Search CVE reports


Toggle filters

681 – 690 of 56918 results

Status is adjusted based on your filters.


CVE-2026-33607

Medium priority
Needs evaluation

An attacker that has valid credentials can use IMAP LIST command to consume CPU. This can cause degradation or denial of service for IMAP. Monitor system for abnormal CPU usage and kill the offending process and lock account....

1 affected package

dovecot

Package 16.04 LTS
dovecot Needs evaluation
Show less packages

CVE-2026-33606

Medium priority
Needs evaluation

Mail content stored by a user can be crafted so that it is interpreted as dsync protocol commands when an administrator later runs dsync with the stream protocol, for example during a migration. Injected commands can modify...

1 affected package

dovecot

Package 16.04 LTS
dovecot Needs evaluation
Show less packages

CVE-2026-33605

Medium priority
Needs evaluation

An unauthenticated attacker can crash the ManageSieve login process by sending a small malformed command before authenticating. If running in high-security mode (default for community releases), only the attacker's own connection...

1 affected package

dovecot

Package 16.04 LTS
dovecot Needs evaluation
Show less packages

CVE-2026-33604

Medium priority
Needs evaluation

An attacker that can get Dovecot to relay a message, for example through Sieve redirect or submission relay, can use a crafted line ending in the message body to bypass the outbound protection that prevents message content from...

1 affected package

dovecot

Package 16.04 LTS
dovecot Needs evaluation
Show less packages

CVE-2026-33263

Medium priority
Needs evaluation

When mail_max_userip_connections is set (default 10) and reached, submission-login can crash with epoll() panic caused by file descriptor handling issues. If running in high-security mode (default for community releases), only the...

1 affected package

dovecot

Package 16.04 LTS
dovecot Needs evaluation
Show less packages

CVE-2026-27852

Medium priority
Needs evaluation

An attacker that can send mail to a user can craft a message whose headers contain a very large number of email addresses or MIME parameters, which causes excessive memory usage when the message is later parsed. The message is...

1 affected package

dovecot

Package 16.04 LTS
dovecot Needs evaluation
Show less packages

CVE-2026-81934

Medium priority
Needs evaluation

Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute...

1 affected package

redis

Package 16.04 LTS
redis Needs evaluation
Show less packages

CVE-2026-81893

Medium priority
Needs evaluation

A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG image containing chunked ICC profile markers, an error during ICC profile parsing can leave stale size metadata after the profile buffer is freed. A subsequent...

1 affected package

gdk-pixbuf

Package 16.04 LTS
gdk-pixbuf Needs evaluation
Show less packages

CVE-2026-81525

Medium priority
Needs evaluation

The MongoDB client library for PHP does not sufficiently sanitize special elements in application-supplied namespace identifiers before using them to construct the target namespace for database operations. An application...

1 affected package

php-mongodb

Package 16.04 LTS
php-mongodb Needs evaluation
Show less packages

CVE-2026-59314

Medium priority
Needs evaluation

Applications that build a Content-Disposition header value from untrusted input may be vulnerable to HTTP response splitting when the input is a malicious file name. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 -...

1 affected package

libspring-java

Package 16.04 LTS
libspring-java Needs evaluation
Show less packages