Search CVE reports


Toggle filters

1201 – 1210 of 58108 results

Status is adjusted based on your filters.


CVE-2026-88050

Medium priority
Needs evaluation

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, RecodedCharID::DeSerialize in src/ccutil/unicharcompress.h validates length_ but accepts negative code_ values from a crafted .traineddata recoder component....

1 affected package

tesseract

Package 16.04 LTS
tesseract Needs evaluation
Show less packages

CVE-2026-88049

Medium priority
Needs evaluation

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, prior .traineddata hardening added bounds checks to NetworkIO::CopyTimeStepGeneral and NetworkIO::Randomize in src/lstm/networkio.cpp but left...

1 affected package

tesseract

Package 16.04 LTS
tesseract Needs evaluation
Show less packages

CVE-2026-88048

Medium priority
Needs evaluation

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, FullyConnected::DeSerialize in src/lstm/fullyconnected.cpp does not validate the deserialized layer scalars ni_ and no_ against the weight-matrix dimensions....

1 affected package

tesseract

Package 16.04 LTS
tesseract Needs evaluation
Show less packages

CVE-2026-88047

Medium priority
Needs evaluation

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Classify::ReadNormProtos in src/classify/normmatch.cpp parses the NORMPROTO component of a .traineddata file and uses std::istream::operator>>(char*) to extract...

1 affected package

tesseract

Package 16.04 LTS
tesseract Needs evaluation
Show less packages

CVE-2026-88924

Medium priority
Needs evaluation

A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled...

1 affected package

gvfs

Package 16.04 LTS
gvfs Needs evaluation
Show less packages

CVE-2026-46387

Medium priority
Needs evaluation

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, Suricata's HTTP/2 decompression path could grow the...

1 affected package

suricata

Package 16.04 LTS
suricata Needs evaluation
Show less packages

CVE-2026-45747

Medium priority
Needs evaluation

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.16, the Lua TLS certificate information helper could dereference NULL certificate fields...

1 affected package

suricata

Package 16.04 LTS
suricata Needs evaluation
Show less packages

CVE-2026-45763

Medium priority
Needs evaluation

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, when Lua rule execution is enabled, the Lua sandbox memory...

1 affected package

suricata

Package 16.04 LTS
suricata Needs evaluation
Show less packages

CVE-2026-88038

Medium priority
Needs evaluation

cookies is a Node.js library for reading and writing HTTP cookies, used by Koa via ctx.cookies. In versions before 0.9.2 the library validates the cookie name and value against character sets that reject the semicolon separator,...

1 affected package

node-cookies

Package 16.04 LTS
node-cookies Needs evaluation
Show less packages

CVE-2026-88859

Medium priority
Needs evaluation

A flaw was found in Evolution. A remote attacker can exploit this vulnerability by sending a specially crafted HTML email containing a spoofed vCard control. When a victim clicks on this control, Evolution's trusted JavaScript...

1 affected package

evolution

Package 16.04 LTS
evolution Needs evaluation
Show less packages