Search CVE reports


Toggle filters

191 – 200 of 59858 results

Status is adjusted based on your filters.


CVE-2026-47360

Medium priority
Needs evaluation

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module. When SessionCookieRemove changes across internal redirects, the session cookie may still be passed to a...

1 affected package

apache2

Package 16.04 LTS
apache2 Needs evaluation
Show less packages

CVE-2026-46729

Medium priority
Needs evaluation

NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

1 affected package

apache2

Package 16.04 LTS
apache2 Needs evaluation
Show less packages

CVE-2026-42528

Medium priority
Needs evaluation

A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child processes. Users are recommended to upgrade to version 2.4.69, which fixes this issue

1 affected package

apache2

Package 16.04 LTS
apache2 Needs evaluation
Show less packages

CVE-2026-42356

Medium priority
Needs evaluation

Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and...

1 affected package

apache2

Package 16.04 LTS
apache2 Needs evaluation
Show less packages

CVE-2026-19553

Medium priority
Needs evaluation

ssl.SSLContext.wrap_bio() didn't require the server_hostname argument to not be None if ssl.SSLContext.check_hostname was set. Due to a missing parameter check in SSLObject, if the server_hostname argument isn't supplied then...

11 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7...

Package 16.04 LTS
python2.7 Needs evaluation
python3.4 —
python3.5 Needs evaluation
python3.6 —
python3.7 —
python3.8 —
python3.9 —
python3.10 —
python3.11 —
python3.12 —
python3.14 —
Show all 11 packages Show less packages

CVE-2026-19445

Medium priority
Needs evaluation

A remote, unauthenticated TLS client can make a server crash or call through a freed pointer if its sni_callback assigns a different context to SSLSocket.context (the documented way to select a certificate per server name) and...

11 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7...

Package 16.04 LTS
python2.7 Needs evaluation
python3.4 —
python3.5 Needs evaluation
python3.6 —
python3.7 —
python3.8 —
python3.9 —
python3.10 —
python3.11 —
python3.12 —
python3.14 —
Show all 11 packages Show less packages

CVE-2026-104201

Medium priority
Needs evaluation

[GHSA-wj29-mxmc-q98c: Heap OOB read/write in MS-MPPE key re-encryption]

1 affected package

radsecproxy

Package 16.04 LTS
radsecproxy Needs evaluation
Show less packages

CVE-2026-103680

Medium priority
Needs evaluation

A flaw was found in tnef. A heap-based buffer overflow can occur in the find_free_number() function when generating numbered backup suffixes for duplicate filenames. When numbered backups are enabled and file overwriting is...

1 affected package

tnef

Package 16.04 LTS
tnef Needs evaluation
Show less packages

CVE-2026-103679

Medium priority
Needs evaluation

A flaw was found in tnef. A remote attacker could exploit this vulnerability by providing a specially crafted Transport Neutral Encapsulation Format (TNEF) file containing multiple message bodies. During extraction, improper...

1 affected package

tnef

Package 16.04 LTS
tnef Needs evaluation
Show less packages

CVE-2026-103678

Medium priority
Needs evaluation

A flaw was found in tnef. An attacker can exploit this vulnerability by providing a specially crafted file containing uncompressed Rich Text Format (RTF) data. Because the application fails to properly validate input...

1 affected package

tnef

Package 16.04 LTS
tnef Needs evaluation
Show less packages