Search CVE reports


Toggle filters

11 – 20 of 33763 results

Status is adjusted based on your filters.


CVE-2026-4150

Medium priority
Needs evaluation

GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this...

1 affected package

gimp

Package 24.04 LTS
gimp Needs evaluation
Show less packages

CVE-2026-40396

Medium priority
Needs evaluation

Varnish Cache 9 before 9.0.1 allows a "workspace overflow" denial of service (daemon panic) after timeout_linger. A malicious client could send an HTTP/1 request, wait long enough until the session releases its worker thread...

1 affected package

varnish

Package 24.04 LTS
varnish Needs evaluation
Show less packages

CVE-2026-40395

Medium priority
Needs evaluation

Varnish Enterprise before 6.0.16r12 allows a "workspace overflow" denial of service (daemon panic) for shared VCL. The headerplus.write_req0() function from vmod_headerplus updates the underlying req0, which is normally...

1 affected package

varnish

Package 24.04 LTS
varnish Needs evaluation
Show less packages

CVE-2026-40394

Medium priority
Needs evaluation

Varnish Cache 9 before 9.0.1 and Varnish Enterprise before 6.0.16r11 allows a "workspace overflow" denial of service (daemon panic) for certain amounts of prefetched data. The setup of an HTTP/2 session starts with a speculative...

1 affected package

varnish

Package 24.04 LTS
varnish Needs evaluation
Show less packages

CVE-2026-40393

Medium priority
Needs evaluation

In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then used for alloca.

1 affected package

mesa

Package 24.04 LTS
mesa Needs evaluation
Show less packages

CVE-2026-40386

Medium priority
Needs evaluation

In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.

1 affected package

libexif

Package 24.04 LTS
libexif Needs evaluation
Show less packages

CVE-2026-40385

Medium priority
Needs evaluation

In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. This only affects 32bit systems.

1 affected package

libexif

Package 24.04 LTS
libexif Needs evaluation
Show less packages

CVE-2026-40354

Medium priority
Needs evaluation

Flatpak xdg-desktop-portal before 1.20.4 and 1.21.x before 1.21.1 allows any Flatpak app to trash any file in the host context via a symlink attack on g_file_trash.

1 affected package

xdg-desktop-portal

Package 24.04 LTS
xdg-desktop-portal Needs evaluation
Show less packages

CVE-2026-40228

Medium priority
Needs evaluation

In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p emerg" command is executed, if ForwardToWall=yes is set.

1 affected package

systemd

Package 24.04 LTS
systemd Needs evaluation
Show less packages

CVE-2026-40227

Medium priority
Needs evaluation

In systemd 260 before 261, a local unprivileged user can trigger an assert via an IPC API call with an array or map that has a null element.

1 affected package

systemd

Package 24.04 LTS
systemd Needs evaluation
Show less packages