Search CVE reports


Toggle filters

701 – 710 of 47985 results

Status is adjusted based on your filters.


CVE-2026-58649

Medium priority

Not in release

Origin validation error in .NET allows an unauthorized attacker to disclose information over a network.

4 affected packages

dotnet6, dotnet7, dotnet8, dotnet10

Package 20.04 LTS
dotnet6 Not in release
dotnet7 Not in release
dotnet8 Not in release
dotnet10 Not in release
Show less packages

CVE-2026-16028

Medium priority
Needs evaluation

Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion via closed streams that stream_state never removes from the connection stream table. When a stream reaches the CLOSED state, stream_state returns...

1 affected package

libprotocol-http2-perl

Package 20.04 LTS
libprotocol-http2-perl Needs evaluation
Show less packages

CVE-2026-19843

Medium priority
Needs evaluation

A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP entry's distinguished name (DN) into a shell command string without proper escaping. An LDAP user with...

1 affected package

389-ds-base

Package 20.04 LTS
389-ds-base Needs evaluation
Show less packages

CVE-2026-18922

Medium priority
Needs evaluation

A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent,...

1 affected package

389-ds-base

Package 20.04 LTS
389-ds-base Needs evaluation
Show less packages

CVE-2026-18453

Medium priority
Needs evaluation

A flaw was found in 389 Directory Server. A missing NULL pointer check in the paged results handling of op_shared_search allows an unauthenticated remote attacker to crash the LDAP server by sending a crafted sequence of search...

1 affected package

389-ds-base

Package 20.04 LTS
389-ds-base Needs evaluation
Show less packages

CVE-2026-18355

Medium priority
Needs evaluation

A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), the wrapped-record length read from the wire is validated only against an upper bound. A small wire...

1 affected package

389-ds-base

Package 20.04 LTS
389-ds-base Needs evaluation
Show less packages

CVE-2026-76560

Medium priority
Needs evaluation

A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy...

1 affected package

389-ds-base

Package 20.04 LTS
389-ds-base Needs evaluation
Show less packages

CVE-2026-79678

Medium priority
Needs evaluation

A flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-url input reaches a constrained eval() call before the corresponding LDAP access control check is enforced. This allows any...

1 affected package

freeipa

Package 20.04 LTS
freeipa Needs evaluation
Show less packages

CVE-2026-76578

Medium priority
Needs evaluation

A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP client can exploit this, combined...

1 affected package

freeipa

Package 20.04 LTS
freeipa Needs evaluation
Show less packages

CVE-2026-78135

Medium priority
Needs evaluation

libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Because CREATE_CHILD_SA requests are mishandled, there can be an authentication bypass.

1 affected package

strongswan

Package 20.04 LTS
strongswan Needs evaluation
Show less packages