Search CVE reports


Toggle filters

411 – 420 of 37797 results

Status is adjusted based on your filters.


CVE-2026-5314

Medium priority
Needs evaluation

A vulnerability was found in Nothings stb up to 1.26. Impacted is the function stbtt_InitFont_internal in the library stb_truetype.h of the component TTF File Handler. Performing a manipulation results in out-of-bounds read....

1 affected package

libstb

Package 22.04 LTS
libstb Needs evaluation
Show less packages

CVE-2026-5313

Medium priority
Needs evaluation

A vulnerability has been found in Nothings stb up to 2.30. This issue affects the function stbi__gif_load_next in the library stb_image.h of the component GIF Decoder. Such manipulation leads to denial of service. The attack may...

1 affected package

libstb

Package 22.04 LTS
libstb Needs evaluation
Show less packages

CVE-2026-34873

Medium priority
Needs evaluation

An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session.

1 affected package

mbedtls

Package 22.04 LTS
mbedtls Needs evaluation
Show less packages

CVE-2026-34545

Medium priority
Needs evaluation

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From version 3.4.0 to before version 3.4.7, an attacker providing a crafted .exr file...

1 affected package

openexr

Package 22.04 LTS
openexr Needs evaluation
Show less packages

CVE-2026-34544

Medium priority
Needs evaluation

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From version 3.4.0 to before version 3.4.8, a crafted B44 or B44A EXR file can cause...

1 affected package

openexr

Package 22.04 LTS
openexr Needs evaluation
Show less packages

CVE-2026-34543

Medium priority
Needs evaluation

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From version 3.4.0 to before version 3.4.8, sensitive information from heap memory...

1 affected package

openexr

Package 22.04 LTS
openexr Needs evaluation
Show less packages

CVE-2026-34531

Medium priority
Needs evaluation

Flask-HTTPAuth provides Basic, Digest and Token HTTP authentication for Flask routes. Prior to version 4.8.1, in a situation where the client makes a request to a token protected resource without passing a token, or passing an...

1 affected package

python-flask-httpauth

Package 22.04 LTS
python-flask-httpauth Needs evaluation
Show less packages

CVE-2026-34525

Medium priority
Needs evaluation

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, multiple Host headers were allowed in aiohttp. This issue has been patched in version 3.13.4.

1 affected package

python-aiohttp

Package 22.04 LTS
python-aiohttp Needs evaluation
Show less packages

CVE-2026-34520

Medium priority
Needs evaluation

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, the C parser (the default for most installs) accepted null bytes and control characters in response headers. This issue has...

1 affected package

python-aiohttp

Package 22.04 LTS
python-aiohttp Needs evaluation
Show less packages

CVE-2026-34519

Medium priority
Needs evaluation

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an attacker who controls the reason parameter when creating a Response may be able to inject extra headers or similar...

1 affected package

python-aiohttp

Package 22.04 LTS
python-aiohttp Needs evaluation
Show less packages