Search CVE reports


Toggle filters

1 – 10 of 50028 results

Status is adjusted based on your filters.


CVE-2026-42326

Medium priority
Needs evaluation

[Unknown description]

1 affected package

imagemagick

Package 16.04 LTS
imagemagick Needs evaluation
Show less packages

CVE-2026-47784

Medium priority
Needs evaluation

In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_userdb_checkpass.

1 affected package

memcached

Package 16.04 LTS
memcached Needs evaluation
Show less packages

CVE-2026-46529

Medium priority
Needs evaluation

[Unknown description]

4 affected packages

atril, evince, evince-gtk3, papers

Package 16.04 LTS
atril
evince Needs evaluation
evince-gtk3
papers
Show less packages

CVE-2026-44608

Medium priority
Needs evaluation

NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a locking inconsistency vulnerability that when certain conditions are met (multi-threaded, RPZ XFR reload, RPZ zone with 'rpz-nsip'/'rpz-nsdname' triggers) it could...

1 affected package

unbound

Package 16.04 LTS
unbound Needs evaluation
Show less packages

CVE-2026-44390

Medium priority
Needs evaluation

Unbounded name compression in certain cases causes degradation of service

1 affected package

unbound

Package 16.04 LTS
unbound Needs evaluation
Show less packages

CVE-2026-43620

Medium priority
Needs evaluation

Rsync versionĀ 3.4.2 and prior contain a receiver-side out-of-bounds array read vulnerability in recv_files() in receiver.c that allows a malicious rsync server to crash the rsync client process. Attackers can exploit...

1 affected package

rsync

Package 16.04 LTS
rsync Needs evaluation
Show less packages

CVE-2026-43619

Medium priority
Needs evaluation

Rsync versionĀ 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod, lchown, utimes, rename, unlink, mkdir, symlink, mknod, link, rmdir, and lstat that allow local attackers to...

1 affected package

rsync

Package 16.04 LTS
rsync Needs evaluation
Show less packages

CVE-2026-43618

High priority
Needs evaluation

The receiver's compressed-token decoder accumulated a 32-bit signed counter without overflow checking. A malicious sender can trigger an overflow that, with careful manipulation, leaks process memory contents to the attacker --...

1 affected package

rsync

Package 16.04 LTS
rsync Needs evaluation
Show less packages

CVE-2026-43617

Medium priority
Needs evaluation

Rsync versionĀ 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon's hostname-based access control list enforcement when configured with chroot. Attackers can bypass hostname-based deny rules...

1 affected package

rsync

Package 16.04 LTS
rsync Needs evaluation
Show less packages

CVE-2026-42960

Medium priority
Needs evaluation

NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section. Promiscuous RRSets that complement DNS replies in the authority section can be used to trick...

1 affected package

unbound

Package 16.04 LTS
unbound Needs evaluation
Show less packages