Search CVE reports


Toggle filters

741 – 750 of 54269 results

Status is adjusted based on your filters.


CVE-2026-94651

Medium priority
Needs evaluation

improper handling of exceptional conditions, Missing release of resource after effective lifetime vulnerability in Apache Thrift java bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to...

1 affected package

libthrift-java

Package 22.04 LTS
libthrift-java Needs evaluation
Show less packages

CVE-2026-85494

Medium priority
Needs evaluation

Improper handling of length parameter inconsistency, Uncaught exception, Inefficient Algorithmic Complexity, Memory allocation with excessive size value, Initialization of a resource with an insecure default vulnerability in...

4 affected packages

php-horde-thrift, python-thrift, ruby-thrift, thrift

Package 22.04 LTS
php-horde-thrift Not in release
python-thrift Not in release
ruby-thrift Needs evaluation
thrift Needs evaluation
Show less packages

CVE-2026-103885

Medium priority
Needs evaluation

Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API. A LDAP server using the LDAP API (like Apache DS) may consume 100% of a CPU core indefinitely when processing some badly crafted Telephone Numbers. This...

1 affected package

apache-directory-api

Package 22.04 LTS
apache-directory-api Needs evaluation
Show less packages

CVE-2026-103880

Medium priority
Needs evaluation

Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API. Storing a password using the bcrypt algorithm with a high force like 30 in a LDAP server that supports this algorithm will cause the server CPU to run for...

1 affected package

apache-directory-api

Package 22.04 LTS
apache-directory-api Needs evaluation
Show less packages

CVE-2026-103878

Medium priority
Needs evaluation

Cleartext transmission of sensitive information vulnerability in Apache Directory LDAP API. A StartTLS extended operation started after a Search request has been sent can lead to receive data in plain text before the TLS Handshake...

1 affected package

apache-directory-api

Package 22.04 LTS
apache-directory-api Needs evaluation
Show less packages

CVE-2026-103877

Medium priority
Needs evaluation

Deserialization of Untrusted Data vulnerability in Apache Directory LDAP API. A rogue/compromised LDAP server (or pre-TLS MITM) can answer a client's loadSchema() subschema search with a schema object that contains a serialized...

1 affected package

apache-directory-api

Package 22.04 LTS
apache-directory-api Needs evaluation
Show less packages

CVE-2026-103552

Medium priority
Needs evaluation

Stack Overflow vulnerability in Apache Directory LDAP API. Before binding, a client can send a deeply nested search filter that overflows the stack in the server's decoder. This issue affects Apache Directory LDAP API: from 1.2.0...

1 affected package

apache-directory-api

Package 22.04 LTS
apache-directory-api Needs evaluation
Show less packages

CVE-2026-102731

Medium priority
Needs evaluation

Memory allocation with excessive size value vulnerability in Apache Directory LDAP API. A malicious peer (or a MITM) can send a small BER-encoded response causing a large memory allocation before any data is received. This can...

1 affected package

apache-directory-api

Package 22.04 LTS
apache-directory-api Needs evaluation
Show less packages

CVE-2026-95616

Medium priority
Needs evaluation

An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An unauthenticated attacker can send a SOAP message carrying an X.509 certificate whose SubjectKeyIdentifier extension declares a length...

1 affected package

wss4j

Package 22.04 LTS
wss4j Needs evaluation
Show less packages

CVE-2026-95512

Medium priority
Fixed

A flaw was found in FreeType, specifically within its CID font loader. A remote attacker could exploit this vulnerability by tricking a user into opening content that embeds or references a specially crafted CID-keyed font. This...

1 affected package

freetype

Package 22.04 LTS
freetype Fixed
Show less packages