Search CVE reports


Toggle filters

261 – 270 of 39027 results

Status is adjusted based on your filters.


CVE-2026-61721

Medium priority
Needs evaluation

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS loader assigns file-controlled wsmp.loop_start and wsmp.loop_length values to samples without calling...

1 affected package

fluidsynth

Package 26.04 LTS
fluidsynth Needs evaluation
Show less packages

CVE-2026-61720

Medium priority
Needs evaluation

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the SF2 parser computes the DMOD modulator count as chunk.size / SF_MOD_SIZE - 1 without rejecting chunks smaller than one...

1 affected package

fluidsynth

Package 26.04 LTS
fluidsynth Needs evaluation
Show less packages

CVE-2026-61714

Medium priority
Needs evaluation

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.2.4 until 2.5.6, configuring synth.midi-channels above 16 allows the MIDI player to index _fluid_player_t::channel_isplaying outside its...

1 affected package

fluidsynth

Package 26.04 LTS
fluidsynth Needs evaluation
Show less packages

CVE-2026-58264

Medium priority
Needs evaluation

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 1.1.2 until 2.5.6, the FluidSynth command handler accepts a pitch_bend_range command whose channel argument is not bounds checked before the...

1 affected package

fluidsynth

Package 26.04 LTS
fluidsynth Needs evaluation
Show less packages

CVE-2026-57226

Medium priority
Needs evaluation

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, HTTP SWF decompression with the non-default swf-decompression feature and an unsafe...

1 affected package

suricata

Package 26.04 LTS
suricata Needs evaluation
Show less packages

CVE-2026-57224

Medium priority
Needs evaluation

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the DHCP parser in rust/src/dhcp/dhcp.rs creates stateless transactions...

1 affected package

suricata

Package 26.04 LTS
suricata Needs evaluation
Show less packages

CVE-2026-57222

Medium priority
Needs evaluation

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, crafted IPv4 and IPv6 address pairs can collide in the IPPair hash...

1 affected package

suricata

Package 26.04 LTS
suricata Needs evaluation
Show less packages

CVE-2026-93854

Medium priority
Needs evaluation

In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce object-level authorization on its update and delete operations (PUT /v2/leases/{lease_id} and DELETE /v2/leases/{lease_id}). The policy authorize() wrapper...

1 affected package

blazar

Package 26.04 LTS
blazar Needs evaluation
Show less packages

CVE-2026-93852

Medium priority
Needs evaluation

In OpenStack Blazar before 17.0.1, the V2 lease listing operation (GET /v2/leases) returns leases for every project without enforcing project scoping or an administrator-only policy. Any authenticated user with access to the...

1 affected package

blazar

Package 26.04 LTS
blazar Needs evaluation
Show less packages

CVE-2026-75894

Medium priority
Needs evaluation

In osmo-iuh from 0.1.0 through 1.8.0 a reachable assertion was found in the ranap_handle_co_dt() function via a arbitrarily sized NAS-PDU that leads to process crash and remote denial of service.

1 affected package

osmo-iuh

Package 26.04 LTS
osmo-iuh Needs evaluation
Show less packages