Search CVE reports


Toggle filters

3161 – 3170 of 49928 results

Status is adjusted based on your filters.


CVE-2026-21925

Medium priority

Some fixes available 1 of 2

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: RMI). Supported versions that are affected are Oracle Java SE: 8u471, 8u471-b50, 8u471-perf,...

12 affected packages

openjdk-8, openjdk-9, openjdk-lts, openjdk-13, openjdk-16...

Package 16.04 LTS
openjdk-8 Fixed
openjdk-9 Ignored
openjdk-lts
openjdk-13
openjdk-16
openjdk-17
openjdk-17-crac
openjdk-18
openjdk-21
openjdk-21-crac
openjdk-25
openjdk-25-crac
Show all 12 packages Show less packages

CVE-2026-0865

Medium priority
Fixed

User-controlled header names and values containing newlines can allow injecting HTTP headers.

12 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7...

Package 16.04 LTS
python2.7 Fixed
python3.4
python3.5 Fixed
python3.6
python3.7
python3.8
python3.9
python3.10
python3.11
python3.12
python3.13
python3.14
Show all 12 packages Show less packages

CVE-2026-0672

Medium priority
Fixed

When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control characters within cookie names, values, and parameters.

12 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7...

Package 16.04 LTS
python2.7 Fixed
python3.4
python3.5 Fixed
python3.6
python3.7
python3.8
python3.9
python3.10
python3.11
python3.12
python3.13
python3.14
Show all 12 packages Show less packages

CVE-2025-15367

Medium priority
Ignored

The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.

12 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7...

Package 16.04 LTS
python2.7 Ignored
python3.4
python3.5 Ignored
python3.6
python3.7
python3.8
python3.9
python3.10
python3.11
python3.12
python3.13
python3.14
Show all 12 packages Show less packages

CVE-2025-15366

Medium priority
Ignored

The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.

12 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7...

Package 16.04 LTS
python2.7 Ignored
python3.4
python3.5 Ignored
python3.6
python3.7
python3.8
python3.9
python3.10
python3.11
python3.12
python3.13
python3.14
Show all 12 packages Show less packages

CVE-2025-15282

Medium priority
Fixed

User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL mediatype.

12 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7...

Package 16.04 LTS
python2.7 Fixed
python3.4
python3.5 Fixed
python3.6
python3.7
python3.8
python3.9
python3.10
python3.11
python3.12
python3.13
python3.14
Show all 12 packages Show less packages

CVE-2025-11468

Medium priority
Not affected

When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled...

12 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7...

Package 16.04 LTS
python2.7 Not affected
python3.4
python3.5 Not affected
python3.6
python3.7
python3.8
python3.9
python3.10
python3.11
python3.12
python3.13
python3.14
Show all 12 packages Show less packages

CVE-2026-21637

Medium priority
Needs evaluation

A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCallback` or `ALPNCallback` are in use. Synchronous exceptions thrown during these callbacks bypass standard TLS...

1 affected package

nodejs

Package 16.04 LTS
nodejs Needs evaluation
Show less packages

CVE-2026-21636

Medium priority
Needs evaluation

A flaw in Node.js's permission model allows Unix Domain Socket (UDS) connections to bypass network restrictions when `--permission` is enabled. Even without `--allow-net`, attacker-controlled inputs (such as URLs or socketPath...

1 affected package

nodejs

Package 16.04 LTS
nodejs Needs evaluation
Show less packages

CVE-2025-59466

Medium priority
Needs evaluation

We have identified a bug in Node.js error handling where "Maximum call stack size exceeded" errors become uncatchable when `async_hooks.createHook()` is enabled. Instead of reaching `process.on('uncaughtException')`, the process...

1 affected package

nodejs

Package 16.04 LTS
nodejs Needs evaluation
Show less packages