Search CVE reports


Toggle filters

191 – 200 of 38480 results

Status is adjusted based on your filters.


CVE-2026-32282

Medium priority
Needs evaluation

On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall...

16 affected packages

golang, golang-1.6, golang-1.8, golang-1.9, golang-1.10...

Package 20.04 LTS
golang
golang-1.6
golang-1.8
golang-1.9
golang-1.10
golang-1.13 Needs evaluation
golang-1.14 Needs evaluation
golang-1.16 Needs evaluation
golang-1.17
golang-1.18 Needs evaluation
golang-1.20 Needs evaluation
golang-1.21 Needs evaluation
golang-1.22 Needs evaluation
golang-1.23
golang-1.24
golang-1.25
Show all 16 packages Show less packages

CVE-2026-32281

Medium priority
Needs evaluation

Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of...

16 affected packages

golang, golang-1.6, golang-1.8, golang-1.9, golang-1.10...

Package 20.04 LTS
golang
golang-1.6
golang-1.8
golang-1.9
golang-1.10
golang-1.13 Needs evaluation
golang-1.14 Needs evaluation
golang-1.16 Needs evaluation
golang-1.17
golang-1.18 Needs evaluation
golang-1.20 Needs evaluation
golang-1.21 Needs evaluation
golang-1.22 Needs evaluation
golang-1.23
golang-1.24
golang-1.25
Show all 16 packages Show less packages

CVE-2026-32280

Medium priority
Needs evaluation

During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both...

16 affected packages

golang, golang-1.6, golang-1.8, golang-1.9, golang-1.10...

Package 20.04 LTS
golang
golang-1.6
golang-1.8
golang-1.9
golang-1.10
golang-1.13 Needs evaluation
golang-1.14 Needs evaluation
golang-1.16 Needs evaluation
golang-1.17
golang-1.18 Needs evaluation
golang-1.20 Needs evaluation
golang-1.21 Needs evaluation
golang-1.22 Needs evaluation
golang-1.23
golang-1.24
golang-1.25
Show all 16 packages Show less packages

CVE-2026-27144

Medium priority
Needs evaluation

The compiler is meant to unwrap pointers which are the operands of a memory move; a no-op interface conversion prevented the compiler from making the correct determination about non-overlapping moves, potentially leading to memory...

16 affected packages

golang, golang-1.6, golang-1.8, golang-1.9, golang-1.10...

Package 20.04 LTS
golang
golang-1.6
golang-1.8
golang-1.9
golang-1.10
golang-1.13 Needs evaluation
golang-1.14 Needs evaluation
golang-1.16 Needs evaluation
golang-1.17
golang-1.18 Needs evaluation
golang-1.20 Needs evaluation
golang-1.21 Needs evaluation
golang-1.22 Needs evaluation
golang-1.23
golang-1.24
golang-1.25
Show all 16 packages Show less packages

CVE-2026-27143

Medium priority
Needs evaluation

Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid indexing to occur at runtime, potentially leading to memory corruption.

16 affected packages

golang, golang-1.6, golang-1.8, golang-1.9, golang-1.10...

Package 20.04 LTS
golang
golang-1.6
golang-1.8
golang-1.9
golang-1.10
golang-1.13 Needs evaluation
golang-1.14 Needs evaluation
golang-1.16 Needs evaluation
golang-1.17
golang-1.18 Needs evaluation
golang-1.20 Needs evaluation
golang-1.21 Needs evaluation
golang-1.22 Needs evaluation
golang-1.23
golang-1.24
golang-1.25
Show all 16 packages Show less packages

CVE-2026-27140

Medium priority
Needs evaluation

SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.

16 affected packages

golang, golang-1.6, golang-1.8, golang-1.9, golang-1.10...

Package 20.04 LTS
golang
golang-1.6
golang-1.8
golang-1.9
golang-1.10
golang-1.13 Needs evaluation
golang-1.14 Needs evaluation
golang-1.16 Needs evaluation
golang-1.17
golang-1.18 Needs evaluation
golang-1.20 Needs evaluation
golang-1.21 Needs evaluation
golang-1.22 Needs evaluation
golang-1.23
golang-1.24
golang-1.25
Show all 16 packages Show less packages

CVE-2026-39881

Medium priority
Needs evaluation

Vim is an open source, command line text editor. Prior to 9.2.0316, a command injection vulnerability in Vim's netbeans interface allows a malicious netbeans server to execute arbitrary Ex commands when Vim connects to it, via...

1 affected package

vim

Package 20.04 LTS
vim Needs evaluation
Show less packages

CVE-2026-31411

Medium priority
Vulnerable

In the Linux kernel, the following vulnerability has been resolved: net: atm: fix crash due to unvalidated vcc pointer in sigd_send() Reproducer available at [1]. The ATM send path (sendmsg -> vcc_sendmsg -> sigd_send) reads the...

157 affected packages

linux-hwe, linux-hwe-5.4, linux-hwe-5.8, linux-hwe-5.11, linux-hwe-5.13...

Package 20.04 LTS
linux-hwe Not in release
linux-hwe-5.4 Not in release
linux-hwe-5.8 Ignored
linux-hwe-5.11 Ignored
linux-hwe-5.13 Ignored
linux-hwe-5.15 Vulnerable
linux-hwe-5.19 Not in release
linux-hwe-6.2 Not in release
linux-hwe-6.5 Not in release
linux-hwe-6.8 Not in release
linux-hwe-6.11 Not in release
linux-hwe-6.14 Not in release
linux-hwe-6.17 Not in release
linux-hwe-edge Not in release
linux-lts-xenial Not in release
linux-kvm Vulnerable
linux-allwinner-5.19 Not in release
linux-aws-5.0 Not in release
linux-aws-5.3 Not in release
linux-aws-5.4 Not in release
linux-aws-5.8 Ignored
linux-aws-5.11 Ignored
linux-aws-5.13 Ignored
linux-aws-5.15 Vulnerable
linux-aws-5.19 Not in release
linux-aws-6.2 Not in release
linux-aws-6.5 Not in release
linux-aws-6.8 Not in release
linux-aws-6.14 Not in release
linux-aws-6.17 Not in release
linux-aws-hwe Not in release
linux-azure-4.15 Not in release
linux-azure-5.3 Not in release
linux-azure-5.4 Not in release
linux-azure-5.8 Ignored
linux-azure-5.11 Ignored
linux-azure-5.13 Ignored
linux-azure-5.15 Vulnerable
linux-azure-5.19 Not in release
linux-azure-6.2 Not in release
linux-azure-6.5 Not in release
linux-azure-6.8 Not in release
linux-azure-6.11 Not in release
linux-azure-6.14 Not in release
linux-azure-6.17 Not in release
linux-azure-fde-5.15 Not affected
linux-azure-fde-5.19 Not in release
linux-azure-fde-6.2 Not in release
linux-azure-fde-6.8 Not in release
linux-azure-fde-6.14 Not in release
linux-azure-fde-6.17 Not in release
linux-azure-nvidia Not in release
linux-azure-nvidia-6.14 Not in release
linux-bluefield Vulnerable
linux-azure-edge Not in release
linux-fips Vulnerable
linux-aws-fips Vulnerable
linux-azure-fips Vulnerable
linux-gcp-fips Vulnerable
linux-gcp-4.15 Not in release
linux-gcp-5.3 Not in release
linux-gcp-5.4 Not in release
linux-gcp-5.8 Ignored
linux-gcp-5.11 Ignored
linux-gcp-5.13 Ignored
linux-gcp-5.15 Vulnerable
linux-gcp-5.19 Not in release
linux-gcp-6.2 Not in release
linux-gcp-6.5 Not in release
linux-gcp-6.8 Not in release
linux-gcp-6.11 Not in release
linux-gcp-6.14 Not in release
linux-gcp-6.17 Not in release
linux-gke Ignored
linux-gke-4.15 Not in release
linux-gke-5.4 Not in release
linux-gke-5.15 Ignored
linux-gkeop Ignored
linux-gkeop-5.4 Not in release
linux-gkeop-5.15 Ignored
linux-ibm Vulnerable
linux-ibm-5.4 Not in release
linux-ibm-5.15 Vulnerable
linux-ibm-6.8 Not in release
linux-intel-5.13 Ignored
linux-intel-iotg Not in release
linux-intel-iotg-5.15 Vulnerable
linux-iot Vulnerable
linux-intel-iot-realtime Not in release
linux-lowlatency Not in release
linux-lowlatency-hwe-5.15 Vulnerable
linux-lowlatency-hwe-5.19 Not in release
linux-lowlatency-hwe-6.2 Not in release
linux-lowlatency-hwe-6.5 Not in release
linux-lowlatency-hwe-6.8 Not in release
linux-lowlatency-hwe-6.11 Not in release
linux-nvidia Not in release
linux-nvidia-6.2 Not in release
linux-nvidia-6.5 Not in release
linux-nvidia-6.8 Not in release
linux-nvidia-6.11 Not in release
linux-nvidia-lowlatency Not in release
linux-nvidia-tegra Not in release
linux-nvidia-tegra-5.15 Vulnerable
linux-nvidia-tegra-igx Not in release
linux-oracle-5.0 Not in release
linux-oracle-5.3 Not in release
linux-oracle-5.4 Not in release
linux-oracle-5.8 Ignored
linux-oracle-5.11 Ignored
linux-oracle-5.13 Ignored
linux-oracle-5.15 Vulnerable
linux-oracle-6.5 Not in release
linux-oracle-6.8 Not in release
linux-oracle-6.14 Not in release
linux-oracle-6.17 Not in release
linux-oem Not in release
linux-oem-5.6 Ignored
linux-oem-5.10 Ignored
linux-oem-5.13 Ignored
linux-oem-5.14 Ignored
linux-oem-5.17 Not in release
linux-oem-6.0 Not in release
linux-oem-6.1 Not in release
linux-oem-6.5 Not in release
linux-oem-6.8 Not in release
linux-oem-6.11 Not in release
linux-oem-6.14 Not in release
linux-oem-6.17 Not in release
linux-raspi2 Ignored
linux-raspi-5.4 Not in release
linux-raspi-realtime Not in release
linux-realtime-6.8 Not in release
linux-realtime-6.14 Not in release
linux-riscv Ignored
linux-riscv-5.8 Ignored
linux-riscv-5.11 Ignored
linux-riscv-5.15 Vulnerable
linux-riscv-5.19 Not in release
linux-riscv-6.5 Not in release
linux-riscv-6.8 Not in release
linux-riscv-6.14 Not in release
linux-riscv-6.17 Not in release
linux-starfive-5.19 Not in release
linux-starfive-6.2 Not in release
linux-starfive-6.5 Not in release
linux-xilinx Not in release
linux-xilinx-zynqmp Vulnerable
linux-realtime-6.17 Not in release
linux Vulnerable
linux-aws Vulnerable
linux-azure Vulnerable
linux-azure-fde Ignored
linux-gcp Vulnerable
linux-oracle Vulnerable
linux-raspi Vulnerable
linux-realtime Not in release
Show all 157 packages Show less packages

CVE-2026-34582

Medium priority
Needs evaluation

Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records to be processed prior to the Finished message being received. A server which is attempting to enforce client...

2 affected packages

botan, botan3

Package 20.04 LTS
botan Needs evaluation
botan3
Show less packages

CVE-2026-34580

Medium priority
Needs evaluation

Botan is a C++ cryptography library. In 3.11.0, the function Certificate_Store::certificate_known had a misleading name; it would return true if any certificate in the store had a DN (and subject key identifier, if set) matching...

2 affected packages

botan3, botan

Package 20.04 LTS
botan3
botan Needs evaluation
Show less packages