Search CVE reports


Toggle filters

291 – 300 of 33257 results

Status is adjusted based on your filters.


CVE-2026-20346

Medium priority
Needs evaluation

A vulnerability in the PDF file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This...

1 affected package

clamav

Package 26.04 LTS
clamav Needs evaluation
Show less packages

CVE-2026-20345

Medium priority
Needs evaluation

A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This...

1 affected package

clamav

Package 26.04 LTS
clamav Needs evaluation
Show less packages

CVE-2026-20339

Medium priority
Needs evaluation

A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an...

1 affected package

clamav

Package 26.04 LTS
clamav Needs evaluation
Show less packages

CVE-2026-20338

Medium priority
Needs evaluation

A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper memory handling when processing content in...

1 affected package

clamav

Package 26.04 LTS
clamav Needs evaluation
Show less packages

CVE-2026-20337

Medium priority
Needs evaluation

A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper boundary checks for content in zip files...

1 affected package

clamav

Package 26.04 LTS
clamav Needs evaluation
Show less packages

CVE-2026-62996

Medium priority
Needs evaluation

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. From 5.0.0 until 5.8.4, Smarty's stream: resource-name handling does not adequately restrict which PHP stream...

2 affected packages

smarty3, smarty4

Package 26.04 LTS
smarty3 Needs evaluation
smarty4 Needs evaluation
Show less packages

CVE-2026-62992

Medium priority
Needs evaluation

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to 5.8.2 (and 4.5.7 on the 4.x line), Security::_checkDir() does not fully resolve symbolic links before...

2 affected packages

smarty3, smarty4

Package 26.04 LTS
smarty3 Needs evaluation
smarty4 Needs evaluation
Show less packages

CVE-2026-18497

Medium priority
Needs evaluation

A heap-buffer-overflow vulnerability exists in the nothings stb TrueType library, up to version 1.26, that is used for parsing TrueType font files. The vulnerability exists in the stbtt__GetGlyphShapeTT() function within the...

1 affected package

libstb

Package 26.04 LTS
libstb Needs evaluation
Show less packages

CVE-2026-15816

Medium priority
Needs evaluation

A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the...

1 affected package

dracut

Package 26.04 LTS
dracut Needs evaluation
Show less packages

CVE-2026-71554

Medium priority
Needs evaluation

h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header blocks containing more than one Host header, and forward every Host header to the consuming application. Where...

1 affected package

python-h2

Package 26.04 LTS
python-h2 Needs evaluation
Show less packages