Search CVE reports


Toggle filters

1081 – 1090 of 59781 results

Status is adjusted based on your filters.


CVE-2026-88837

Medium priority
Needs evaluation

BusyBox httpd treats yescrypt ($y$) password hashes as plaintext during Basic Authentication, inverting the authentication check.

1 affected package

busybox

Package 16.04 LTS
busybox Needs evaluation
Show less packages

CVE-2026-88835

Medium priority
Needs evaluation

BusyBox dpkg read_package_field() steps past a NUL terminator on malformed .deb packages, causing an out-of-bounds heap read.

1 affected package

busybox

Package 16.04 LTS
busybox Needs evaluation
Show less packages

CVE-2026-88831

Medium priority
Needs evaluation

BusyBox httpd IP deny rules with invalid CIDR prefix lengths fail open, leaving a parsed IP with a zeroed mask so the rule matches no clients.

1 affected package

busybox

Package 16.04 LTS
busybox Needs evaluation
Show less packages

CVE-2026-88832

Medium priority
Needs evaluation

BusyBox romfs volume ID parsing uses unbounded strlen on attacker-controlled metadata, causing a heap buffer overflow when processing crafted filesystem images.

1 affected package

busybox

Package 16.04 LTS
busybox Needs evaluation
Show less packages

CVE-2026-88830

Medium priority
Needs evaluation

A unit confusion in BusyBox TLS Montgomery reduction buffer allocation causes a pre-authentication heap buffer overflow when processing a crafted ClientKeyExchange message.

1 affected package

busybox

Package 16.04 LTS
busybox Needs evaluation
Show less packages

CVE-2026-6669

Medium priority
Needs evaluation

Missing upper bound on the key derivation iteration count accepted during SCRAM authentication to a backend server in PgBouncer through 1.25.2 allows a malicious or compromised PostgreSQL backend to cause uncontrolled...

1 affected package

pgbouncer

Package 16.04 LTS
pgbouncer Needs evaluation
Show less packages

CVE-2026-6668

Medium priority
Needs evaluation

Integer overflow in the packet buffer growth logic in PgBouncer through 1.25.2 allows an unauthenticated remote attacker to cause a denial of service. Sufficiently large input makes the buffer size computation overflow, leaving...

1 affected package

pgbouncer

Package 16.04 LTS
pgbouncer Needs evaluation
Show less packages

CVE-2026-19888

Medium priority
Needs evaluation

Missing validation of a mandatory attribute in the SCRAM client-final-message parser in PgBouncer through 1.25.2 allows an unauthenticated remote attacker to crash the process. A malformed message can make the parser report...

1 affected package

pgbouncer

Package 16.04 LTS
pgbouncer Needs evaluation
Show less packages

CVE-2026-96675

Medium priority
Needs evaluation

alsa-lib through 1.2.16.1 contains a denial of service vulnerability in the multi PCM plugin that fails to validate sparse binding indices before array access. Attackers can supply a malicious ALSA configuration file with sparse...

1 affected package

alsa-lib

Package 16.04 LTS
alsa-lib Needs evaluation
Show less packages

CVE-2026-96674

Medium priority
Needs evaluation

alsa-lib through 1.2.16.1 computes combined topology element size using 32-bit arithmetic in src/topology/ctl.c, allowing integer overflow that defeats bounds checks. Attackers can supply crafted topology files that wrap size...

1 affected package

alsa-lib

Package 16.04 LTS
alsa-lib Needs evaluation
Show less packages