Search CVE reports
1241 – 1250 of 47438 results
SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code injection via an X-Spip-Filtre HTTP request header that is mishandled by...
1 affected package
spip
| Package | 20.04 LTS |
|---|---|
| spip | Needs evaluation |
The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.
1 affected package
rust-arrayref
| Package | 20.04 LTS |
|---|---|
| rust-arrayref | Needs evaluation |
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected...
5 affected packages
webkitgtk, webkit2gtk, qtwebkit-source, qtwebkit-opensource-src, wpewebkit
| Package | 20.04 LTS |
|---|---|
| webkitgtk | — |
| webkit2gtk | Ignored |
| qtwebkit-source | — |
| qtwebkit-opensource-src | Ignored |
| wpewebkit | Ignored |
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead...
5 affected packages
webkitgtk, webkit2gtk, qtwebkit-source, qtwebkit-opensource-src, wpewebkit
| Package | 20.04 LTS |
|---|---|
| webkitgtk | — |
| webkit2gtk | Ignored |
| qtwebkit-source | — |
| qtwebkit-opensource-src | Ignored |
| wpewebkit | Ignored |
A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 26.6, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. Processing...
5 affected packages
webkitgtk, webkit2gtk, qtwebkit-source, qtwebkit-opensource-src, wpewebkit
| Package | 20.04 LTS |
|---|---|
| webkitgtk | — |
| webkit2gtk | Ignored |
| qtwebkit-source | — |
| qtwebkit-opensource-src | Ignored |
| wpewebkit | Ignored |
The issue was addressed with improved UI. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Visiting a website that frames malicious content may lead to UI spoofing.
5 affected packages
webkitgtk, webkit2gtk, qtwebkit-source, qtwebkit-opensource-src, wpewebkit
| Package | 20.04 LTS |
|---|---|
| webkitgtk | — |
| webkit2gtk | Ignored |
| qtwebkit-source | — |
| qtwebkit-opensource-src | Ignored |
| wpewebkit | Ignored |
A permissions issue was addressed with improved validation. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Maliciously crafted web content may violate iframe...
5 affected packages
webkitgtk, webkit2gtk, qtwebkit-source, qtwebkit-opensource-src, wpewebkit
| Package | 20.04 LTS |
|---|---|
| webkitgtk | — |
| webkit2gtk | Ignored |
| qtwebkit-source | — |
| qtwebkit-opensource-src | Ignored |
| wpewebkit | Ignored |
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6....
5 affected packages
webkitgtk, webkit2gtk, qtwebkit-source, qtwebkit-opensource-src, wpewebkit
| Package | 20.04 LTS |
|---|---|
| webkitgtk | — |
| webkit2gtk | Ignored |
| qtwebkit-source | — |
| qtwebkit-opensource-src | Ignored |
| wpewebkit | Ignored |
This issue was addressed with improved checks. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Websites may know if the user has visited a given link.
5 affected packages
webkitgtk, webkit2gtk, qtwebkit-source, qtwebkit-opensource-src, wpewebkit
| Package | 20.04 LTS |
|---|---|
| webkitgtk | — |
| webkit2gtk | Ignored |
| qtwebkit-source | — |
| qtwebkit-opensource-src | Ignored |
| wpewebkit | Ignored |
Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has two HTTP parsing weaknesses in http.c. evhttp_decode_uri_internal decodes percent-encoded %00 bytes into literal NUL characters, which can...
1 affected package
libevent
| Package | 20.04 LTS |
|---|---|
| libevent | Fixed |