Search CVE reports


Toggle filters

1451 – 1460 of 38020 results

Status is adjusted based on your filters.


CVE-2026-87432

Medium priority
Not affected

Incorrect authorization in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

1 affected package

chromium-browser

Package 26.04 LTS
chromium-browser Not affected
Show less packages

CVE-2026-87431

Medium priority
Not affected

Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Medium)

1 affected package

chromium-browser

Package 26.04 LTS
chromium-browser Not affected
Show less packages

CVE-2026-87430

Medium priority
Not affected

Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)

1 affected package

chromium-browser

Package 26.04 LTS
chromium-browser Not affected
Show less packages

CVE-2026-87429

Medium priority
Not affected

Missing authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security...

1 affected package

chromium-browser

Package 26.04 LTS
chromium-browser Not affected
Show less packages

CVE-2026-53939

Medium priority
Needs evaluation

OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). In versions 0.6.1 through 0.6.2.5, when cjose encrypts a JWE using an AES-CBC-HMAC content-encryption algorithm...

1 affected package

cjose

Package 26.04 LTS
cjose Needs evaluation
Show less packages

CVE-2026-53938

Medium priority
Needs evaluation

OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). Prior to version 0.6.2.5, cjose's JWE decryption path for the AES Key Wrap key-management algorithms (`alg` = `A128KW`,...

1 affected package

cjose

Package 26.04 LTS
cjose Needs evaluation
Show less packages

CVE-2026-19201

Medium priority
Needs evaluation

An uncontrolled recursion vulnerability in the Windows SIPA event log parser of Google go-attestation versions up to and including 0.6.1 allows an attacker to cause a denial of service (DoS). The (*WinEvents).readELAMAggregation...

1 affected package

golang-github-google-go-attestation

Package 26.04 LTS
golang-github-google-go-attestation Needs evaluation
Show less packages

CVE-2026-85013

Medium priority
Needs evaluation

[Unknown description]

1 affected package

modules

Package 26.04 LTS
modules Needs evaluation
Show less packages

CVE-2026-86564

Medium priority
Vulnerable

A flaw was found in DPDK lib/vhost. Missing length validation before reading command_data in the virtio-net control-queue handler can cause an out-of-bounds read and a host process crash.

1 affected package

dpdk

Package 26.04 LTS
dpdk Vulnerable
Show less packages

CVE-2026-18090

Medium priority
Needs evaluation

A flaw was found in gdk-pixbuf. This vulnerability allows a remote attacker to cause a heap out-of-bounds read by providing a specially crafted Apple Icon Image (.icns) file. The uncompress() function, which handles RLE-encoded...

1 affected package

gdk-pixbuf

Package 26.04 LTS
gdk-pixbuf Needs evaluation
Show less packages