Search CVE reports


Toggle filters

111 – 120 of 50831 results

Status is adjusted based on your filters.


CVE-2026-45490

Medium priority

Not in release

Improper authorization in .NET allows an authorized attacker to elevate privileges locally.

5 affected packages

dotnet10, dotnet6, dotnet7, dotnet8, dotnet9

Package 16.04 LTS
dotnet10 Not in release
dotnet6 Not in release
dotnet7 Not in release
dotnet8 Not in release
dotnet9 Not in release
Show less packages

CVE-2026-45447

High priority
Fixed

Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process crashes, heap corruption, or...

5 affected packages

edk2, nodejs, openssl, openssl-fips, openssl1.0

Package 16.04 LTS
edk2
nodejs
openssl Fixed
openssl-fips
openssl1.0
Show less packages

CVE-2026-45446

Low priority
Not affected

Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) mishandle the authentication of AAD (Additional Authenticated Data) with an empty ciphertext allowing a forgery of such messages. Impact summary:...

5 affected packages

edk2, nodejs, openssl, openssl-fips, openssl1.0

Package 16.04 LTS
edk2
nodejs
openssl Not affected
openssl-fips
openssl1.0
Show less packages

CVE-2026-45445

Medium priority
Not affected

Issue summary: When an application drives an AES-OCB context through the public EVP_Cipher() one-shot interface, the application-supplied initialisation vector (IV) is silently discarded. Impact summary: Every message encrypted...

5 affected packages

edk2, nodejs, openssl, openssl-fips, openssl1.0

Package 16.04 LTS
edk2
nodejs
openssl Not affected
openssl-fips
openssl1.0
Show less packages

CVE-2026-42771

Low priority
Not affected

Issue summary: When the X509_VERIFY_PARAM_set1_email is called by an application to validate a crafted e-mail address, such as during S/MIME message validation, an out of bounds read can happen. Impact summary: This out of bounds...

5 affected packages

edk2, nodejs, openssl, openssl-fips, openssl1.0

Package 16.04 LTS
edk2
nodejs
openssl Not affected
openssl-fips
openssl1.0
Show less packages

CVE-2026-42770

Low priority
Not affected

Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly checked for the subgroup membership. Impact summary: A malicious peer which presents an X9.42 key carrying...

5 affected packages

edk2, nodejs, openssl, openssl-fips, openssl1.0

Package 16.04 LTS
edk2
nodejs
openssl Not affected
openssl-fips
openssl1.0
Show less packages

CVE-2026-42769

Low priority
Not affected

Issue Summary: An error in the callback used to verify the certificate provided in a Root CA key update Certificate Management Protocol (CMP) message response rendered the certificate validation ineffectual, which could lead to...

5 affected packages

edk2, nodejs, openssl, openssl-fips, openssl1.0

Package 16.04 LTS
edk2
nodejs
openssl Not affected
openssl-fips
openssl1.0
Show less packages

CVE-2026-42768

Low priority
Not affected

Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to Bleichenbacher-style attack when an attacker is able to provide the CMS or S/MIME messages and observe the error code and/or decryption output. Impact...

5 affected packages

edk2, nodejs, openssl, openssl-fips, openssl1.0

Package 16.04 LTS
edk2
nodejs
openssl Not affected
openssl-fips
openssl1.0
Show less packages

CVE-2026-42767

Low priority
Not affected

Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer dereference in a CMP client application. Impact summary: A NULL pointer dereference causes a crash of the application...

5 affected packages

edk2, nodejs, openssl, openssl-fips, openssl1.0

Package 16.04 LTS
edk2
nodejs
openssl Not affected
openssl-fips
openssl1.0
Show less packages

CVE-2026-42766

Low priority
Fixed

Issue summary: A specially crafted password-encrypted CMS message can trigger a NULL pointer dereference during CMS decryption. Impact summary: This NULL pointer dereference leads to an application crash and a Denial of...

5 affected packages

edk2, nodejs, openssl, openssl-fips, openssl1.0

Package 16.04 LTS
edk2
nodejs
openssl Fixed
openssl-fips
openssl1.0
Show less packages