Search CVE reports


Toggle filters

391 – 400 of 56196 results

Status is adjusted based on your filters.


CVE-2026-68516

Medium priority
Needs evaluation

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. From version 3.4.0 through 3.4.13, a crafted HTJ2K-compressed EXR can crash OpenEXR during normal...

1 affected package

openexr

Package 16.04 LTS
openexr Needs evaluation
Show less packages

CVE-2026-65915

Medium priority
Needs evaluation

NLTK versions before 3.10.0 contain a logic bug in FileSystemPathPointer.open() where the sandbox validation check compares a normalized path against itself, making the security check permanently inert. Attackers can pass file://...

1 affected package

nltk

Package 16.04 LTS
nltk Needs evaluation
Show less packages

CVE-2026-63312

Medium priority
Needs evaluation

NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.ENFORCE by calling builtins.open() directly instead of pathsec.open(). Attackers who control the fileid...

1 affected package

nltk

Package 16.04 LTS
nltk Needs evaluation
Show less packages

CVE-2026-63311

Medium priority
Needs evaluation

NLTK before 3.10.0 (affected versions <= 3.9.4) contains a server-side request forgery (SSRF) vulnerability in the validate_network_url() function in nltk/pathsec.py. The _resolve_hostname() helper catches OSError and ValueError...

1 affected package

nltk

Package 16.04 LTS
nltk Needs evaluation
Show less packages

CVE-2026-63310

Medium priority
Needs evaluation

NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that...

1 affected package

nltk

Package 16.04 LTS
nltk Needs evaluation
Show less packages

CVE-2026-63076

Medium priority
Needs evaluation

Invalid Pointer Dereference in CMP Server via Crafted protectionAlg

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 16.04 LTS
openssl Not affected
openssl-fips
openssl1.0
nodejs Needs evaluation
edk2 Not affected
edk2-hwe
Show less packages

CVE-2026-63075

Low priority
Needs evaluation

QUIC ACK-only Packet Retention Can Cause Memory Exhaustion

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 16.04 LTS
openssl Not affected
openssl-fips
openssl1.0
nodejs Needs evaluation
edk2 Not affected
edk2-hwe
Show less packages

CVE-2026-63074

Low priority
Needs evaluation

CMP Indefinite Cache Growth of ExtraCerts

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 16.04 LTS
openssl Not affected
openssl-fips
openssl1.0
nodejs Needs evaluation
edk2 Not affected
edk2-hwe
Show less packages

CVE-2026-63073

Low priority
Needs evaluation

Untrusted Sender DN Used as Format String in CMP Response Validation

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 16.04 LTS
openssl Not affected
openssl-fips
openssl1.0
nodejs Needs evaluation
edk2 Not affected
edk2-hwe
Show less packages

CVE-2026-63072

Medium priority

Some fixes available 1 of 3

Heap Buffer Overflow in CMS Key Unwrapping

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 16.04 LTS
openssl Fixed
openssl-fips
openssl1.0
nodejs Needs evaluation
edk2 Needs evaluation
edk2-hwe
Show less packages