Search CVE reports


Toggle filters

71 – 80 of 50631 results

Status is adjusted based on your filters.


CVE-2026-19954

Medium priority
Needs evaluation

(Net::Whois::Raw versions before 2.99044 for Perl ship a pwhois command ...)

1 affected package

libnet-whois-raw-perl

Package 20.04 LTS
libnet-whois-raw-perl Needs evaluation
Show less packages

CVE-2026-18040

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.86, HQC leaked secret-derived data through two side channels: its GF(2^8) arithmetic used lookup tables indexed by field elements, making the cache line touched a function of the operand, and its...

1 affected package

bouncycastle

Package 20.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-18036

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.86, NTRU reduced secret values with the % operator in three helpers whose reference implementations are deliberately division-free, so each reduction was carried out by an integer division whose...

1 affected package

bouncycastle

Package 20.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-17508

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.86, several password-based key derivation entry points ran the KDF with cost parameters taken from the untrusted input being processed, without bounding them, so a small input could dictate an...

1 affected package

bouncycastle

Package 20.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-17507

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.86, the MLS implementation (org.bouncycastle.mls) holds RFC 9420's uint32 leaf_index in a signed int, so a wire value with the top bit set decodes to a negative number. That is a legitimate...

1 affected package

bouncycastle

Package 20.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-15109

Medium priority
Ignored

security update

6 affected packages

chromium-browser, webkitgtk, webkit2gtk, qtwebkit-source, qtwebkit-opensource-src, wpewebkit

Package 20.04 LTS
chromium-browser —
webkitgtk —
webkit2gtk Ignored
qtwebkit-source —
qtwebkit-opensource-src Ignored
wpewebkit Ignored
Show less packages

CVE-2026-105221

Medium priority
Needs evaluation

(The gist RubyGem before 6.1.0 contains an improper certificate validat ...)

1 affected package

gist

Package 20.04 LTS
gist Needs evaluation
Show less packages

CVE-2026-105083

Medium priority
Needs evaluation

ImageMagick before 7.1.2-32 and 6.9.13-57 contains a policy bypass vulnerability in LoadPolicyCache that silently skips security policy rules when policy.xml uses an alternate DOCTYPE. A valid DOCTYPE not ending in ']>' makes the...

1 affected package

imagemagick

Package 20.04 LTS
imagemagick Needs evaluation
Show less packages

CVE-2026-104988

Medium priority
Needs evaluation

A flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST authentication plugin fails open when an EST fullcmc enrollment request is submitted via BasicAuth without an end-user TLS client certificate. The...

1 affected package

dogtag-pki

Package 20.04 LTS
dogtag-pki Needs evaluation
Show less packages

CVE-2026-104874

Medium priority
Needs evaluation

Multidict is an implementation of a multidict data structure. From 6.7.0 until 6.9.1, the C extension's items-view reflected union operation, operand | d.items(), in multidict_itemsview_or2_impl and subtraction operation,...

1 affected package

python-multidict

Package 20.04 LTS
python-multidict Needs evaluation
Show less packages