Search CVE reports


Toggle filters

871 – 880 of 49990 results

Status is adjusted based on your filters.


CVE-2026-6253

Medium priority
Vulnerable

curl might erroneously pass on credentials for a first proxy to a second proxy.

1 affected package

curl

Package 16.04 LTS
curl Vulnerable
Show less packages

CVE-2026-5773

Low priority
Vulnerable

libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers.

1 affected package

curl

Package 16.04 LTS
curl Vulnerable
Show less packages

CVE-2026-5545

Medium priority
Vulnerable

libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a Negotiate-authenticated one, when both use the same host.

1 affected package

curl

Package 16.04 LTS
curl Vulnerable
Show less packages

CVE-2026-4873

Low priority
Vulnerable

A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool. If an initial transfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent...

1 affected package

curl

Package 16.04 LTS
curl Vulnerable
Show less packages

CVE-2026-22741

Medium priority
Needs evaluation

Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC or...

1 affected package

libspring-java

Package 16.04 LTS
libspring-java Needs evaluation
Show less packages

CVE-2026-22740

Medium priority
Needs evaluation

A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files may remain not deleted after the request is fully processed. This allows...

1 affected package

libspring-java

Package 16.04 LTS
libspring-java Needs evaluation
Show less packages

CVE-2026-40687

Medium priority
Needs evaluation

In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from...

1 affected package

exim4

Package 16.04 LTS
exim4 Needs evaluation
Show less packages

CVE-2026-40686

Medium priority
Needs evaluation

In Exim before 4.99.2, when utf8 operators are enabled, there is an out-of-bounds read if large UTF-8 trailing characters are present (malformed UTF-8 header data). Information might be divulged within an error message produced...

1 affected package

exim4

Package 16.04 LTS
exim4 Needs evaluation
Show less packages

CVE-2026-40685

Medium priority
Needs evaluation

In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrusted header, because of an incorrect implementation of \ skipping.

1 affected package

exim4

Package 16.04 LTS
exim4 Needs evaluation
Show less packages

CVE-2026-40684

Medium priority
Not affected

In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a dn_expand oddity in octal printing.

1 affected package

exim4

Package 16.04 LTS
exim4 Not affected
Show less packages