Search CVE reports


Toggle filters

71 – 80 of 32112 results

Status is adjusted based on your filters.


CVE-2026-66759

Medium priority
Needs evaluation

A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the plugin reads from the mask data buffer without verifying if the cursor exceeds the allocated resource size. If a...

1 affected package

gimp

Package 26.04 LTS
gimp Needs evaluation
Show less packages

CVE-2026-66758

Medium priority
Needs evaluation

A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation sizes using signed 32-bit integers for width and height. If a crafted file sets both values to large...

1 affected package

gimp

Package 26.04 LTS
gimp Needs evaluation
Show less packages

CVE-2026-66757

Medium priority
Needs evaluation

A flaw was found in the file-sgi plugin in GIMP. When processing an RLE-compressed SGI image, the plugin allocates memory for a row table. The image header dimensions (ysize and zsize) are read as 16-bit unsigned integers. If a...

1 affected package

gimp

Package 26.04 LTS
gimp Needs evaluation
Show less packages

CVE-2026-54272

Medium priority
Needs evaluation

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Versions 10.1.1 through 10.2.0 are vulnerable to SSRF through misclassification of IPv4-mapped/NAT64 IPv6 addresses. Address6.getType()...

1 affected package

node-ip-address

Package 26.04 LTS
node-ip-address Needs evaluation
Show less packages

CVE-2026-45623

Medium priority
Needs evaluation

PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. In versions 8.5.11 and prior, the PreviousMap parses the /*# sourceMappingURL=PATH */ comment...

1 affected package

node-postcss

Package 26.04 LTS
node-postcss Needs evaluation
Show less packages

CVE-2026-59251

Medium priority
Needs evaluation

Allocation of resources without limits in Erlang/OTP public_key certificate path validation allows a remote unauthenticated attacker to cause denial of service by sending a crafted X.509 certificate chain during the...

1 affected package

erlang

Package 26.04 LTS
erlang Needs evaluation
Show less packages

CVE-2026-59250

Medium priority
Needs evaluation

Classic buffer overflow in the Erlang/OTP megaco flex scanner C driver allows a remote unauthenticated attacker to corrupt the driver's memory (and potentially achieve remote code execution or a denial-of-service crash) by sending...

1 affected package

erlang

Package 26.04 LTS
erlang Needs evaluation
Show less packages

CVE-2026-58227

Medium priority
Needs evaluation

The Erlang/OTP ssl application does not detect cycles when reconstructing an incomplete peer certificate chain during a TLS or DTLS handshake. In ssl_certificate:handle_incomplete_chain/5, the received chain is passed...

1 affected package

erlang

Package 26.04 LTS
erlang Needs evaluation
Show less packages

CVE-2026-55953

Medium priority
Needs evaluation

The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does not verify that the cipher suite selected by the server in ServerHello was among the suites offered by the client in ClientHello. The client-side tls_handshake:hello/5...

1 affected package

erlang

Package 26.04 LTS
erlang Needs evaluation
Show less packages

CVE-2026-55737

Medium priority
Needs evaluation

Signed to Unsigned Conversion Error and Out-of-bounds Write vulnerability in Erlang OTP erts allows an attacker who can supply a crafted Erlang external term format (ETF) binary to binary_to_term/1 to corrupt the BEAM heap pointer...

1 affected package

erlang

Package 26.04 LTS
erlang Needs evaluation
Show less packages