Search CVE reports


Toggle filters

241 – 250 of 51437 results

Status is adjusted based on your filters.


CVE-2026-92240

Medium priority
Vulnerable

A malicious or compromised IMAP server can trigger an out-of-bounds read in the IMAP response parser by sending an untagged '* ID' response, crashing Thunderbird. The affected parsing path is reachable before authentication. This...

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 22.04 LTS
firefox Not affected
thunderbird Vulnerable
mozjs38 Not in release
mozjs52 Not in release
mozjs68 Not in release
mozjs78 Ignored
mozjs91 Ignored
mozjs102 Ignored
mozjs115 Not in release
Show all 9 packages Show less packages

CVE-2026-92239

Medium priority
Vulnerable

A maliciously constructed IMAP line could cause an out-of-bounds buffer read. This vulnerability was fixed in Thunderbird 156 and Thunderbird 140.16.

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 22.04 LTS
firefox Not affected
thunderbird Vulnerable
mozjs38 Not in release
mozjs52 Not in release
mozjs68 Not in release
mozjs78 Ignored
mozjs91 Ignored
mozjs102 Ignored
mozjs115 Not in release
Show all 9 packages Show less packages

CVE-2026-92238

Medium priority
Vulnerable

A maliciously constructed mail header could lead to multiple fields being parsed as one, or potential memory safety violations. This vulnerability was fixed in Thunderbird 156 and Thunderbird 140.16.

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 22.04 LTS
firefox Not affected
thunderbird Vulnerable
mozjs38 Not in release
mozjs52 Not in release
mozjs68 Not in release
mozjs78 Ignored
mozjs91 Ignored
mozjs102 Ignored
mozjs115 Not in release
Show all 9 packages Show less packages

CVE-2026-92091

Medium priority
Needs evaluation

A flaw was found in jwcrypto. The JWK.import_key() function validates the key_ops JWK member for duplicate values using an algorithm with O(n^2) time complexity, and the length of key_ops is not bounded. A remote, unauthenticated...

1 affected package

python-jwcrypto

Package 22.04 LTS
python-jwcrypto Needs evaluation
Show less packages

CVE-2026-91841

Medium priority
Needs evaluation

[Incomplete fix of CVE-2018-10900]

1 affected package

network-manager-vpnc

Package 22.04 LTS
network-manager-vpnc Needs evaluation
Show less packages

CVE-2026-91840

Medium priority
Needs evaluation

[username newline injection reaches a root password helper]

1 affected package

network-manager-vpnc

Package 22.04 LTS
network-manager-vpnc Needs evaluation
Show less packages

CVE-2026-91839

Medium priority
Needs evaluation

[credential newline injection permits local root code execution]

1 affected package

network-manager-fortisslvpn

Package 22.04 LTS
network-manager-fortisslvpn Needs evaluation
Show less packages

CVE-2026-91838

Medium priority
Needs evaluation

[profile data reaches root pppd pty shell]

1 affected package

network-manager-sstp

Package 22.04 LTS
network-manager-sstp Needs evaluation
Show less packages

CVE-2026-91837

Medium priority
Needs evaluation

[network-manager-iodine: Option confusion reaches iodine's pre-drop root shell]

1 affected package

network-manager-iodine

Package 22.04 LTS
network-manager-iodine Needs evaluation
Show less packages

CVE-2026-91749

Medium priority
Not affected

Use after free in Workers in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

1 affected package

chromium-browser

Package 22.04 LTS
chromium-browser Not affected
Show less packages