Search CVE reports


Toggle filters

341 – 350 of 49601 results

Status is adjusted based on your filters.


CVE-2026-102999

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF containing many embedded files can cause the dictionary-based attachments API in pypdf/_doc_common.py to reparse the full attachment list for...

2 affected packages

pypdf, pypdf2

Package 24.04 LTS
pypdf Needs evaluation
pypdf2 Needs evaluation
Show less packages

CVE-2026-102998

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF with form field values can cause pypdf/generic/_appearance_stream.py appearance-stream generation to repeat invariant selection-data work...

2 affected packages

pypdf, pypdf2

Package 24.04 LTS
pypdf Needs evaluation
pypdf2 Needs evaluation
Show less packages

CVE-2026-102997

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF containing a partially malformed /FlateDecode stream with padded data can force pypdf/filters.py to use inefficient byte-by-byte decompression...

2 affected packages

pypdf, pypdf2

Package 24.04 LTS
pypdf Needs evaluation
pypdf2 Needs evaluation
Show less packages

CVE-2026-102996

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can provide a TrueType or Type1 simple font with an unusually large /Widths array, causing pypdf/_font.py Font._collect_tt_t1_character_widths...

2 affected packages

pypdf, pypdf2

Package 24.04 LTS
pypdf Needs evaluation
pypdf2 Needs evaluation
Show less packages

CVE-2026-102995

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can place unusually large source-code or destination-string tokens in a font /ToUnicode mapping, causing pypdf/_cmap.py parse_bfchar to decode...

2 affected packages

pypdf, pypdf2

Package 24.04 LTS
pypdf Needs evaluation
pypdf2 Needs evaluation
Show less packages

CVE-2026-102994

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to 6.18.0, a crafted PDF containing indirect-object identifiers or generation-number tokens that continue for a long time without whitespace can cause pypdf/_reader.py...

2 affected packages

pypdf, pypdf2

Package 24.04 LTS
pypdf Needs evaluation
pypdf2 Needs evaluation
Show less packages

CVE-2026-102993

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to 6.17.0, a crafted PDF can provide unusually large Roman page-label values that cause pypdf/_page_labels.py to generate excessively large numeral strings when...

2 affected packages

pypdf, pypdf2

Package 24.04 LTS
pypdf Needs evaluation
pypdf2 Needs evaluation
Show less packages

CVE-2026-102991

Medium priority
Needs evaluation

Mako is a template library written in Python. Prior to 1.4.2, on Windows, TemplateLookup.get_template() in mako/lookup.py resolves template URIs with posixpath, while Template.__init__() in mako/template.py validates them with...

1 affected package

mako

Package 24.04 LTS
mako Needs evaluation
Show less packages

CVE-2026-102990

Medium priority
Needs evaluation

basic-ftp is an FTP client for Node.js. Prior to 6.2.1, Client.list() can be forced by a malicious or compromised FTP server to spend quadratic CPU time parsing a directory listing because the RE_LINE expression...

1 affected package

node-proxy-agents

Package 24.04 LTS
node-proxy-agents Needs evaluation
Show less packages

CVE-2026-103500

Medium priority
Needs evaluation

An attacker could cause a heap buffer overflow by getting a user to open an email that is greater than or equal to 2GB in size. This vulnerability was fixed in Thunderbird 157, Thunderbird 140.17, and Thunderbird 153.4.

1 affected package

thunderbird

Package 24.04 LTS
thunderbird Needs evaluation
Show less packages