Search CVE reports


Toggle filters

41 – 50 of 44746 results

Status is adjusted based on your filters.


CVE-2026-13072

Medium priority

Not in release

When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline processing can result in memory corruption, potentially leading to...

1 affected package

mongodb

Package 22.04 LTS
mongodb Not in release
Show less packages

CVE-2026-13070

Medium priority

Not in release

A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP response from a remote peer during the TLS handshake. OCSP stapling validation is enabled by default for outgoing TLS...

1 affected package

mongodb

Package 22.04 LTS
mongodb Not in release
Show less packages

CVE-2026-13069

Medium priority

Not in release

An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by sending a crafted Queryable Encryption find payload containing an unvalidated field used to control an...

1 affected package

mongodb

Package 22.04 LTS
mongodb Not in release
Show less packages

CVE-2026-13057

Medium priority

Not in release

An issue in the server’s Atlas Search integration allows an authenticated user to bypass per-user access controls. In sharded topologies, the $search and $searchMeta aggregation stages use internal routing that is normally...

1 affected package

mongodb

Package 22.04 LTS
mongodb Not in release
Show less packages

CVE-2026-64835

Medium priority
Needs evaluation

FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted...

2 affected packages

ffmpeg, libav

Package 22.04 LTS
ffmpeg Needs evaluation
libav Not in release
Show less packages

CVE-2026-64834

Medium priority
Needs evaluation

FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service by sending a crafted RTP/ASF stream. The...

2 affected packages

ffmpeg, libav

Package 22.04 LTS
ffmpeg Needs evaluation
libav Not in release
Show less packages

CVE-2026-64833

Medium priority
Needs evaluation

FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger...

2 affected packages

ffmpeg, libav

Package 22.04 LTS
ffmpeg Needs evaluation
libav Not in release
Show less packages

CVE-2026-64832

Medium priority
Needs evaluation

FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no...

2 affected packages

ffmpeg, libav

Package 22.04 LTS
ffmpeg Needs evaluation
libav Not in release
Show less packages

CVE-2026-64831

Medium priority
Needs evaluation

FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses and adjacent stack frames by supplying a crafted...

2 affected packages

ffmpeg, libav

Package 22.04 LTS
ffmpeg Needs evaluation
libav Not in release
Show less packages

CVE-2026-64830

Medium priority
Needs evaluation

FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more...

2 affected packages

ffmpeg, libav

Package 22.04 LTS
ffmpeg Needs evaluation
libav Not in release
Show less packages