Search CVE reports


Toggle filters

361 – 370 of 37432 results

Status is adjusted based on your filters.


CVE-2026-89266

Medium priority
Needs evaluation

stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int. Attackers can craft a malicious Ogg Vorbis file with large entries and...

1 affected package

libstb

Package 26.04 LTS
libstb Needs evaluation
Show less packages

CVE-2026-89259

Medium priority
Needs evaluation

Hugo is a static site generator. From v0.161.0, Hugo executes Node tools under Node's permission model, but TailwindCSS — included in the default security.exec.allow list — requires a highly permissive...

1 affected package

hugo

Package 26.04 LTS
hugo Needs evaluation
Show less packages

CVE-2026-89258

Medium priority
Needs evaluation

Hugo is a static site generator. In versions after v0.123.0 and before v0.165.0, symlinks in parent directories were not dropped during direct resource lookups, allowing path confinement to be bypassed. An attacker who can place —...

1 affected package

hugo

Package 26.04 LTS
hugo Needs evaluation
Show less packages

CVE-2026-89169

Medium priority
Needs evaluation

live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .verity file is missing.

1 affected package

live-boot

Package 26.04 LTS
live-boot Needs evaluation
Show less packages

CVE-2026-89162

Medium priority
Needs evaluation

In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe.

1 affected package

pcre2

Package 26.04 LTS
pcre2 Needs evaluation
Show less packages

CVE-2026-89161

Medium priority
Needs evaluation

In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur.

1 affected package

pcre2

Package 26.04 LTS
pcre2 Needs evaluation
Show less packages

CVE-2026-89160

Medium priority
Needs evaluation

PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject.

1 affected package

pcre2

Package 26.04 LTS
pcre2 Needs evaluation
Show less packages

CVE-2026-89158

Medium priority
Needs evaluation

PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write.

1 affected package

pcre2

Package 26.04 LTS
pcre2 Needs evaluation
Show less packages

CVE-2026-89157

Medium priority
Needs evaluation

PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern.

1 affected package

pcre2

Package 26.04 LTS
pcre2 Needs evaluation
Show less packages

CVE-2026-89156

Medium priority
Needs evaluation

PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data.

1 affected package

pcre2

Package 26.04 LTS
pcre2 Needs evaluation
Show less packages