Search CVE reports


Toggle filters

831 – 840 of 50365 results

Status is adjusted based on your filters.


CVE-2026-97059

Medium priority
Needs evaluation

DCMTK through 3.7.0 contains a heap over-read vulnerability in ConcatenationLoader that copies pixel data frames without validating the PixelData buffer length against the declared NumberOfFrames. Attackers can craft malicious...

1 affected package

dcmtk

Package 20.04 LTS
dcmtk Needs evaluation
Show less packages

CVE-2026-97058

Medium priority
Needs evaluation

sprintf-js through 1.1.3 passes unbounded precision specifiers to toFixed, toExponential, and toPrecision methods without validation, causing uncaught RangeError exceptions. Attackers who control format strings can...

1 affected package

node-sprintf-js

Package 20.04 LTS
node-sprintf-js Needs evaluation
Show less packages

CVE-2026-96749

Medium priority
Needs evaluation

An integer overflow in the BSON document encoding component of the MongoDB Python Driver's bundled native extension may occur when a single document is built from an unusually large amount of caller-supplied data. Size arithmetic...

1 affected package

pymongo

Package 20.04 LTS
pymongo Needs evaluation
Show less packages

CVE-2026-96748

Medium priority
Needs evaluation

PyMongo's connection string parsing decodes percent-encoded characters in the host portion before the host list is separated on its delimiters. When an application places a hostname value supplied by an unauthenticated party into...

1 affected package

pymongo

Package 20.04 LTS
pymongo Needs evaluation
Show less packages

CVE-2026-96747

Medium priority
Needs evaluation

The client-side field level encryption support in the MongoDB Python Driver can treat a key management endpoint value ending in ".sock" as a local Unix domain socket path rather than a remote host. A user with write access to the...

1 affected package

pymongo

Package 20.04 LTS
pymongo Needs evaluation
Show less packages

CVE-2026-96746

Medium priority
Needs evaluation

An out-of-bounds write in the connection-monitoring logic of the MongoDB C Driver may allow an unauthenticated party who controls name resolution and the responses of the hosts named in a client's connection string to write beyond...

1 affected package

pymongo

Package 20.04 LTS
pymongo Needs evaluation
Show less packages

CVE-2026-96745

Medium priority
Needs evaluation

Deserialization of untrusted data in the command monitoring support of the MongoDB PHP Driver can cause class names embedded in document content to be honored when the driver builds monitoring event objects. When an application...

1 affected package

pymongo

Package 20.04 LTS
pymongo Needs evaluation
Show less packages

CVE-2026-95521

Medium priority
Needs evaluation

A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames contain a %() macro construct causes rpm to execute an attacker-controlled shell command via popen() while...

1 affected package

rpm

Package 20.04 LTS
rpm Needs evaluation
Show less packages

CVE-2026-95519

Medium priority
Needs evaluation

A flaw was found in rpm. An attacker can supply a crafted manifest file that, when processed by a user or automation using `rpm -q -p` or similar manifest-processing flows, leads to arbitrary code execution. This occurs because...

1 affected package

rpm

Package 20.04 LTS
rpm Needs evaluation
Show less packages

CVE-2026-94281

Medium priority
Needs evaluation

An out-of-bounds read in libXi's XListInputDevices() class parsing in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.

1 affected package

libxi

Package 20.04 LTS
libxi Needs evaluation
Show less packages