Search CVE reports


Toggle filters

31 – 40 of 42201 results

Status is adjusted based on your filters.


CVE-2019-25544

Medium priority
Needs evaluation

Pidgin 2.13.0 contains a denial of service vulnerability that allows local attackers to crash the application by providing an excessively long username string during account creation. Attackers can input a buffer of 1000...

1 affected package

pidgin

Package 18.04 LTS
pidgin Needs evaluation
Show less packages

CVE-2026-33236

Medium priority
Needs evaluation

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, the NLTK downloader does not...

1 affected package

nltk

Package 18.04 LTS
nltk Needs evaluation
Show less packages

CVE-2026-33231

Medium priority
Needs evaluation

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, `nltk.app.wordnet_app` allows...

1 affected package

nltk

Package 18.04 LTS
nltk Needs evaluation
Show less packages

CVE-2026-33230

Medium priority
Needs evaluation

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, `nltk.app.wordnet_app` contains a...

1 affected package

nltk

Package 18.04 LTS
nltk Needs evaluation
Show less packages

CVE-2026-33210

Medium priority
Needs evaluation

Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the...

1 affected package

ruby-json

Package 18.04 LTS
ruby-json Needs evaluation
Show less packages

CVE-2026-33186

High priority
Needs evaluation

gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in...

2 affected packages

golang-google-grpc, google-guest-agent

Package 18.04 LTS
golang-google-grpc Needs evaluation
google-guest-agent Needs evaluation
Show less packages

CVE-2026-33179

Medium priority
Needs evaluation

libfuse is the reference implementation of the Linux FUSE. From version 3.18.0 to before version 3.18.2, a NULL pointer dereference and memory leak in fuse_uring_init_queue allows a local user to crash the FUSE daemon or cause...

2 affected packages

fuse, fuse3

Package 18.04 LTS
fuse Needs evaluation
fuse3
Show less packages

CVE-2026-33165

Medium priority
Needs evaluation

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a crafted HEVC bitstream causes an out-of-bounds heap write confirmed by AddressSanitizer. The trigger is a stale ctb_info.log2unitSize...

1 affected package

libde265

Package 18.04 LTS
libde265 Needs evaluation
Show less packages

CVE-2026-33164

Medium priority
Needs evaluation

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a malformed H.265 PPS NAL unit causes a segmentation fault in pic_parameter_set::set_derived_values(). This issue has been patched in...

1 affected package

libde265

Package 18.04 LTS
libde265 Needs evaluation
Show less packages

CVE-2026-33150

Medium priority
Needs evaluation

libfuse is the reference implementation of the Linux FUSE. From version 3.18.0 to before version 3.18.2, a use-after-free vulnerability in the io_uring subsystem of libfuse allows a local attacker to crash FUSE filesystem...

2 affected packages

fuse, fuse3

Package 18.04 LTS
fuse Needs evaluation
fuse3
Show less packages