Search CVE reports


Toggle filters

861 – 870 of 46511 results

Status is adjusted based on your filters.


CVE-2026-18147

Medium priority
Needs evaluation

(A flaw was found in FreeIPA. An unauthenticated remote attacker could ...)

1 affected package

freeipa

Package 24.04 LTS
freeipa Needs evaluation
Show less packages

CVE-2026-61915

Medium priority
Needs evaluation

VPATCH BYPARAM double-free: An authenticated calendar user could crash a Cyrus CalDAV worker with a PATCH containing PATCH-ACTION="BYPARAM@..." against a resource with two or more properties of the matched kind. The memory...

1 affected package

cyrus-imapd

Package 24.04 LTS
cyrus-imapd Needs evaluation
Show less packages

CVE-2026-61911

Medium priority
Needs evaluation

Sieve mailbox existence oracle: An authenticated user could install a Sieve script that probed whether another user's private mailbox existed, or read the value of shared mailbox annotations, by observing which fileinto branch...

1 affected package

cyrus-imapd

Package 24.04 LTS
cyrus-imapd Needs evaluation
Show less packages

CVE-2026-61910

Medium priority
Needs evaluation

Mailbox/set let sharee change special-use role on shared mailboxes: An authenticated user with maySetKeywords on another user's mailbox could change that mailbox's specialuse annotation. This could allow the sharee to change the...

1 affected package

cyrus-imapd

Package 24.04 LTS
cyrus-imapd Needs evaluation
Show less packages

CVE-2026-61909

Medium priority
Needs evaluation

CalDAV/CardDAV multiget bypasses per-href ACL: An authenticated DAV user with some shared access to another user's calendar or address book could read even unshared events or contacts by including the target hrefs in...

1 affected package

cyrus-imapd

Package 24.04 LTS
cyrus-imapd Needs evaluation
Show less packages

CVE-2026-61908

Medium priority
Needs evaluation

JMAP email-header blob ID out-of-bounds index: An authenticated user could attempt to download a specially crafted JMAP blob ID of the form H<emailid>-<index>, which could read past the end of the internal blob_headers array...

1 affected package

cyrus-imapd

Package 24.04 LTS
cyrus-imapd Needs evaluation
Show less packages

CVE-2026-61907

Medium priority
Needs evaluation

JMAP snooze bypasses destination-mailbox ACL: An authenticated user with insert permissions on another user's snoozed mailbox could cause insertion of mail to that user's inbox, or any other of their mailboxes whose id was known...

1 affected package

cyrus-imapd

Package 24.04 LTS
cyrus-imapd Needs evaluation
Show less packages

CVE-2026-86469

Medium priority
Needs evaluation

(A flaw was found in GLib2. When g_file_replace() is used with G_FILE_C ...)

1 affected package

glib2.0

Package 24.04 LTS
glib2.0 Needs evaluation
Show less packages

CVE-2026-86435

Medium priority
Needs evaluation

(commonmark versions from 1.5.0 before 2.8.4 contain a denial of servic ...)

1 affected package

php-league-commonmark

Package 24.04 LTS
php-league-commonmark Needs evaluation
Show less packages

CVE-2026-86434

Medium priority
Needs evaluation

(league/commonmark versions &gt;= 2.0.0 and &lt; 2.8.4 (patched in 2.9.0) con ...)

1 affected package

php-league-commonmark

Package 24.04 LTS
php-league-commonmark Needs evaluation
Show less packages