Search CVE reports


Toggle filters

1531 – 1540 of 39027 results

Status is adjusted based on your filters.


CVE-2026-92005

Medium priority
Not affected

Use-after-free in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 26.04 LTS
firefox Not affected
thunderbird Not affected
mozjs38 Not in release
mozjs52 Not in release
mozjs68 Not in release
mozjs78 Not in release
mozjs91 Not in release
mozjs102 Not in release
mozjs115 Not in release
Show all 9 packages Show less packages

CVE-2026-91926

Medium priority
Needs evaluation

A flaw was found in gss-ntlmssp. A memory leak occurs in the NTLM target-info parser when a crafted NTLM CHALLENGE message contains duplicated string-valued AV_PAIR entries. The parser allocates memory for each string value but...

1 affected package

gss-ntlmssp

Package 26.04 LTS
gss-ntlmssp Needs evaluation
Show less packages

CVE-2026-62379

Medium priority

Not in release

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /authservice PLL endpoint accepts a CustomCallback XML element whose className value selects an arbitrary Java class for...

1 affected package

openam

Package 26.04 LTS
openam Not in release
Show less packages

CVE-2026-62280

Medium priority

Not in release

Open Access Management (OpenAM) is an access management solution. From 13.0.0 until 16.1.2, the OAuth2 authorize endpoint's display=wap consent page reflects request-derived values through ConsentRequiredResource...

1 affected package

openam

Package 26.04 LTS
openam Not in release
Show less packages

CVE-2026-62263

Medium priority

Not in release

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, WebAuthnAuthentication.deserialize applies an ObjectInputFilter that allows every serialized object at depth greater than 1 and...

1 affected package

openam

Package 26.04 LTS
openam Not in release
Show less packages

CVE-2026-53660

Medium priority

Not in release

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the default configuration initializes the iPlanetDirectoryPro SSO cookie with HttpOnly disabled and without a protective SameSite default, and...

1 affected package

openam

Package 26.04 LTS
openam Not in release
Show less packages

CVE-2026-48717

Medium priority

Not in release

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, AuthorizationCodeGrantTypeHandler requires a code_verifier only when the realm-wide codeVerifierEnforced setting is enabled, even when...

1 affected package

openam

Package 26.04 LTS
openam Not in release
Show less packages

CVE-2026-47426

Medium priority

Not in release

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the private_key_jwt client authentication path uses ClientJwksResolverCache without reliably binding a cached jwks_uri resolver and verified...

1 affected package

openam

Package 26.04 LTS
openam Not in release
Show less packages

CVE-2026-47424

Medium priority

Not in release

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, GroovySandboxValueFilter permits an authenticated server-side script author to escape the scripting sandbox despite the default class allow and...

1 affected package

openam

Package 26.04 LTS
openam Not in release
Show less packages

CVE-2026-46623

Medium priority

Not in release

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth2 authentication module updates an existing local account with profile attributes that can include userPassword and...

1 affected package

openam

Package 26.04 LTS
openam Not in release
Show less packages