Search CVE reports


Toggle filters

731 – 740 of 54252 results

Status is adjusted based on your filters.


CVE-2026-102731

Medium priority
Needs evaluation

Memory allocation with excessive size value vulnerability in Apache Directory LDAP API. A malicious peer (or a MITM) can send a small BER-encoded response causing a large memory allocation before any data is received. This can...

1 affected package

apache-directory-api

Package 22.04 LTS
apache-directory-api Needs evaluation
Show less packages

CVE-2026-95616

Medium priority
Needs evaluation

An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An unauthenticated attacker can send a SOAP message carrying an X.509 certificate whose SubjectKeyIdentifier extension declares a length...

1 affected package

wss4j

Package 22.04 LTS
wss4j Needs evaluation
Show less packages

CVE-2026-95512

Medium priority
Fixed

A flaw was found in FreeType, specifically within its CID font loader. A remote attacker could exploit this vulnerability by tricking a user into opening content that embeds or references a specially crafted CID-keyed font. This...

1 affected package

freetype

Package 22.04 LTS
freetype Fixed
Show less packages

CVE-2026-94603

Medium priority

Not in release

[Unknown description]

1 affected package

podman

Package 22.04 LTS
podman Not in release
Show less packages

CVE-2026-92899

Medium priority
Needs evaluation

Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reused. It stored the Nonce as raw base64 text, but authentication decodes that text and uses the bytes.The same bytes can be written...

1 affected package

wss4j

Package 22.04 LTS
wss4j Needs evaluation
Show less packages

CVE-2026-92121

Medium priority
Needs evaluation

In the WSS4J streaming (StAX) code, a signature reference using the WS-Security STR-Transform leaves an internal "inside signed content" flag permanently set. The WS-SecurityPolicy enforcer uses that flag to decide whether an...

1 affected package

wss4j

Package 22.04 LTS
wss4j Needs evaluation
Show less packages

CVE-2026-91148

Medium priority
Needs evaluation

[Unknown description]

1 affected package

cockpit

Package 22.04 LTS
cockpit Needs evaluation
Show less packages

CVE-2026-89238

Medium priority
Needs evaluation

WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass. Users are recommended to upgrade to...

1 affected package

wss4j

Package 22.04 LTS
wss4j Needs evaluation
Show less packages

CVE-2026-88920

Medium priority
Needs evaluation

An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge authenticated SOAP messages via a crafted unsigned SAML sender-vouches assertion containing...

1 affected package

wss4j

Package 22.04 LTS
wss4j Needs evaluation
Show less packages

CVE-2026-87830

Medium priority
Needs evaluation

In the StAX streaming WS-SecurityPolicy validator, certain relative or unsupported XPath expressions can be converted into paths that never match the actual XML element path. A remote SOAP peer may therefore send a required...

1 affected package

wss4j

Package 22.04 LTS
wss4j Needs evaluation
Show less packages