Search CVE reports


Toggle filters

241 – 250 of 42041 results

Status is adjusted based on your filters.


CVE-2026-12259

Medium priority
Needs evaluation

In nltk version 3.9.4, the `nltk.downloader.Downloader._download_package()` function writes downloaded package bytes to disk and may extract them before enforcing SHA-256 or MD5 checksum validation. This allows an attacker to...

1 affected package

nltk

Package 24.04 LTS
nltk Needs evaluation
Show less packages

CVE-2026-6695

Medium priority
Needs evaluation

A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially crafted PAA (Paint Shop Pro Array) image file. This vulnerability, a heap-based out-of-bounds write in the decode_lzss()...

1 affected package

gimp

Package 24.04 LTS
gimp Needs evaluation
Show less packages

CVE-2026-6694

Medium priority
Needs evaluation

A flaw was found in GIMP's file-png plugin. A remote attacker can exploit this by crafting a malicious Animated Portable Network Graphics (APNG) image containing an oversized tRNS chunk. This can lead to a stack-based buffer...

1 affected package

gimp

Package 24.04 LTS
gimp Needs evaluation
Show less packages

CVE-2026-14682

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before...

1 affected package

bouncycastle

Package 24.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-13586

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS). This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before...

1 affected package

bouncycastle

Package 24.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-13506

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7...

1 affected package

bouncycastle

Package 24.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-12860

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

1 affected package

bouncycastle

Package 24.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-12852

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque length before bounds check.

1 affected package

bouncycastle

Package 24.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-12817

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.85, OpenPGP AEAD decryption skips final tag on chunk-aligned data. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips...

1 affected package

bouncycastle

Package 24.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-12816

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.85, IESEngine stream-mode MAC forgery via length-dependent KDF split. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

1 affected package

bouncycastle

Package 24.04 LTS
bouncycastle Needs evaluation
Show less packages