Search CVE reports


Toggle filters

121 – 130 of 38851 results

Status is adjusted based on your filters.


CVE-2026-93311

Medium priority
Needs evaluation

A vulnerability was detected in Freedesktop Poppler 26.07.0. This issue affects the function SampledFunction::SampledFunction of the file poppler/Function.cc of the component SampledFunction. The manipulation of the argument...

1 affected package

poppler

Package 26.04 LTS
poppler Needs evaluation
Show less packages

CVE-2026-93019

Medium priority
Needs evaluation

Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read. The reader unpacks the two-byte colour map length into a signed short, so a length of 32768 or...

1 affected package

libimager-perl

Package 26.04 LTS
libimager-perl Needs evaluation
Show less packages

CVE-2026-93018

Medium priority
Needs evaluation

Imager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes past its colour map in i_gpix_p and i_glin_p. The palette is allocated uninitialised, and only the entries a...

1 affected package

libimager-perl

Package 26.04 LTS
libimager-perl Needs evaluation
Show less packages

CVE-2026-92768

Medium priority
Needs evaluation

A flaw was found in cockpit-machines. This vulnerability allows a local attacker to expose sensitive Virtual Machine (VM) credentials, including plaintext passwords, by inspecting process command-line arguments during VM creation...

1 affected package

cockpit-machines

Package 26.04 LTS
cockpit-machines Needs evaluation
Show less packages

CVE-2026-92747

Medium priority
Needs evaluation

A flaw was found in `cockpit-machines`. This vulnerability allows a local attacker with the ability to inspect running processes to expose sensitive guest virtual machine (VM) credentials, such as `rootPassword`...

1 affected package

cockpit-machines

Package 26.04 LTS
cockpit-machines Needs evaluation
Show less packages

CVE-2026-92745

Medium priority
Needs evaluation

A flaw was found in cockpit-machines. This vulnerability allows a local attacker with the ability to inspect process metadata to disclose a sensitive Red Hat Subscription Management (RHSM) offline token. The token is exposed when...

1 affected package

cockpit-machines

Package 26.04 LTS
cockpit-machines Needs evaluation
Show less packages

CVE-2026-92382

Medium priority
Needs evaluation

[usbredir: usbredir: unbounded iso_packet_desc[] index in usbredirhost_iso_packet() leads to heap out-of-bounds write]

1 affected package

usbredir

Package 26.04 LTS
usbredir Needs evaluation
Show less packages

CVE-2026-91205

Medium priority
Needs evaluation

A flaw was found in cockpit-files. A local unprivileged attacker can exploit a race condition during directory creation with owner assignment. By controlling a writable parent directory, the attacker can replace a newly created...

1 affected package

cockpit-files

Package 26.04 LTS
cockpit-files Needs evaluation
Show less packages

CVE-2026-91203

Medium priority
Needs evaluation

A flaw was found in cockpit-files. This vulnerability allows a local attacker to exploit a timing issue, known as a symlink race condition, during privileged file operations such as changing file ownership or permissions. By...

1 affected package

cockpit-files

Package 26.04 LTS
cockpit-files Needs evaluation
Show less packages

CVE-2026-91202

Medium priority
Needs evaluation

A flaw was found in cockpit-files. A low-privileged local user can exploit this vulnerability by crafting a directory containing a symbolic link (symlink) and then using the privileged "Paste as owner" function. This allows for...

1 affected package

cockpit-files

Package 26.04 LTS
cockpit-files Needs evaluation
Show less packages