Search CVE reports


Toggle filters

341 – 350 of 50531 results

Status is adjusted based on your filters.


CVE-2026-54875

Low priority
Not affected

Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 private key operations on ARM64 and RISC-V platforms. Impact summary: An attacker able to measure the time taken by, or...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 20.04 LTS
openssl Not affected
openssl-fips —
openssl1.0 —
nodejs Not affected
edk2 Not affected
edk2-hwe —
Show less packages

CVE-2026-54872

Low priority

Some fixes available 1 of 2

Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret nonce through timing. Impact...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 20.04 LTS
openssl Fixed
openssl-fips —
openssl1.0 —
nodejs Not affected
edk2 Needs evaluation
edk2-hwe —
Show less packages

CVE-2026-46675

Medium priority
Needs evaluation

[Use-after-free of zlib input in `png_read_end` after incomplete zTXt, iTXt or iCCP decompression]

5 affected packages

libpng, libpng1.6, firefox, thunderbird, chromium-browser

Package 20.04 LTS
libpng —
libpng1.6 Needs evaluation
firefox —
thunderbird —
chromium-browser —
Show less packages

CVE-2026-35191

Low priority
Not affected

Issue summary: The OpenSSL QUIC server, when configured to not preform address validation, can be forced to count incoming packets multiple times in its unvalidated credit computation, leading to a violation of the RFC...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 20.04 LTS
openssl Not affected
openssl-fips —
openssl1.0 —
nodejs Not affected
edk2 Not affected
edk2-hwe —
Show less packages

CVE-2026-35189

Low priority

Some fixes available 1 of 2

Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions. Impact summary: Receiving a crafted certificate from a malicious peer...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 20.04 LTS
openssl Fixed
openssl-fips —
openssl1.0 —
nodejs Not affected
edk2 Needs evaluation
edk2-hwe —
Show less packages

CVE-2026-102414

Medium priority
Needs evaluation

pbkdf2 through 3.1.6 re-hashes passwords longer than the digest's block size on every iteration in its JavaScript fallback (lib/sync.js). A password longer than the block size (64 bytes, or 128 bytes for sha384 and sha512) is...

1 affected package

node-pbkdf2

Package 20.04 LTS
node-pbkdf2 Needs evaluation
Show less packages

CVE-2026-101281

Medium priority
Needs evaluation

A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_sp2_find_mailfrom_domain of the file libopendmarc/opendmarc_spf.c of the component SPF Macro Handler....

1 affected package

opendmarc

Package 20.04 LTS
opendmarc Needs evaluation
Show less packages

CVE-2026-101280

Medium priority
Needs evaluation

A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected is the function opendmarc_policy_query_dmarc of the component Multi-Record Set Handler. The manipulation results in authentication bypass by...

1 affected package

opendmarc

Package 20.04 LTS
opendmarc Needs evaluation
Show less packages

CVE-2026-101279

Medium priority
Needs evaluation

A security vulnerability has been detected in Trusted Domain Project OpenDMARC up to 1.4.2. This impacts an unknown function of the file libopendmarc/opendmarc_policy.c of the component DMARC Parser. The manipulation of the...

1 affected package

opendmarc

Package 20.04 LTS
opendmarc Needs evaluation
Show less packages

CVE-2026-101278

Medium priority
Needs evaluation

A weakness has been identified in Trusted Domain Project OpenDMARC up to 1.4.2. This affects the function opendmarc_get_tld of the file libopendmarc/opendmarc_tld.c : of the component PSL Wildcard Handler. Executing a manipulation...

1 affected package

opendmarc

Package 20.04 LTS
opendmarc Needs evaluation
Show less packages