Search CVE reports


Toggle filters

1001 – 1010 of 48458 results

Status is adjusted based on your filters.


CVE-2026-77159

Medium priority
Needs evaluation

A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost() function. The function uses a path-based chown() on the swtpm logfile without checking for symbolic links. A local attacker with access to the swtpm...

2 affected packages

libvirt, libvirt-hwe

Package 20.04 LTS
libvirt Needs evaluation
libvirt-hwe
Show less packages

CVE-2026-87908

Medium priority
Needs evaluation

multiparty is a Node.js library for parsing multipart/form-data request bodies. In versions from 2.1.0 up to but not including 4.3.1, the parser does not bound the amount of memory used while accumulating the headers of a single...

1 affected package

node-multiparty

Package 20.04 LTS
node-multiparty Needs evaluation
Show less packages

CVE-2026-89169

Medium priority
Needs evaluation

live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .verity file is missing.

1 affected package

live-boot

Package 20.04 LTS
live-boot Needs evaluation
Show less packages

CVE-2026-89162

Medium priority
Needs evaluation

In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe.

1 affected package

pcre2

Package 20.04 LTS
pcre2 Needs evaluation
Show less packages

CVE-2026-89161

Medium priority
Needs evaluation

In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur.

1 affected package

pcre2

Package 20.04 LTS
pcre2 Needs evaluation
Show less packages

CVE-2026-89160

Medium priority
Needs evaluation

PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject.

1 affected package

pcre2

Package 20.04 LTS
pcre2 Needs evaluation
Show less packages

CVE-2026-89158

Medium priority
Needs evaluation

PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write.

1 affected package

pcre2

Package 20.04 LTS
pcre2 Needs evaluation
Show less packages

CVE-2026-89157

Medium priority
Needs evaluation

PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern.

1 affected package

pcre2

Package 20.04 LTS
pcre2 Needs evaluation
Show less packages

CVE-2026-89156

Medium priority
Needs evaluation

PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data.

1 affected package

pcre2

Package 20.04 LTS
pcre2 Needs evaluation
Show less packages

CVE-2026-89092

Medium priority
Needs evaluation

The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack overflow when a malicious DNS server returns too large a response for a DNS query, resulting in degraded DNS resolution for the system. Exploitation of...

2 affected packages

glibc, eglibc

Package 20.04 LTS
glibc Needs evaluation
eglibc
Show less packages