Search CVE reports


Toggle filters

1201 – 1210 of 47099 results

Status is adjusted based on your filters.


CVE-2026-87822

Medium priority
Needs evaluation

t-digest versions 3.1 through 3.3 fail to validate centroid means during deserialization in MergingDigest.fromBytes, allowing attackers to inject NaN values that bypass validation checks. Attackers can craft malicious serialized...

1 affected package

t-digest

Package 24.04 LTS
t-digest Needs evaluation
Show less packages

CVE-2026-83530

Medium priority
Needs evaluation

A user could provide an expression whose string length is longer than the ParserExpressionSizeLimit() configured on the CEL environment, and a memory allocation would occur proportional to the size of the input before the limit...

1 affected package

golang-github-google-cel-go

Package 24.04 LTS
golang-github-google-cel-go Needs evaluation
Show less packages

CVE-2026-73324

Medium priority
Needs evaluation

Certain VLC media player builds in versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing media from an attacker-controlled network source. Exploitation requires user interaction and may...

1 affected package

vlc

Package 24.04 LTS
vlc Needs evaluation
Show less packages

CVE-2026-56711

Medium priority
Needs evaluation

VLC media player versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing crafted media. Exploitation requires user interaction and may result in application termination or code execution with...

1 affected package

vlc

Package 24.04 LTS
vlc Needs evaluation
Show less packages

CVE-2026-61915

Medium priority
Needs evaluation

An issue was discovered in Cyrus IMAP before 3.12.4. There is a VPATCH BYPARAM double-free. An authenticated calendar user could crash a Cyrus CalDAV worker with a PATCH containing PATCH-ACTION="BYPARAM@..." against a resource...

1 affected package

cyrus-imapd

Package 24.04 LTS
cyrus-imapd Needs evaluation
Show less packages

CVE-2026-61911

Medium priority
Needs evaluation

An issue was discovered in Cyrus IMAP before 3.12.4. There is a Sieve mailbox existence oracle. An authenticated user could install a Sieve script that probed whether another user's private mailbox existed, or read the value of...

1 affected package

cyrus-imapd

Package 24.04 LTS
cyrus-imapd Needs evaluation
Show less packages

CVE-2026-61910

Medium priority
Needs evaluation

An issue was discovered in Cyrus IMAP before 3.12.4. Mailbox/set let a sharee change a special-use role on shared mailboxes. An authenticated user with maySetKeywords on another user's mailbox could change that...

1 affected package

cyrus-imapd

Package 24.04 LTS
cyrus-imapd Needs evaluation
Show less packages

CVE-2026-61909

Medium priority
Needs evaluation

An issue was discovered in Cyrus IMAP before 3.12.4. CalDAV/CardDAV multiget bypasses a per-href ACL. An authenticated DAV user with some shared access to another user's calendar or address book could read even unshared events or...

1 affected package

cyrus-imapd

Package 24.04 LTS
cyrus-imapd Needs evaluation
Show less packages

CVE-2026-61908

Medium priority
Needs evaluation

An issue was discovered in Cyrus IMAP before 3.12.4. A JMAP email-header blob ID can reference an out-of-bounds index. An authenticated user could attempt to download a crafted JMAP blob ID of the form H<emailid>-<index>, which...

1 affected package

cyrus-imapd

Package 24.04 LTS
cyrus-imapd Needs evaluation
Show less packages

CVE-2026-61907

Medium priority
Needs evaluation

An issue was discovered in Cyrus IMAP before 3.12.4. JMAP snooze bypasses the destination-mailbox ACL. An authenticated user with insert permissions on another user's snoozed mailbox could cause insertion of mail to that user's...

1 affected package

cyrus-imapd

Package 24.04 LTS
cyrus-imapd Needs evaluation
Show less packages