Search CVE reports


Toggle filters

441 – 450 of 45172 results

Status is adjusted based on your filters.


CVE-2026-13057

Medium priority

Not in release

An issue in the server’s Atlas Search integration allows an authenticated user to bypass per-user access controls. In sharded topologies, the $search and $searchMeta aggregation stages use internal routing that is normally...

1 affected package

mongodb

Package 22.04 LTS
mongodb Not in release
Show less packages

CVE-2026-13056

Medium priority

Not in release

Using expressions that generate large arrays it is possible to craft a query that creates very large intermediate objects in memory, causing the server to crash with OOM error.

1 affected package

mongodb

Package 22.04 LTS
mongodb Not in release
Show less packages

CVE-2026-13055

Medium priority

Not in release

The `$_internalIndexKey` aggregation expression can be used by any authenticated user to crash a MongoDB server (mongod). The expression fails to handle compound wildcard index specifications, triggering an internal consistency...

1 affected package

mongodb

Package 22.04 LTS
mongodb Not in release
Show less packages

CVE-2026-64835

Medium priority
Needs evaluation

FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted...

2 affected packages

ffmpeg, libav

Package 22.04 LTS
ffmpeg Needs evaluation
libav Not in release
Show less packages

CVE-2026-64834

Medium priority
Needs evaluation

FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service by sending a crafted RTP/ASF stream. The...

2 affected packages

ffmpeg, libav

Package 22.04 LTS
ffmpeg Needs evaluation
libav Not in release
Show less packages

CVE-2026-64833

Medium priority
Needs evaluation

FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger...

2 affected packages

ffmpeg, libav

Package 22.04 LTS
ffmpeg Needs evaluation
libav Not in release
Show less packages

CVE-2026-64832

Medium priority
Needs evaluation

FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no...

2 affected packages

ffmpeg, libav

Package 22.04 LTS
ffmpeg Needs evaluation
libav Not in release
Show less packages

CVE-2026-64831

Medium priority
Needs evaluation

FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses and adjacent stack frames by supplying a crafted...

2 affected packages

ffmpeg, libav

Package 22.04 LTS
ffmpeg Needs evaluation
libav Not in release
Show less packages

CVE-2026-64830

Medium priority
Needs evaluation

FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more...

2 affected packages

ffmpeg, libav

Package 22.04 LTS
ffmpeg Needs evaluation
libav Not in release
Show less packages

CVE-2026-16615

Medium priority
Needs evaluation

A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated "code verifier" lacks...

1 affected package

librest

Package 22.04 LTS
librest Needs evaluation
Show less packages