---
title: "CVEs\n  \n\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/cves?format=md
keywords: index, follow
---

# Search CVE reports

CVE ID or description contains:

Search

---

[Toggle filters](https://ubuntu.com/security/cves?format=md#drawer)

1
–
10
of
77186 results

Detailed view

Sort by:

Date
Newest
Oldest

---

## [CVE-2026-84642](https://ubuntu.com/security/CVE-2026-84642)

Medium priority

Needs evaluation

(The values of the mail.allowed\_attachment\_hostnames advanced config se
...)

1 affected package

thunderbird

---

## [CVE-2026-84641](https://ubuntu.com/security/CVE-2026-84641)

Medium priority

Needs evaluation

(A malicious IMAP server can trigger use-after-free and heap-memory dis
...)

1 affected package

thunderbird

---

## [CVE-2026-84640](https://ubuntu.com/security/CVE-2026-84640)

Medium priority

Needs evaluation

(A maliciously constructed mail header could lead to a one byte read pa
...)

1 affected package

thunderbird

---

## [CVE-2026-84639](https://ubuntu.com/security/CVE-2026-84639)

Medium priority

Needs evaluation

(Triggering an error condition in certain MIME bodies would cause unini
...)

1 affected package

thunderbird

---

## [CVE-2026-84637](https://ubuntu.com/security/CVE-2026-84637)

Medium priority

Needs evaluation

(Malicious calendar invitations could use file URI attachments to launc
...)

1 affected package

thunderbird

---

## [CVE-2026-84441](https://ubuntu.com/security/CVE-2026-84441)

Medium priority

(A security vulnerability has been detected in Piwigo up to 16.3.0. Aff
...)

0 affected package

---

## [CVE-2026-84375](https://ubuntu.com/security/CVE-2026-84375)

Medium priority

Needs evaluation

(js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15.
...)

1 affected package

node-js-yaml

---

## [CVE-2026-84372](https://ubuntu.com/security/CVE-2026-84372)

Medium priority

Needs evaluation

(Predis is a flexible and feature-complete Redis and Valkey client for ...)

1 affected package

php-nrk-predis

---

## [CVE-2026-84366](https://ubuntu.com/security/CVE-2026-84366)

Medium priority

Needs evaluation

(Scrapy is a high-level web crawling and scraping framework for Python.
...)

11 affected packages

python2.7,
python3.4,
python3.5,
python3.6,
python3.7...

---

## [CVE-2026-84361](https://ubuntu.com/security/CVE-2026-84361)

Medium priority

Needs evaluation

(Composer is a dependency Manager for the PHP language. From 1.0 until ...)

7 affected packages

php5,
php7.0,
php7.2,
php7.4,
php8.1...

1. *Previous page*
2. [1](https://ubuntu.com/security/cves?format=md&offset=0)
3. [2](https://ubuntu.com/security/cves?format=md&offset=10)
4. [3](https://ubuntu.com/security/cves?format=md&offset=20)
5. [4](https://ubuntu.com/security/cves?format=md&offset=30)
6. [5](https://ubuntu.com/security/cves?format=md&offset=40)
7. [*Next page*](https://ubuntu.com/security/cves?format=md&offset=10 "Next page")

[Export to JSON](https://ubuntu.com/security/cves?format=md)

Results by page:

10
20
