Search CVE reports


Toggle filters

221 – 230 of 59858 results

Status is adjusted based on your filters.


CVE-2026-102994

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to 6.18.0, a crafted PDF containing indirect-object identifiers or generation-number tokens that continue for a long time without whitespace can cause pypdf/_reader.py...

2 affected packages

pypdf, pypdf2

Package 16.04 LTS
pypdf —
pypdf2 Needs evaluation
Show less packages

CVE-2026-102993

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to 6.17.0, a crafted PDF can provide unusually large Roman page-label values that cause pypdf/_page_labels.py to generate excessively large numeral strings when...

2 affected packages

pypdf, pypdf2

Package 16.04 LTS
pypdf —
pypdf2 Needs evaluation
Show less packages

CVE-2026-102991

Medium priority
Needs evaluation

Mako is a template library written in Python. Prior to 1.4.2, on Windows, TemplateLookup.get_template() in mako/lookup.py resolves template URIs with posixpath, while Template.__init__() in mako/template.py validates them with...

1 affected package

mako

Package 16.04 LTS
mako Needs evaluation
Show less packages

CVE-2026-102505

Medium priority
Needs evaluation

Imager versions before 1.037 for Perl overflow a heap buffer fetching float samples from a paletted image in i_gsampf_fp. For a paletted image, getsamples() with type "float" allocates a buffer of one sample per pixel and fetches...

1 affected package

libimager-perl

Package 16.04 LTS
libimager-perl Needs evaluation
Show less packages

CVE-2026-102504

Medium priority
Needs evaluation

Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range raw_datachannels value in i_readraw_wiol. Nothing range-checks raw_datachannels. The line buffer is sized as the image width times the...

1 affected package

libimager-perl

Package 16.04 LTS
libimager-perl Needs evaluation
Show less packages

CVE-2026-101283

Medium priority
Needs evaluation

iperf3 3.20–3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decrypt_rsa_message(): a 256-byte RSA buffer is BIO_read with the attacker-controlled ciphertext length (guard warns only), so an unauthenticated client...

1 affected package

iperf3

Package 16.04 LTS
iperf3 Needs evaluation
Show less packages

CVE-2026-101276

Medium priority
Needs evaluation

iperf3 3.21 (esnet/iperf) contains a remote, unauthenticated heap use-after-free: the server's per-test watchdog server_timer_proc() frees streams without cancelling/joining their worker threads, so a blocked worker dereferences a...

1 affected package

iperf3

Package 16.04 LTS
iperf3 Needs evaluation
Show less packages

CVE-2026-102588

Medium priority
Needs evaluation

A flaw was found in Moodle. The XML grade import feature lacks proper Cross-Site Request Forgery (CSRF) token validation. By tricking an authenticated user with grade management permissions into visiting a malicious webpage, an...

1 affected package

moodle

Package 16.04 LTS
moodle Needs evaluation
Show less packages

CVE-2026-102587

Medium priority
Needs evaluation

A flaw was found in Moodle. User list filters do not properly enforce visibility restrictions on user profile fields. An authorized user with manager privileges can filter user lists using profile attributes they are not permitted...

1 affected package

moodle

Package 16.04 LTS
moodle Needs evaluation
Show less packages

CVE-2026-102586

Medium priority
Needs evaluation

A flaw was found in Moodle. Insufficient sanitization of username input on the password reset page allows a remote attacker to conduct a cross-site scripting (XSS) attack. By convincing an unauthenticated user to access...

1 affected package

moodle

Package 16.04 LTS
moodle Needs evaluation
Show less packages