Search CVE reports


Toggle filters

81 – 90 of 50631 results

Status is adjusted based on your filters.


CVE-2026-104851

Medium priority
Needs evaluation

fsspec is a specification and Python implementation framework for filesystem interfaces. From 0.9.0 until 2026.6.0, fsspec.implementations.reference.ReferenceFileSystem evaluates fields from Kerchunk reference JSON documents...

1 affected package

fsspec

Package 20.04 LTS
fsspec Needs evaluation
Show less packages

CVE-2026-104733

Medium priority
Needs evaluation

User Impersonation in ProcessOnes XMMP Server ejabberd <= 26.04 allows an attacker to impersonate arbitrary users via unvalidated authzid parameter in SASL-PLAIN mechanism.

1 affected package

ejabberd

Package 20.04 LTS
ejabberd Needs evaluation
Show less packages

CVE-2026-104721

Medium priority
Needs evaluation

Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an MDC-based discriminator value flows unsanitized into a nested FileAppender...

1 affected package

logback

Package 20.04 LTS
logback Needs evaluation
Show less packages

CVE-2026-103885

Medium priority
Needs evaluation

Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API. A LDAP server using the LDAP API (like Apache DS) may consume 100% of a CPU core indefinitely when processing some badly crafted Telephone Numbers. This...

1 affected package

apache-directory-api

Package 20.04 LTS
apache-directory-api Needs evaluation
Show less packages

CVE-2026-103880

Medium priority
Needs evaluation

Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API. Storing a password using the bcrypt algorithm with a high force like 30 in a LDAP server that supports this algorithm will cause the server CPU to run for...

1 affected package

apache-directory-api

Package 20.04 LTS
apache-directory-api Needs evaluation
Show less packages

CVE-2026-103878

Medium priority
Needs evaluation

Cleartext transmission of sensitive information vulnerability in Apache Directory LDAP API. A StartTLS extended operation started after a Search request has been sent can lead to receive data in plain text before the TLS Handshake...

1 affected package

apache-directory-api

Package 20.04 LTS
apache-directory-api Needs evaluation
Show less packages

CVE-2026-103877

Medium priority
Needs evaluation

Deserialization of Untrusted Data vulnerability in Apache Directory LDAP API. A rogue/compromised LDAP server (or pre-TLS MITM) can answer a client's loadSchema() subschema search with a schema object that contains a serialized...

1 affected package

apache-directory-api

Package 20.04 LTS
apache-directory-api Needs evaluation
Show less packages

CVE-2026-103552

Medium priority
Needs evaluation

Stack Overflow vulnerability in Apache Directory LDAP API. Before binding, a client can send a deeply nested search filter that overflows the stack in the server's decoder. This issue affects Apache Directory LDAP API: from 1.2.0...

1 affected package

apache-directory-api

Package 20.04 LTS
apache-directory-api Needs evaluation
Show less packages

CVE-2026-102795

Medium priority
Needs evaluation

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which...

1 affected package

trafficserver

Package 20.04 LTS
trafficserver Needs evaluation
Show less packages

CVE-2026-102731

Medium priority
Needs evaluation

Memory allocation with excessive size value vulnerability in Apache Directory LDAP API. A malicious peer (or a MITM) can send a small BER-encoded response causing a large memory allocation before any data is received. This can...

1 affected package

apache-directory-api

Package 20.04 LTS
apache-directory-api Needs evaluation
Show less packages