Search CVE reports


Toggle filters

361 – 370 of 38817 results

Status is adjusted based on your filters.


CVE-2026-33948

Medium priority
Needs evaluation

jq is a command-line JSON processor. Commits before 6374ae0bcdfe33a18eb0ae6db28493b1f34a0a5b contain a vulnerability where CLI input parsing allows validation bypass via embedded NUL bytes. When reading JSON from files or stdin,...

1 affected package

jq

Package 20.04 LTS
jq Needs evaluation
Show less packages

CVE-2026-34003

Medium priority
Needs evaluation

XKB Buffer overflow in CheckKeyTypes(). The function CheckKeyTypes() will loop over the client's request but won't perform any additional bound checking to ensure that the data read remains within the request bounds. As a result,...

7 affected packages

xorg, xorg-server, xwayland, xorg-server-hwe-16.04, xorg-server-hwe-18.04...

Package 20.04 LTS
xorg Not affected
xorg-server Needs evaluation
xwayland
xorg-server-hwe-16.04
xorg-server-hwe-18.04
xorg-hwe-16.04
xorg-hwe-18.04
Show all 7 packages Show less packages

CVE-2026-34002

Medium priority
Needs evaluation

XKB Out-of-bounds read in CheckModifierMap(). CheckModifierMap() reads from the wire in a loop without verifying that the data remains within the bounds of the client request. As a result, the total number of keys could exceed the...

7 affected packages

xorg, xorg-server, xwayland, xorg-server-hwe-16.04, xorg-server-hwe-18.04...

Package 20.04 LTS
xorg Not affected
xorg-server Needs evaluation
xwayland
xorg-server-hwe-16.04
xorg-server-hwe-18.04
xorg-hwe-16.04
xorg-hwe-18.04
Show all 7 packages Show less packages

CVE-2026-34001

Medium priority
Needs evaluation

XSYNC Use-after-free in miSyncTriggerFence(). When walking the list of fences to trigger, miSyncTriggerFence() may call TriggerFence() for the current trigger, which end up calling the function SyncAwaitTriggerFired()....

7 affected packages

xorg, xorg-server, xwayland, xorg-server-hwe-16.04, xorg-server-hwe-18.04...

Package 20.04 LTS
xorg Not affected
xorg-server Needs evaluation
xwayland
xorg-server-hwe-16.04
xorg-server-hwe-18.04
xorg-hwe-16.04
xorg-hwe-18.04
Show all 7 packages Show less packages

CVE-2026-34000

Medium priority
Needs evaluation

XKB Out-of-bounds Read in CheckSetGeom(). Each key alias entry contains two key names (the alias and the real key name). The code in CheckSetGeom() does its bounds checking using only the first name, allowing XkbAddGeomKeyAlias to...

7 affected packages

xorg, xorg-server, xwayland, xorg-server-hwe-16.04, xorg-server-hwe-18.04...

Package 20.04 LTS
xorg Not affected
xorg-server Needs evaluation
xwayland
xorg-server-hwe-16.04
xorg-server-hwe-18.04
xorg-hwe-16.04
xorg-hwe-18.04
Show all 7 packages Show less packages

CVE-2026-33999

Medium priority
Needs evaluation

XKB Integer Underflow in XkbSetCompatMap(). If a "compat" buffer was previously truncated, there will be unused space left in the buffer. The code in XkbSetCompatMap() will use that space, but fails to update the number of valid...

7 affected packages

xorg, xorg-server, xwayland, xorg-server-hwe-16.04, xorg-server-hwe-18.04...

Package 20.04 LTS
xorg Not affected
xorg-server Needs evaluation
xwayland
xorg-server-hwe-16.04
xorg-server-hwe-18.04
xorg-hwe-16.04
xorg-hwe-18.04
Show all 7 packages Show less packages

CVE-2026-33116

Medium priority

Not in release

Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network.

5 affected packages

dotnet6, dotnet7, dotnet8, dotnet9, dotnet10

Package 20.04 LTS
dotnet6 Not in release
dotnet7 Not in release
dotnet8 Not in release
dotnet9 Not in release
dotnet10 Not in release
Show less packages

CVE-2026-32203

Medium priority

Not in release

Stack-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to deny service over a network.

5 affected packages

dotnet6, dotnet7, dotnet8, dotnet9, dotnet10

Package 20.04 LTS
dotnet6 Not in release
dotnet7 Not in release
dotnet8 Not in release
dotnet9 Not in release
dotnet10 Not in release
Show less packages

CVE-2026-32178

Medium priority

Not in release

Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network.

5 affected packages

dotnet6, dotnet7, dotnet8, dotnet9, dotnet10

Package 20.04 LTS
dotnet6 Not in release
dotnet7 Not in release
dotnet8 Not in release
dotnet9 Not in release
dotnet10 Not in release
Show less packages

CVE-2026-26171

Medium priority

Not in release

Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a network.

5 affected packages

dotnet6, dotnet7, dotnet8, dotnet9, dotnet10

Package 20.04 LTS
dotnet6 Not in release
dotnet7 Not in release
dotnet8 Not in release
dotnet9 Not in release
dotnet10 Not in release
Show less packages