle filters

341 – 350 of 27411 results

Status is adjusted based on your filters.


CVE-2026-40033

Medium priority
Needs evaluation

FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers to write out-of-bounds heap memory. The vulnerability occurs because rectangle validation clamps coordinates to...

3 affected packages

freerdp, freerdp2, freerdp3

Package 26.04 LTS
freerdp Not in release
freerdp2 Not in release
freerdp3 Needs evaluation
Show less packages

CVE-2026-9541

Medium priority
Needs evaluation

A security flaw has been discovered in Squirrel up to 3.2. Impacted is the function ReadObject of the file squirrel/sqobject.cpp of the component Cnut File Handler. Performing a manipulation results in heap-based buffer overflow....

1 affected package

squirrel3

Package 26.04 LTS
squirrel3 Needs evaluation
Show less packages

CVE-2026-8376

Medium priority
Needs evaluation

Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in...

1 affected package

perl

Package 26.04 LTS
perl Needs evaluation
Show less packages

CVE-2026-9538

Medium priority
Needs evaluation

Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header. _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the...

1 affected package

perl

Package 26.04 LTS
perl Needs evaluation
Show less packages

CVE-2026-48715

Medium priority
Needs evaluation

[Stack Buffer Overflow in radvdump Route Information Option Parser]

1 affected package

radvd

Package 26.04 LTS
radvd Needs evaluation
Show less packages

CVE-2026-48710

Medium priority
Needs evaluation

Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path...

1 affected package

starlette

Package 26.04 LTS
starlette Needs evaluation
Show less packages

CVE-2026-4480

Medium priority
Fixed

A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta...

1 affected package

samba

Package 26.04 LTS
samba Fixed
Show less packages

CVE-2026-4408

Medium priority
Fixed

Unauthenticated Remote Code Execution in Samba DCE/RPC SAMR server

1 affected package

samba

Package 26.04 LTS
samba Fixed
Show less packages

CVE-2026-42497

Medium priority
Needs evaluation

Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory. _make_special_file() passes the tar header's linkname to link() without validating it against absolute...

1 affected package

perl

Package 26.04 LTS
perl Needs evaluation
Show less packages

CVE-2026-42496

Medium priority
Needs evaluation

Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against...

1 affected package

perl

Package 26.04 LTS
perl Needs evaluation
Show less packages