Search CVE reports


Toggle filters

31 – 40 of 41073 results

Status is adjusted based on your filters.


CVE-2026-107210

Medium priority
Needs evaluation

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, a crafted highly compressed MAT image can make the MAT decoder create temporary files larger than the...

1 affected package

imagemagick

Package 26.04 LTS
imagemagick Needs evaluation
Show less packages

CVE-2026-107209

Medium priority
Needs evaluation

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, when ImageMagick is built without Cairo support, a crafted RSVG image that reaches a resource limit...

1 affected package

imagemagick

Package 26.04 LTS
imagemagick Needs evaluation
Show less packages

CVE-2026-107208

Medium priority
Needs evaluation

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, a crafted XMP profile can reach a recursion limit that is handled as a fatal condition instead of an...

1 affected package

imagemagick

Package 26.04 LTS
imagemagick Needs evaluation
Show less packages

CVE-2026-107183

Medium priority
Needs evaluation

llama.cpp before b11393 contains a use-after-free and double free vulnerability in common_chat_peg_mapper::map that allows unauthenticated remote attackers to corrupt heap memory via a dangling current_tool pointer. Attackers can...

1 affected package

llama.cpp

Package 26.04 LTS
llama.cpp Needs evaluation
Show less packages

CVE-2026-107181

Medium priority

Not in release

Telegram Desktop before 7.2.9 contains an IPC record-separator injection vulnerability in Core::Sandbox that allows remote attackers to inject OPEN: records via crafted tg:// links containing unescaped semicolons. Attackers can...

1 affected package

telegram-desktop

Package 26.04 LTS
telegram-desktop Not in release
Show less packages

CVE-2026-107170

Medium priority
Needs evaluation

A flaw was found in m17n-lib. A partial failure during library initialization can leave an internal driver pointer uninitialized. Under specific error conditions, such as system resource exhaustion or database corruption, an...

1 affected package

m17n-lib

Package 26.04 LTS
m17n-lib Needs evaluation
Show less packages

CVE-2026-107169

Medium priority
Needs evaluation

A flaw was found in m17n-lib. An attacker could provide specially crafted or truncated UTF-8 input to trigger an unhandled null pointer dereference during text processing. This issue causes the application to crash unexpectedly,...

1 affected package

m17n-lib

Package 26.04 LTS
m17n-lib Needs evaluation
Show less packages

CVE-2026-107168

Medium priority
Needs evaluation

A flaw was found in m17n-lib. By providing crafted input containing an invalid UTF-8 character sequence, an attacker can cause the text parsing function to enter an infinite loop. This issue leads to sustained high...

1 affected package

m17n-lib

Package 26.04 LTS
m17n-lib Needs evaluation
Show less packages

CVE-2026-107167

Medium priority
Needs evaluation

A flaw was found in m17n-lib. A user providing specially crafted text input can trigger a heap use-after-free condition during input-method state transitions. Under specific conditions, the library frees an internal input context...

1 affected package

m17n-lib

Package 26.04 LTS
m17n-lib Needs evaluation
Show less packages

CVE-2026-107161

Medium priority
Needs evaluation

A heap-based buffer overflow flaw was found in Cyrus SASL. The add_to_challenge() function in the DIGEST-MD5 plugin computes the size of the buffer needed for a challenge/response field before DIGEST-MD5 quoting is applied, but...

1 affected package

cyrus-sasl2

Package 26.04 LTS
cyrus-sasl2 Needs evaluation
Show less packages