Search CVE reports


Toggle filters

221 – 230 of 44612 results

Status is adjusted based on your filters.


CVE-2026-59090

Medium priority
Needs evaluation

A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user opens a specially crafted `.psd` image file. The underflow leads to...

1 affected package

gimp

Package 20.04 LTS
gimp Needs evaluation
Show less packages

CVE-2026-18370

Medium priority
Needs evaluation

entr is vulnerable to Heap-based buffer overflow in run_utility() function. The function allocates a fixed-size heap buffer using malloc(ARG_MAX) and copies command-line arguments into it. It advances the destination pointer based...

1 affected package

entr

Package 20.04 LTS
entr Needs evaluation
Show less packages

CVE-2026-59088

Medium priority
Needs evaluation

A flaw was found in GIMP. A signed integer overflow vulnerability exists in the `file-fli` plugin when processing FLI image files. This occurs due to an incorrect calculation during memory allocation for image buffers, where the...

1 affected package

gimp

Package 20.04 LTS
gimp Needs evaluation
Show less packages

CVE-2026-59087

Medium priority
Needs evaluation

A flaw was found in the GIMP image manipulation program, specifically within its Seattle Filmworks file loader. A remote attacker could exploit this vulnerability by tricking a user into opening a specially crafted Seattle...

1 affected package

gimp

Package 20.04 LTS
gimp Needs evaluation
Show less packages

CVE-2026-19404

Medium priority
Needs evaluation

A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operations perform no authorization check, allowing an unauthenticated remote attacker to invoke them when...

1 affected package

389-ds-base

Package 20.04 LTS
389-ds-base Needs evaluation
Show less packages

CVE-2026-12570

Medium priority
Needs evaluation

A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model files via the keras.models.load_model() function. The H5IOStore.__getitem__ method...

1 affected package

keras

Package 20.04 LTS
keras Needs evaluation
Show less packages

CVE-2026-19389

Medium priority
Needs evaluation

Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation...

1 affected package

gst-plugins-ugly1.0

Package 20.04 LTS
gst-plugins-ugly1.0 Needs evaluation
Show less packages

CVE-2026-19387

Medium priority
Needs evaluation

A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a...

1 affected package

gst-plugins-bad1.0

Package 20.04 LTS
gst-plugins-bad1.0 Needs evaluation
Show less packages

CVE-2026-16742

Medium priority
Not affected

systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user

1 affected package

systemd

Package 20.04 LTS
systemd Not affected
Show less packages

CVE-2026-15060

Medium priority
Not affected

When systemd-machined >= v259 (or v258 with a custom `polkit` policy that allows `register-machine` access) is running on a desktop system, an unprivileged user logged in a desktop graphical session can kill arbitrary processes,...

1 affected package

systemd

Package 20.04 LTS
systemd Not affected
Show less packages