Search CVE reports


Toggle filters

371 – 380 of 41070 results

Status is adjusted based on your filters.


CVE-2026-65706

Medium priority
Needs evaluation

FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a crafted NV12 video frame with odd width dimensions. The...

2 affected packages

ffmpeg, libav

Package 24.04 LTS
ffmpeg Needs evaluation
libav Not in release
Show less packages

CVE-2026-65705

Medium priority
Needs evaluation

FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph...

2 affected packages

ffmpeg, libav

Package 24.04 LTS
ffmpeg Needs evaluation
libav Not in release
Show less packages

CVE-2026-65704

Medium priority
Needs evaluation

FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplying a crafted ffconcat file processed with the -safe 0 flag. The TY demuxer's demux_audio() function...

2 affected packages

ffmpeg, libav

Package 24.04 LTS
ffmpeg Needs evaluation
libav Not in release
Show less packages

CVE-2026-65703

Medium priority
Needs evaluation

FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying a crafted AVI file that changes frame dimensions across...

2 affected packages

ffmpeg, libav

Package 24.04 LTS
ffmpeg Needs evaluation
libav Not in release
Show less packages

CVE-2026-60122

Medium priority
Needs evaluation

gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the gpsprof utility that allows an attacker who controls GPS input data to execute arbitrary OS commands by injecting malicious...

1 affected package

gpsd

Package 24.04 LTS
gpsd Needs evaluation
Show less packages

CVE-2026-25800

Medium priority
Needs evaluation

Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Starting in version 0.1.0 and prior to version 0.11.15, the `Assembler` component that assembles unordered stream fragments...

1 affected package

rust-quinn-proto

Package 24.04 LTS
rust-quinn-proto Needs evaluation
Show less packages

CVE-2026-15687

Medium priority
Not affected

A security issue was discovered in the Kubernetes Java client library where a compromised pod may be able to create new files in arbitrary locations on the client machine executing copy operations via non-tar copyDirectoryFromPod...

1 affected package

kubernetes

Package 24.04 LTS
kubernetes Not affected
Show less packages

CVE-2026-65918

Medium priority

Not in release

PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the GIF decoder's read_from_tensor callback that passes unclamped length to memcpy. Attackers can supply malicious...

2 affected packages

pytorch, pytorch-vision

Package 24.04 LTS
pytorch Not in release
pytorch-vision Not in release
Show less packages

CVE-2026-16768

Medium priority
Needs evaluation

A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the defined palette range, an out-of-bounds read can occur due to improper bounds checking against the actual palette size....

1 affected package

gdk-pixbuf

Package 24.04 LTS
gdk-pixbuf Needs evaluation
Show less packages

CVE-2026-65914

Medium priority
Needs evaluation

DOMPurify before 3.3.2 contains a mutation-XSS vulnerability when sanitized HTML is reinserted into special parsing contexts using innerHTML with wrappers like script, xmp, iframe, noembed, noframes, or noscript. Attackers can...

1 affected package

node-dompurify

Package 24.04 LTS
node-dompurify Needs evaluation
Show less packages