Search CVE reports


Toggle filters

1371 – 1380 of 34287 results

Status is adjusted based on your filters.


CVE-2026-28753

Medium priority
Needs evaluation

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of CRLF sequences in DNS responses. This allows an attacker-controlled DNS server to inject arbitrary headers...

1 affected package

nginx

Package 24.04 LTS
nginx Needs evaluation
Show less packages

CVE-2026-27784

Medium priority
Needs evaluation

The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to over-read or over-write NGINX worker memory resulting in its termination, using a specially...

1 affected package

nginx

Package 24.04 LTS
nginx Needs evaluation
Show less packages

CVE-2026-27654

Medium priority
Needs evaluation

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination of the...

1 affected package

nginx

Package 24.04 LTS
nginx Needs evaluation
Show less packages

CVE-2026-27651

Medium priority
Needs evaluation

When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and...

1 affected package

nginx

Package 24.04 LTS
nginx Needs evaluation
Show less packages

CVE-2026-4729

Medium priority
Ignored

Memory safety bugs present in Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This...

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 24.04 LTS
firefox Not affected
thunderbird Not affected
mozjs38 Not in release
mozjs52 Not in release
mozjs68 Not in release
mozjs78 Not in release
mozjs91 Not in release
mozjs102 Ignored
mozjs115 Ignored
Show all 9 packages Show less packages

CVE-2026-4728

Medium priority
Ignored

Spoofing issue in the Privacy: Anti-Tracking component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 24.04 LTS
firefox Not affected
thunderbird Not affected
mozjs38 Not in release
mozjs52 Not in release
mozjs68 Not in release
mozjs78 Not in release
mozjs91 Not in release
mozjs102 Ignored
mozjs115 Ignored
Show all 9 packages Show less packages

CVE-2026-4727

Medium priority
Ignored

Denial-of-service in the Libraries component in NSS. This vulnerability was fixed in Firefox 149 and Thunderbird 149.

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 24.04 LTS
firefox Not affected
thunderbird Not affected
mozjs38 Not in release
mozjs52 Not in release
mozjs68 Not in release
mozjs78 Not in release
mozjs91 Not in release
mozjs102 Ignored
mozjs115 Ignored
Show all 9 packages Show less packages

CVE-2026-4726

Medium priority
Ignored

Denial-of-service in the XML component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 24.04 LTS
firefox Not affected
thunderbird Not affected
mozjs38 Not in release
mozjs52 Not in release
mozjs68 Not in release
mozjs78 Not in release
mozjs91 Not in release
mozjs102 Ignored
mozjs115 Ignored
Show all 9 packages Show less packages

CVE-2026-4725

Medium priority
Ignored

Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 24.04 LTS
firefox Not affected
thunderbird Not affected
mozjs38 Not in release
mozjs52 Not in release
mozjs68 Not in release
mozjs78 Not in release
mozjs91 Not in release
mozjs102 Ignored
mozjs115 Ignored
Show all 9 packages Show less packages

CVE-2026-4724

Medium priority
Ignored

Undefined behavior in the Audio/Video component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 24.04 LTS
firefox Not affected
thunderbird Not affected
mozjs38 Not in release
mozjs52 Not in release
mozjs68 Not in release
mozjs78 Not in release
mozjs91 Not in release
mozjs102 Ignored
mozjs115 Ignored
Show all 9 packages Show less packages