Search CVE reports


Toggle filters

31 – 40 of 59631 results

Status is adjusted based on your filters.


CVE-2026-74220

Medium priority
Needs evaluation

U-Boot before 2026.10-rc5 contains a buffer overflow in nfs_read_reply() function in net/nfs-common.c that allows attackers to corrupt memory by supplying crafted NFS READ reply lengths. A malicious NFS server can exploit signed...

2 affected packages

u-boot, u-boot-nezha

Package 16.04 LTS
u-boot Needs evaluation
u-boot-nezha —
Show less packages

CVE-2026-71974

Medium priority
Needs evaluation

U-Boot before 2026.10-rc3 contains an out-of-bounds write vulnerability in read_slotted_partition() that fails to validate image size against partition bounds. Attackers with physical access can supply crafted boot media with...

2 affected packages

u-boot, u-boot-nezha

Package 16.04 LTS
u-boot Needs evaluation
u-boot-nezha —
Show less packages

CVE-2026-71973

Medium priority
Needs evaluation

U-Boot before 2026.10-rc4 contains an integer overflow vulnerability in sqfs_read_directory_table() function when allocating the directory table buffer. Attackers can supply a crafted SquashFS image with an attacker-controlled...

2 affected packages

u-boot, u-boot-nezha

Package 16.04 LTS
u-boot Needs evaluation
u-boot-nezha —
Show less packages

CVE-2026-71972

Medium priority
Needs evaluation

U-Boot through 2026.10-rc5 contains an out-of-bounds write vulnerability in the video_display_rle8_bitmap function in drivers/video/video_bmp.c. Attackers can supply a crafted RLE8-compressed BMP image to corrupt memory adjacent...

2 affected packages

u-boot, u-boot-nezha

Package 16.04 LTS
u-boot Needs evaluation
u-boot-nezha —
Show less packages

CVE-2026-71971

Medium priority
Needs evaluation

U-Boot before 2026.10-rc3 with CONFIG_IP_DEFRAG enabled contains an out-of-bounds write vulnerability in the __net_defragment() function in net/net.c. Remote attackers can send a crafted IP fragment with non-zero offset and...

2 affected packages

u-boot, u-boot-nezha

Package 16.04 LTS
u-boot Needs evaluation
u-boot-nezha —
Show less packages

CVE-2026-102621

Medium priority
Needs evaluation

A vulnerability was identified in Freedesktop Poppler up to 26.08.0. Affected is the function SplashClip::clipToPath of the file splash/SplashClip.cc. Such manipulation leads to integer overflow. The attack can only be performed...

1 affected package

poppler

Package 16.04 LTS
poppler Needs evaluation
Show less packages

CVE-2026-93853

Medium priority
Needs evaluation

Unverified ownership in Barman snapshot backup deletion allows a principal who can write the backup catalog to cause Barman to delete unrelated cloud snapshots. When a snapshot backup is deleted, either explicitly or by retention...

1 affected package

barman

Package 16.04 LTS
barman Needs evaluation
Show less packages

CVE-2026-102938

Medium priority
Needs evaluation

virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.11, PyEnvCfg.write() writes prompt values verbatim to the line-oriented pyvenv.cfg format while PyEnvCfg._read_values() parses the file with...

1 affected package

python-virtualenv

Package 16.04 LTS
python-virtualenv Needs evaluation
Show less packages

CVE-2026-102937

Medium priority
Needs evaluation

virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.12, BatchActivator.quote() returns prompt text unchanged before activate.bat inserts it into a cmd.exe set "VAR=value" statement. An attacker...

1 affected package

python-virtualenv

Package 16.04 LTS
python-virtualenv Needs evaluation
Show less packages

CVE-2026-102930

Medium priority
Needs evaluation

virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.12, download_wheel() accepts pip and setuptools seed wheels fetched for periodic updates or the --download option without checking their bytes...

1 affected package

python-virtualenv

Package 16.04 LTS
python-virtualenv Needs evaluation
Show less packages