Search CVE reports
251 – 260 of 40452 results
An attacker could cause a heap buffer overflow by getting a user to open an email that is greater than or equal to 2GB in size. This vulnerability was fixed in Thunderbird 157, Thunderbird 140.17, and Thunderbird 153.4.
1 affected package
thunderbird
| Package | 26.04 LTS |
|---|---|
| thunderbird | Needs evaluation |
IVFFlat index build in pgvector before 0.8.7 allows a database user to write data out-of-bounds, which can lead to arbitrary code execution.
1 affected package
pgvector
| Package | 26.04 LTS |
|---|---|
| pgvector | Needs evaluation |
apcupsd through 3.14.14 discloses uninitialized stack memory in getupsvar() in src/cgi/upsfetch.c (used by upsstats.cgi, multimon.cgi, and upsfstats.cgi. On the single-field path, when the matched STATUS line has fewer than three...
1 affected package
apcupsd
| Package | 26.04 LTS |
|---|---|
| apcupsd | Needs evaluation |
apcupsd through 3.14.14 has an sscanf stack-based buffer overflow in getupsvar() in src/cgi/upsfetch.c (used by upsstats.cgi, multimon.cgi, and upsfstats.cgi), a related issue to CVE-2026-15544.
1 affected package
apcupsd
| Package | 26.04 LTS |
|---|---|
| apcupsd | Needs evaluation |
colmux in collectl before 4.3.20.2 does not sanitize ANSI/VT100 terminal escape sequences in data received from remote collectl instances before displaying it, allowing a local user on a monitored host to inject escape sequences...
1 affected package
collectl
| Package | 26.04 LTS |
|---|---|
| collectl | Needs evaluation |
A flaw was found in SoupServer (libsoup). When an HTTP/1.x client sends a request with Expect: 100-continue and a request body, and SoupServer returns an early final (non-1xx) response before the body is read, the server neither...
2 affected packages
libsoup2.4, libsoup3
| Package | 26.04 LTS |
|---|---|
| libsoup2.4 | Needs evaluation |
| libsoup3 | Needs evaluation |
A weakness has been identified in garycourt uri-js up to 4.4.1. This affects the function URI.parse of the file src/schemes/mailto.ts of the component Mailto Header Handler. This manipulation of the argument to causes uncaught...
1 affected package
node-uri-js
| Package | 26.04 LTS |
|---|---|
| node-uri-js | Needs evaluation |
Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within it. When a symlink pointing outside the...
1 affected package
python-tornado
| Package | 26.04 LTS |
|---|---|
| python-tornado | Needs evaluation |
Tornado versions before 6.5.9 contain an unbounded memory accumulation vulnerability in CurlAsyncHTTPClient that allows remote attackers to cause denial of service by sending a compressed response. Attackers can send...
1 affected package
python-tornado
| Package | 26.04 LTS |
|---|---|
| python-tornado | Needs evaluation |
Tornado before 6.5.9 fails to limit the number of query string fields in HTTPServerRequest.__init__, allowing remote attackers to cause event-loop stalling by sending requests with thousands of query parameters. Attackers can send...
1 affected package
python-tornado
| Package | 26.04 LTS |
|---|---|
| python-tornado | Needs evaluation |