Search CVE reports


Toggle filters

251 – 260 of 36488 results

Status is adjusted based on your filters.


CVE-2026-85042

Medium priority
Not affected

Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

1 affected package

chromium-browser

Package 26.04 LTS
chromium-browser Not affected
Show less packages

CVE-2026-84989

Medium priority

Not in release

ntopng is a web-based network traffic monitoring application. In versions 6.7.0 through 6.7.260717, two REST v2 endpoints that manage ntopng's tag/badge feature — `POST /lua/rest/v2/delete/tag/tag.lua` and...

1 affected package

ntopng

Package 26.04 LTS
ntopng Not in release
Show less packages

CVE-2026-84971

Medium priority
Needs evaluation

Improper handling of an unexpected value size in the decryption path of a client-side encryption library can cause a failed internal check that terminates the process using the library. A party able to place a suitably formed...

1 affected package

libmongocrypt

Package 26.04 LTS
libmongocrypt Needs evaluation
Show less packages

CVE-2026-84970

Medium priority

Not in release

A numeric truncation weakness exists in the JSON parsing component of the MongoDB C++ Driver's BSON library. An actor who controls the text that an embedding application hands to the library's public JSON parsing interface, when...

1 affected package

mongo-cxx-driver

Package 26.04 LTS
mongo-cxx-driver Not in release
Show less packages

CVE-2026-84969

Medium priority
Needs evaluation

A memory-handling error in the BSON-to-JSON conversion helpers of the MongoDB C Driver can write a small number of bytes past the end of a heap buffer when a binary field is encoded and the output is cut short at...

1 affected package

mongo-c-driver

Package 26.04 LTS
mongo-c-driver Needs evaluation
Show less packages

CVE-2026-84968

Medium priority
Needs evaluation

An out-of-bounds read in the BSON decoding component of the MongoDB PHP driver may allow an unauthenticated party who supplies specially formed input to have a small amount of adjacent process memory copied into an error message...

1 affected package

php-mongodb

Package 26.04 LTS
php-mongodb Needs evaluation
Show less packages

CVE-2026-84966

Medium priority

Not in release

An incorrect numeric type conversion in the BSON document building component of the MongoDB C++ Driver may cause a length value to be interpreted incorrectly. When an application supplies an extremely large, non-terminated field...

1 affected package

mongo-cxx-driver

Package 26.04 LTS
mongo-cxx-driver Not in release
Show less packages

CVE-2026-84965

Medium priority
Needs evaluation

An integer wraparound in an allocation size calculation in the BSON library's JSON parsing code can cause a buffer to be released while a following copy operation still writes through the stale pointer. On builds where sizes are...

1 affected package

mongo-c-driver

Package 26.04 LTS
mongo-c-driver Needs evaluation
Show less packages

CVE-2026-84964

Medium priority
Needs evaluation

A double free in the OpenSSL-based TLS certificate revocation checking path of the MongoDB C Driver can be reached by a TLS endpoint that the client already trusts. During the handshake, specially formed certificate data can cause...

1 affected package

mongo-c-driver

Package 26.04 LTS
mongo-c-driver Needs evaluation
Show less packages

CVE-2026-84963

Medium priority
Needs evaluation

An incorrect numeric conversion in the JSON parsing component of the MongoDB C Driver's BSON library may cause an unusually large text value to be silently shortened, or the corresponding field to be omitted, while the parsing...

1 affected package

mongo-c-driver

Package 26.04 LTS
mongo-c-driver Needs evaluation
Show less packages