Search CVE reports


Toggle filters

1 – 10 of 155 results


CVE-2026-91205

Medium priority
Needs evaluation

A flaw was found in cockpit-files. A local unprivileged attacker can exploit a race condition during directory creation with owner assignment. By controlling a writable parent directory, the attacker can replace a newly created...

1 affected package

cockpit-files

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cockpit-files Needs evaluation Not in release Not in release
Show less packages

CVE-2026-91203

Medium priority
Needs evaluation

A flaw was found in cockpit-files. This vulnerability allows a local attacker to exploit a timing issue, known as a symlink race condition, during privileged file operations such as changing file ownership or permissions. By...

1 affected package

cockpit-files

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cockpit-files Needs evaluation Not in release Not in release
Show less packages

CVE-2026-91202

Medium priority
Needs evaluation

A flaw was found in cockpit-files. A low-privileged local user can exploit this vulnerability by crafting a directory containing a symbolic link (symlink) and then using the privileged "Paste as owner" function. This allows for...

1 affected package

cockpit-files

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cockpit-files Needs evaluation Not in release Not in release
Show less packages

CVE-2026-78322

Low priority
Needs evaluation

A flaw was found in file-roller. When opening or extracting a malicious 7z or RAR archive containing a file entry with an excessively long path, file-roller's progress-line parsing copies the path into a fixed-size stack buffer...

1 affected package

file-roller

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
file-roller Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-72814

Medium priority

Not in release

The actix-files crate (actix_files) before version 0.6.10 contains an information exposure vulnerability. When a non-existing folder is passed as the serve_from argument to Files::new(), the mount path defaults to an empty path;...

1 affected package

rust-actix-files

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rust-actix-files Not in release Not in release Not in release
Show less packages

CVE-2026-72813

Medium priority

Not in release

actix-files before 0.6.10 contains a denial of service vulnerability triggered by an empty Range header in GET requests for static files. When panic is set to abort, remote attackers can crash the process on-demand by sending a...

1 affected package

rust-actix-files

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rust-actix-files Not in release Not in release Not in release
Show less packages

CVE-2026-11527

Medium priority

Some fixes available 4 of 7

Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via a 2-arg open() of the -file argument in _make_filehandle. Config::IniFiles::_make_filehandle opens a filename argument with...

1 affected package

libconfig-inifiles-perl

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libconfig-inifiles-perl Fixed Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2026-37555

Medium priority
Vulnerable

An issue was discovered in libsndfile 1.2.2 IMA ADPCM codec. The AIFF code path (line 241) was fixed with (sf_count_t) cast, but the WAV code path (line 235) and close path (line 167) were not. When samplesperblock (int) * blocks...

1 affected package

libsndfile

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libsndfile Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2019-25683

Medium priority
Needs evaluation

FileZilla 3.40.0 contains a denial of service vulnerability in the local search functionality that allows local attackers to crash the application by supplying a malformed path string. Attackers can trigger the crash by entering a...

1 affected package

filezilla

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
filezilla Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-56226

Low priority
Needs evaluation

Libsndfile <=1.2.2 contains a memory leak vulnerability in the mpeg_l3_encoder_init() function within the mpeg_l3_encode.c file.

1 affected package

libsndfile

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libsndfile Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages