Search CVE reports


Toggle filters

51 – 60 of 49237 results

Status is adjusted based on your filters.


CVE-2026-102253

Medium priority
Needs evaluation

iperf3 versions prior to 3.22 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash-loop the server's UDP receive worker into an unrecoverable infinite loop by sending a single crafted...

1 affected package

iperf3

Package 24.04 LTS
iperf3 Needs evaluation
Show less packages

CVE-2026-67987

Medium priority

Not in release

crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains polynomial-time regular expression denial-of-service conditions in think-tag response parsing on Ruby 3.1.x. A malicious or anomalous model response...

1 affected package

ruby-llm

Package 24.04 LTS
ruby-llm Not in release
Show less packages

CVE-2026-102875

Medium priority
Needs evaluation

VLC media player before 3.0.24 contains a path traversal vulnerability in the skins2 ThemeLoader that fails to validate member names in .vlt skin archives. Attackers can craft malicious skin files with path traversal sequences to...

1 affected package

vlc

Package 24.04 LTS
vlc Needs evaluation
Show less packages

CVE-2026-102831

Medium priority
Needs evaluation

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 4.5.0 until 4.5.11 and 4.6.4, from Notebook 7.5.0 until 7.6.3, and from JupyterLite...

2 affected packages

jupyter-notebook, jupyterlab

Package 24.04 LTS
jupyter-notebook Needs evaluation
jupyterlab Not in release
Show less packages

CVE-2026-102830

Medium priority

Not in release

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 3.0.0 until 4.5.11 and 4.6.4, and in JupyterLite Core 0.8.3 and earlier, the...

1 affected package

jupyterlab

Package 24.04 LTS
jupyterlab Not in release
Show less packages

CVE-2026-102825

Medium priority

Not in release

Russh is a Rust SSH client and server library. Prior to 0.62.6, the USERAUTH_REQUEST path reached from server::run_stream in russh/src/server/encrypted.rs increments self.common.auth_attempts but never compares it with...

1 affected package

rust-russh

Package 24.04 LTS
rust-russh Not in release
Show less packages

CVE-2026-102824

Medium priority

Not in release

Russh is a Rust SSH client and server library. Prior to 0.63.0, the hybrid ML-KEM 768 and X25519 implementation in russh/src/kex/hybrid_mlkem.rs accepts an all-zero 32-byte peer X25519 public key in both server_dh...

1 affected package

rust-russh

Package 24.04 LTS
rust-russh Not in release
Show less packages

CVE-2026-102823

Medium priority

Not in release

Russh is a Rust SSH client and server library. Prior to 0.63.1, client_read_authenticated in russh/src/client/encrypted.rs forwards CHANNEL_DATA, CHANNEL_EXTENDED_DATA, CHANNEL_EOF, CHANNEL_CLOSE, CHANNEL_OPEN_FAILURE,...

1 affected package

rust-russh

Package 24.04 LTS
rust-russh Not in release
Show less packages

CVE-2026-102822

Medium priority

Not in release

Russh is a Rust SSH client and server library. Prior to 0.63.1, a connection configured to permit mac=none can negotiate it with a MAC-requiring CTR or CBC block cipher because the selection logic validates needs_mac() only when...

1 affected package

rust-russh

Package 24.04 LTS
rust-russh Not in release
Show less packages

CVE-2026-102821

Medium priority

Not in release

Russh is a Rust SSH client and server library. Prior to 0.63.2, an authenticated remote peer can send SSH_MSG_KEXINIT without the required SSH_MSG_KEX_ECDH_INIT and then flood SSH_MSG_CHANNEL_OPEN messages...

1 affected package

rust-russh

Package 24.04 LTS
rust-russh Not in release
Show less packages