Search CVE reports


Toggle filters

1881 – 1890 of 43789 results

Status is adjusted based on your filters.


CVE-2026-17583

Medium priority
Needs evaluation

The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files can be edited. An attacker could tamper with these files, altering DNA data and resulting in inaccurate DNA test outcomes.

1 affected package

genetic

Package 24.04 LTS
genetic Needs evaluation
Show less packages

CVE-2026-44605

Medium priority
Needs evaluation

A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vulnerability when processing a specially crafted NDB database file. This issue arises from an error in how RPM handles...

1 affected package

rpm

Package 24.04 LTS
rpm Needs evaluation
Show less packages

CVE-2026-14587

Medium priority
Needs evaluation

Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask. When an unauthenticated client sends a selected protocol version followed by 32 continuation bytes in the...

1 affected package

bolt

Package 24.04 LTS
bolt Needs evaluation
Show less packages

CVE-2026-71287

Medium priority
Needs evaluation

Cacti's sanitize_sql_column (lib/functions.php) sanitizes user-supplied ORDER BY column names using the regex . Because this allowlist retains letters, digits, underscore, parentheses, and dot (intended to support expressions like...

1 affected package

cacti

Package 24.04 LTS
cacti Needs evaluation
Show less packages

CVE-2026-71266

Medium priority
Needs evaluation

tinyobjloader-c's tinyobj_parse_and_index_mtl_file (tinyobj_loader_c.h) reads each line of a .mtl material file into a fixed 4096-byte stack buffer via memcpy(linebuf, p, p_len), guarded only by . The identical vulnerable pattern...

2 affected packages

goxel, raylib

Package 24.04 LTS
goxel Needs evaluation
raylib Not in release
Show less packages

CVE-2026-71261

Medium priority
Needs evaluation

dr_libs dr_wav.h (all versions through current master) contains an integer overflow in W64 CUE chunk metadata parsing. In drwav__metadata_process_chunk, a stage-1 capacity estimate truncates the 64-bit W64 chunk sizeInBytes to...

3 affected packages

libchdr, qt6-multimedia, qtads

Package 24.04 LTS
libchdr Needs evaluation
qt6-multimedia Needs evaluation
qtads Needs evaluation
Show less packages

CVE-2026-71227

Medium priority
Needs evaluation

A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all()...

1 affected package

libkcapi

Package 24.04 LTS
libkcapi Needs evaluation
Show less packages

CVE-2026-71226

Medium priority
Needs evaluation

Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all submitted IOCBs are drained, allowing later kernel writes into caller-owned output buffers.

1 affected package

libkcapi

Package 24.04 LTS
libkcapi Needs evaluation
Show less packages

CVE-2026-71225

Medium priority
Needs evaluation

A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stateful modes such as Counter (CTR) or Cipher Block Chaining (CBC), the library improperly reuses...

1 affected package

libkcapi

Package 24.04 LTS
libkcapi Needs evaluation
Show less packages

CVE-2026-71212

Medium priority
Needs evaluation

xidown (a yt-dlp/ffmpeg GUI wrapper) builds its yt-dlp command-line invocation (xidown/core/scanner.py and downloader.py) by appending the user-provided or scanned URL as a bare trailing positional argument, with no '--'...

4 affected packages

ffmpeg, libav, its, yt-dlp

Package 24.04 LTS
ffmpeg Needs evaluation
libav Not in release
its Not in release
yt-dlp Needs evaluation
Show less packages