Search CVE reports


Toggle filters

1 – 10 of 49410 results

Status is adjusted based on your filters.


CVE-2026-95616

Medium priority
Needs evaluation

An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An unauthenticated attacker can send a SOAP message carrying an X.509 certificate whose SubjectKeyIdentifier extension declares a length...

1 affected package

wss4j

Package 24.04 LTS
wss4j Needs evaluation
Show less packages

CVE-2026-95512

Medium priority
Needs evaluation

A flaw was found in FreeType, specifically within its CID font loader. A remote attacker could exploit this vulnerability by tricking a user into opening content that embeds or references a specially crafted CID-keyed font. This...

1 affected package

freetype

Package 24.04 LTS
freetype Needs evaluation
Show less packages

CVE-2026-94603

Medium priority

Not in release

[Unknown description]

1 affected package

podman

Package 24.04 LTS
podman Not in release
Show less packages

CVE-2026-93546

Medium priority
Needs evaluation

Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests...

1 affected package

apache2

Package 24.04 LTS
apache2 Needs evaluation
Show less packages

CVE-2026-92899

Medium priority
Needs evaluation

Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reused. It stored the Nonce as raw base64 text, but authentication decodes that text and uses the bytes.The same bytes can be written...

1 affected package

wss4j

Package 24.04 LTS
wss4j Needs evaluation
Show less packages

CVE-2026-92121

Medium priority
Needs evaluation

In the WSS4J streaming (StAX) code, a signature reference using the WS-Security STR-Transform leaves an internal "inside signed content" flag permanently set. The WS-SecurityPolicy enforcer uses that flag to decide whether an...

1 affected package

wss4j

Package 24.04 LTS
wss4j Needs evaluation
Show less packages

CVE-2026-91148

Medium priority
Needs evaluation

[Unknown description]

1 affected package

cockpit

Package 24.04 LTS
cockpit Needs evaluation
Show less packages

CVE-2026-89238

Medium priority
Needs evaluation

WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass. Users are recommended to upgrade to...

1 affected package

wss4j

Package 24.04 LTS
wss4j Needs evaluation
Show less packages

CVE-2026-88920

Medium priority
Needs evaluation

An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge authenticated SOAP messages via a crafted unsigned SAML sender-vouches assertion containing...

1 affected package

wss4j

Package 24.04 LTS
wss4j Needs evaluation
Show less packages

CVE-2026-87830

Medium priority
Needs evaluation

In the StAX streaming WS-SecurityPolicy validator, certain relative or unsupported XPath expressions can be converted into paths that never match the actual XML element path. A remote SOAP peer may therefore send a required...

1 affected package

wss4j

Package 24.04 LTS
wss4j Needs evaluation
Show less packages