4 days 6 hours ago
4 days 6 hours ago
4 days 6 hours ago
4 days 6 hours ago
4 days 6 hours ago
It was discovered that Expat, vendored in ITK incorrectly handled certain
files. An attacker could possibly use this issue to cause a crash or
execute arbitrary code. (CVE-2022-25235, CVE-2022-25236)
4 days 7 hours ago
It was discovered that Expat, vendored in Coin3D incorrectly handled
certain files. An attacker could possibly use this issue to cause a crash
or execute arbitrary code.
4 days 7 hours ago
It was discovered that Expat, vendored in Swish-e incorrectly handled
certain files. An attacker could possibly use this issue to cause a crash
or execute arbitrary code. (CVE-2022-25235, CVE-2022-25236)
4 days 14 hours ago
Bartlomiej Dmitruk and Stanislaw Strzalkowski discovered that Apache
HTTP Server incorrectly handled certain memory operations when using the
HTTP/2 protocol. A remote attacker could use this issue to cause Apache
HTTP Server to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue only affected Ubuntu 26.04 LTS.
(CVE-2026-23918)
It was discovered that the Apache HTTP Server mod_rewrite module
incorrectly handled certain privileges. A local attacker could possibly use
this issue to obtain sensitive information. (CVE-2026-24072)
Andrew Lacambra, Elhanan Haenel, Tianshuo Han, and Tristan Madani
discovered that the Apache HTTP Server mod_proxy_ajp module incorrectly
handled certain AJP server messages. An attacker in control of a backend
AJP server could use this issue to cause Apache HTTP Server to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2026-28780)
Pavel Kohout discovered that Apache HTTP Server did not properly limit
resource allocation in mod_md when processing OCSP response data. A
remote attacker could possibly use this issue to cause a denial of
service. (CVE-2026-29168)
Pavel Kohout discovered that the Apache HTTP Server incorrectly handled
certain memory operations in mod_dav_lock. A remote attacker could possibly
use this issue to cause Apache HTTP Server to crash, resulting in a denial
of service. (CVE-2026-29169)
Nitescu Lucian discovered that Apache HTTP Server had a timing attack
vulnerability in mod_auth_digest. A remote attacker could possibly
use this issue to bypass Digest authentication. (CVE-2026-33006)
Pavel Kohout and Arkadi Vainbrand discovered that Apache HTTP Server
incorrectly handled certain memory operations in mod_authn_socache. A
remote attacker could possibly use this issue to cause Apache HTTP Server
to crash, resulting in a denial of service. (CVE-2026-33007)
Haruki Oyama, Merih Mengisteab, and Dawit Jeong discovered that
Apache HTTP Server had an HTTP response splitting vulnerability in
multiple modules when used with untrusted or compromised backend
servers. An attacker could possibly use this issue to inject arbitrary
HTTP headers. (CVE-2026-33523)
Elhanan Haenel discovered that Apache HTTP Server incorrectly handled
certain memory operations in mod_proxy_ajp. A remote attacker could
possibly use this issue to cause Apache HTTP Server to crash, resulting in
a denial of service. (CVE-2026-33857)
Tianshuo Han and Jérôme Djouder discovered that Apache HTTP Server
incorrectly handled certain string operations in mod_proxy_ajp. A remote
attacker could possibly use this issue to obtain sensitive information.
(CVE-2026-34032)
Elhanan Haenel discovered that Apache HTTP Server incorrectly handled
certain memory operations in mod_proxy_ajp. A remote attacker could use
this issue to cause Apache HTTP Server to crash, resulting in a denial of
service, or possibly obtain sensitive information. (CVE-2026-34059)
4 days 14 hours ago
USN-8233-1 fixed a vulnerability in nghttp2. This update provides the
corresponding update for Ubuntu 26.04 LTS.
Original advisory details:
Andrew MacPherson discovered that nghttp2 did not properly validate
internal state when the session termination API was called. A remote
attacker could possibly use this issue to cause nghttp2 to crash,
resulting in a denial of service.
4 days 16 hours ago
It was discovered that EditorConfig incorrectly handled specially crafted
configuration files. A local attacker could possibly use this issue to
cause EditorConfig to crash, resulting in a denial of service.
4 days 20 hours ago
Several security issues were discovered in the WebKitGTK Web and JavaScript
engines. If a user were tricked into viewing a malicious website, a remote
attacker could exploit a variety of issues related to web browser security,
including cross-site scripting attacks, denial of service attacks, and
arbitrary code execution.
4 days 20 hours ago
Version:next-20260506 (linux-next)
Released:2026-05-06
4 days 22 hours ago
4 days 23 hours ago
4 days 23 hours ago
5 days ago
5 days 1 hour ago
5 days 1 hour ago
It was discovered that Dynaconf was incorrectly handling template evaluation
in its string resolvers. A remote attacker could possibly use this issue
to execute arbitrary code.
5 days 1 hour ago
FEDORA-2026-ee7b1c75b6
Packages in this update:
Update description:
Update to 3.1.50; fixes CVE-2026-42215 / GHSA-mv93-w799-cj2w.
5 days 1 hour ago
FEDORA-2026-b4653c757d
Packages in this update:
Update description:
Update to 3.1.50; fixes CVE-2026-42215 / GHSA-mv93-w799-cj2w.