Search CVE reports


Toggle filters

291 – 300 of 42559 results

Status is adjusted based on your filters.


CVE-2026-28871

Medium priority
Ignored

A logic issue was addressed with improved checks. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4. Visiting a maliciously crafted website may lead to a...

5 affected packages

webkitgtk, webkit2gtk, qtwebkit-source, qtwebkit-opensource-src, wpewebkit

Package 18.04 LTS
webkitgtk Ignored
webkit2gtk Ignored
qtwebkit-source Ignored
qtwebkit-opensource-src Ignored
wpewebkit
Show less packages

CVE-2026-28861

Medium priority
Ignored

A logic issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. A malicious website may be able to access...

5 affected packages

webkitgtk, webkit2gtk, qtwebkit-source, qtwebkit-opensource-src, wpewebkit

Package 18.04 LTS
webkitgtk Ignored
webkit2gtk Ignored
qtwebkit-source Ignored
qtwebkit-opensource-src Ignored
wpewebkit
Show less packages

CVE-2026-28859

Medium priority
Ignored

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. A malicious website may be able to process restricted...

5 affected packages

webkitgtk, webkit2gtk, qtwebkit-source, qtwebkit-opensource-src, wpewebkit

Package 18.04 LTS
webkitgtk Ignored
webkit2gtk Ignored
qtwebkit-source Ignored
qtwebkit-opensource-src Ignored
wpewebkit
Show less packages

CVE-2026-28857

Medium priority
Ignored

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Processing maliciously crafted web content may lead to an unexpected process crash.

5 affected packages

webkitgtk, webkit2gtk, qtwebkit-source, qtwebkit-opensource-src, wpewebkit

Package 18.04 LTS
webkitgtk Ignored
webkit2gtk Ignored
qtwebkit-source Ignored
qtwebkit-opensource-src Ignored
wpewebkit
Show less packages

CVE-2026-20691

Medium priority
Ignored

An authorization issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4, watchOS 26.4. A maliciously crafted webpage may be able...

5 affected packages

webkitgtk, webkit2gtk, qtwebkit-source, qtwebkit-opensource-src, wpewebkit

Package 18.04 LTS
webkitgtk Ignored
webkit2gtk Ignored
qtwebkit-source Ignored
qtwebkit-opensource-src Ignored
wpewebkit
Show less packages

CVE-2026-20665

Medium priority
Ignored

This issue was addressed through improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4....

5 affected packages

webkitgtk, webkit2gtk, qtwebkit-source, qtwebkit-opensource-src, wpewebkit

Package 18.04 LTS
webkitgtk Ignored
webkit2gtk Ignored
qtwebkit-source Ignored
qtwebkit-opensource-src Ignored
wpewebkit
Show less packages

CVE-2026-20664

Medium priority
Ignored

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Processing maliciously crafted web content may lead to an unexpected process crash.

5 affected packages

webkitgtk, webkit2gtk, qtwebkit-source, qtwebkit-opensource-src, wpewebkit

Package 18.04 LTS
webkitgtk Ignored
webkit2gtk Ignored
qtwebkit-source Ignored
qtwebkit-opensource-src Ignored
wpewebkit
Show less packages

CVE-2026-3608

Medium priority
Needs evaluation

Sending a maliciously crafted message to the kea-ctrl-agent, kea-dhcp-ddns, kea-dhcp4, or kea-dhcp6 daemons over any configured API socket or HA listener can cause the receiving daemon to exit with a stack overflow error. This...

1 affected package

isc-kea

Package 18.04 LTS
isc-kea Needs evaluation
Show less packages

CVE-2026-3591

Medium priority
Needs evaluation

A use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0). Using a specially-crafted DNS request, an attacker may be able to cause an ACL to improperly (mis)match an IP address. In...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 18.04 LTS
bind9 Not affected
isc-dhcp Needs evaluation
bind9-libs
Show less packages

CVE-2026-3119

Medium priority
Needs evaluation

Under certain conditions, `named` may crash when processing a correctly signed query containing a TKEY record. The affected code can only be reached if an incoming request has a valid transaction signature (TSIG) from a key...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 18.04 LTS
bind9 Not affected
isc-dhcp Needs evaluation
bind9-libs
Show less packages