Search CVE reports


Toggle filters

61 – 70 of 39999 results

Status is adjusted based on your filters.


CVE-2026-86335

Medium priority

Not in release

Missing Authorization in imageDownload in Canonical LXD before 5.0.10, 5.21.8, and 6.10 on Linux allows a project-restricted client to access private images from other projects via local fingerprint reuse during image or instance...

1 affected package

lxd

Package 26.04 LTS
lxd Not in release
Show less packages

CVE-2026-86334

Medium priority

Not in release

Path traversal in the CLI client image export and copy functionality in Canonical LXD from 4.0.2 before 4.0.14, 5.0.10, 5.21.8, and 6.10 on all platforms allows a remote malicious or machine-in-the-middle image server to overwrite...

1 affected package

lxd

Package 26.04 LTS
lxd Not in release
Show less packages

CVE-2026-85644

Medium priority
Needs evaluation

XS::Parse::Infix versions from 0.40 through 0.49 for Perl treat a number as an array reference. The wrapper function XS::Parse::Infix generates for a list-associative infix operator checks whether arguments are array references,...

1 affected package

libxs-parse-keyword-perl

Package 26.04 LTS
libxs-parse-keyword-perl Needs evaluation
Show less packages

CVE-2026-85526

Medium priority
Needs evaluation

Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with instance creation privileges to delete or replace arbitrary files and directories on the host filesystem as root...

2 affected packages

incus, lxd

Package 26.04 LTS
incus Needs evaluation
lxd Not in release
Show less packages

CVE-2026-85185

Medium priority
Needs evaluation

Path traversal in the btrfs storage driver in Canonical LXD versions 4.0.2 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create instances in a project to delete...

2 affected packages

incus, lxd

Package 26.04 LTS
incus Needs evaluation
lxd Not in release
Show less packages

CVE-2026-84784

Low priority

Some fixes available 1 of 3

QUIC: Unbounded RETIRE_CONNECTION_ID Backlog

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS
openssl Fixed
openssl-fips Not in release
openssl1.0 Not in release
nodejs Not affected
edk2 Vulnerable
edk2-hwe Vulnerable
Show less packages

CVE-2026-84783

Medium priority
Not affected

Use-After-Free in X.509 Extension Cache Under Concurrent Use

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS
openssl Not affected
openssl-fips Not in release
openssl1.0 Not in release
nodejs Not affected
edk2 Not affected
edk2-hwe Not affected
Show less packages

CVE-2026-84782

High priority

Some fixes available 1 of 3

DTLS Retransmits Handshake Messages From a Stale Buffer Offset

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS
openssl Fixed
openssl-fips Not in release
openssl1.0 Not in release
nodejs Not affected
edk2 Needs evaluation
edk2-hwe Needs evaluation
Show less packages

CVE-2026-80432

Medium priority
Needs evaluation

Missing Authorization in the drop handling path of the drag and drop protocol in kitty from 0.47.0 before 0.49.0 allows a program writing to the terminal to obtain the contents of files dragged over the window even when the user...

1 affected package

kitty

Package 26.04 LTS
kitty Needs evaluation
Show less packages

CVE-2026-80431

Medium priority
Needs evaluation

Out-of-bounds Write in the natural width branch of the text sizing protocol in kitty from 0.40.0 before 0.49.0 allows a program writing to the terminal to write past the end of a fixed-size buffer,...

1 affected package

kitty

Package 26.04 LTS
kitty Needs evaluation
Show less packages