Search CVE reports


Toggle filters

1401 – 1410 of 58295 results

Status is adjusted based on your filters.


CVE-2026-44950

Medium priority
Needs evaluation

fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) copies each glyph's bitmap into a single buffer. Existing checks validates only that the source slice (position, length) lies within the source bitmap buffer....

2 affected packages

libxfont, libxfont2

Package 16.04 LTS
libxfont Needs evaluation
libxfont2 Needs evaluation
Show less packages

CVE-2026-84939

Medium priority
Needs evaluation

Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can specify an arbitrary malformed locale identifier to FreeMarker, and the localized lookup configuration setting is enabled (it's by...

1 affected package

libfreemarker-java

Package 16.04 LTS
libfreemarker-java Needs evaluation
Show less packages

CVE-2026-79522

Medium priority
Needs evaluation

An out-of-bounds read in the gf_dm_get_chunk_data function (src/utils/downloader.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request. Fixed in 2fd5a06ab226767900fd86edb5a1e8bfc1010640.

1 affected package

gpac

Package 16.04 LTS
gpac Needs evaluation
Show less packages

CVE-2026-79514

Medium priority
Needs evaluation

An out-of-bounds read in the gf_dm_data_received function (downloader.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request. Fixed in 2fd5a06ab226767900fd86edb5a1e8bfc1010640.

1 affected package

gpac

Package 16.04 LTS
gpac Needs evaluation
Show less packages

CVE-2026-79513

Medium priority
Needs evaluation

A divide-by-zero vulnerability in the gf_dash_get_timeline_duration function (src/media_tools/dash_client.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via a crafted MPD SegmentTimeline. Fixed in...

1 affected package

gpac

Package 16.04 LTS
gpac Needs evaluation
Show less packages

CVE-2026-71616

Medium priority
Needs evaluation

An issue in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to cause a denial of service via the function gf_route_media_complete_object(). Fixed in 3c4e6c5b3e0c6fa9b16d55599701a08354538fab.

1 affected package

gpac

Package 16.04 LTS
gpac Needs evaluation
Show less packages

CVE-2026-71614

Medium priority
Needs evaluation

An issue in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to execute arbitrary code via the src/media_tools/dvb_mpe.c, descriptorTime_slice_fec_identifier() and gf_m2ts_ipdatagram_reader() components. Fixed in...

1 affected package

gpac

Package 16.04 LTS
gpac Needs evaluation
Show less packages

CVE-2026-71613

Medium priority
Needs evaluation

Buffer Overflow vulnerability in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to execute arbitrary code via the j2kdec_process() function. Fixed in 9a253a07fd3f6b48022bba74302bf39388dda859.

1 affected package

gpac

Package 16.04 LTS
gpac Needs evaluation
Show less packages

CVE-2026-71612

Medium priority
Needs evaluation

Buffer Overflow vulnerability in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to execute arbitrary code via the nhntdmx_process() function. Fixed in fac50e6a12ac27ffabdd5d3080b51afcc44ad8d6.

1 affected package

gpac

Package 16.04 LTS
gpac Needs evaluation
Show less packages

CVE-2026-38998

Medium priority
Needs evaluation

A use-after-free in the SocketDescriptor::tcpReadHandler1 function (liveMedia/RTPInterface.cpp) of LIVE555 Streaming Media (version 2026.02.26) allows attackers to cause a Denial of Service (DoS) via sending a series of crafted...

1 affected package

liblivemedia

Package 16.04 LTS
liblivemedia Needs evaluation
Show less packages