Search CVE reports


Toggle filters

391 – 400 of 36894 results

Status is adjusted based on your filters.


CVE-2026-79604

Medium priority
Needs evaluation

oxenstored: Unbounded accumulation of watches: Oxenstored maintains two datastructures about watches; one global trie, and one hashtable tracked per domain. When a xenbus reconnect is requested, watches are not cleared out of the...

1 affected package

xen

Package 26.04 LTS
xen Needs evaluation
Show less packages

CVE-2026-79603

Medium priority
Needs evaluation

x86 PV guests can free memory pages while still keeping a stale TLB entry pointing to them. A TLB flush is only issued by Xen (if needed) when the page is re-used. Since it's possible for the page to be scrubbed ahead of the TLB...

1 affected package

xen

Package 26.04 LTS
xen Needs evaluation
Show less packages

CVE-2026-79602

Medium priority
Needs evaluation

improper handling of HVM emulation return codes: A guest with a PCI device assigned that has at least a BAR on the IO port space can trigger a BUG() in Xen. A guest with a PCI device assigned that has at least a BAR on the IO port...

1 affected package

xen

Package 26.04 LTS
xen Needs evaluation
Show less packages

CVE-2026-62437

Medium priority
Needs evaluation

When guests are terminated, various pieces of cleanup need carrying out. The cleaning up of PCI devices which were assigned to guests, and the associated removal of tracking structures for IRQs used by the devices occurs...

1 affected package

xen

Package 26.04 LTS
xen Needs evaluation
Show less packages

CVE-2026-71328

Medium priority
Not affected

Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.

4 affected packages

dotnet6, dotnet7, dotnet8, dotnet10

Package 26.04 LTS
dotnet6 Not in release
dotnet7 Not in release
dotnet8 Not in release
dotnet10 Not affected
Show less packages

CVE-2026-69806

Medium priority
Fixed

Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally.

4 affected packages

dotnet6, dotnet7, dotnet8, dotnet10

Package 26.04 LTS
dotnet6 Not in release
dotnet7 Not in release
dotnet8 Not in release
dotnet10 Fixed
Show less packages

CVE-2026-69522

Medium priority
Not affected

This attack requires a user to open a specially crafted file from the attacker to initiate remote code execution.

4 affected packages

dotnet6, dotnet7, dotnet8, dotnet10

Package 26.04 LTS
dotnet6 Not in release
dotnet7 Not in release
dotnet8 Not in release
dotnet10 Not affected
Show less packages

CVE-2026-69439

Medium priority
Not affected

Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to elevate privileges over a network.

4 affected packages

dotnet6, dotnet7, dotnet8, dotnet10

Package 26.04 LTS
dotnet6 Not in release
dotnet7 Not in release
dotnet8 Not in release
dotnet10 Not affected
Show less packages

CVE-2026-69304

Medium priority
Not affected

Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network.

4 affected packages

dotnet6, dotnet7, dotnet8, dotnet10

Package 26.04 LTS
dotnet6 Not in release
dotnet7 Not in release
dotnet8 Not in release
dotnet10 Not affected
Show less packages

CVE-2026-58649

Medium priority
Vulnerable

Origin validation error in .NET allows an unauthorized attacker to disclose information over a network.

4 affected packages

dotnet6, dotnet7, dotnet8, dotnet10

Package 26.04 LTS
dotnet6 Not in release
dotnet7 Not in release
dotnet8 Not in release
dotnet10 Vulnerable
Show less packages