Количество 45 010
Количество 45 010
CVE-2026-3202
NTS-KE protocol dissector crash in Wireshark 4.6.0 to 4.6.3 allows denial of service
CVE-2026-3201
USB HID protocol dissector memory exhaustion in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service
CVE-2026-3196
An integer overflow vulnerability was found in the virtio-snd device via PCM_INFO requests from the guest. A malicious guest can provide out-of-bounds stream counts, potentially leading to unbounded memory allocation on the host and a denial of service condition.
CVE-2026-31965
A flaw was found in HTSlib, a library for reading and writing bioinformatics file formats. This vulnerability, an out-of-bounds read, occurs in the `cram_decode_slice()` function when processing CRAM (Compressed Reference-oriented Alignment Map) records due to delayed validation of the reference ID field. A remote attacker could exploit this by providing a specially crafted CRAM file, potentially leading to the disclosure of two memory values or causing the program to crash, resulting in a Denial of Service (DoS).
CVE-2026-31964
A flaw was found in HTSlib, a library for reading and writing bioinformatics file formats. When processing specially crafted CRAM (Compressed Reference-aligned Alignment Map) data, specifically records that omit sequence or quality data using the CONST, XPACK, or XRLE encodings, the library attempts to write to a NULL pointer. This NULL pointer dereference can cause the program to crash, leading to a Denial of Service (DoS).
CVE-2026-31963
A flaw was found in HTSlib, a library for reading and writing bioinformatics file formats. When processing CRAM (Compressed Reference-oriented Alignment Map) files, an out-by-one error in feature decoding can cause a heap buffer overflow. This vulnerability allows an attacker to craft a malicious CRAM file which, when opened by a user, could lead to a program crash, data corruption, or potentially arbitrary code execution.
CVE-2026-31962
A flaw was found in htslib, a library for reading and writing bioinformatics file formats. A local user could exploit a heap buffer overflow vulnerability by opening a specially crafted CRAM file. This flaw occurs due to incorrect handling of certain CRAM format records, leading to reading and writing a single byte beyond a heap allocation. Successful exploitation could result in a program crash, data corruption, or potentially arbitrary code execution.
CVE-2026-3195
A flaw was found in QEMU. When reading input audio in the virtio-snd device input callback, the `virtio_snd_pcm_in_cb` function did not check whether the iov could fit the data buffer, potentially leading to a heap out-of-bounds write. This issue exists due to an incomplete fix for CVE-2024-7730.
CVE-2026-31958
A flaw was found in tornado-python. A remote attacker can exploit this vulnerability by sending a specially crafted, very large multipart body with numerous parts. Because the parsing of these large bodies occurs synchronously on the main thread, it can consume excessive resources, leading to a denial of service (DoS) for the application.
CVE-2026-31938
A flaw was found in jsPDF, a JavaScript library for generating PDFs. A remote attacker can exploit this vulnerability by providing malicious input to the `options` argument of the `output` function. When a victim creates and opens a PDF using this unsanitized input, arbitrary HTML, including scripts, can be injected and executed within the victim's browser context. This Cross-Site Scripting (XSS) vulnerability allows the attacker to extract or modify sensitive information from the victim's browser.
CVE-2026-3190
A flaw was found in Keycloak. The User-Managed Access (UMA) 2.0 Protection API endpoint for permission tickets fails to enforce the `uma_protection` role check. This allows any authenticated user with a token issued for a resource server client, even without the `uma_protection` role, to enumerate all permission tickets in the system. This vulnerability partial leads to information disclosure.
CVE-2026-31899
A flaw was found in CairoSVG, an SVG converter. A remote attacker could exploit this vulnerability by submitting a specially crafted SVG file that contains recursive `<use>` elements. This can lead to an exponential increase in processing time and CPU exhaustion, resulting in a Denial of Service (DoS) for the system.
CVE-2026-31898
A flaw was found in jsPDF, a JavaScript library used for generating PDF documents. This vulnerability allows a remote attacker to inject arbitrary PDF objects, including JavaScript actions, into a generated PDF. This can occur if unsanitized user input is provided to the `createAnnotation` method's `color` parameter. When a user opens or interacts with the specially crafted PDF, these injected actions may execute, potentially leading to arbitrary code execution or sensitive information disclosure.
CVE-2026-31897
An out of bounds read flaw has been discovered in FreeRDP. This Out-of-bounds read exists in the `freerdp_bitmap_decompress_planar` function when SrcSize is 0. This flaw may allow an attcker to read of 1 byte from heap memory in some situation. The more common and expected impact is a crash when the read hits an unmapped page.
CVE-2026-31892
A flaw was found in Argo Workflows. A user with privileges to submit workflows can bypass security settings defined in a WorkflowTemplate by including a `podSpecPatch` field in their workflow submission. This allows them to circumvent restrictions, even when `templateReferencing: Strict` is configured, potentially leading to unauthorized resource access or privilege escalation.
CVE-2026-31885
An out of bounds read flaw has been discovered in FreeRDP. This out-of-bounds read exists in the MS-ADPCM and IMA-ADPCM decoders due to unchecked predictor and step_index values from input data. An attacker may be able to leverage this weakness to leak global data.
CVE-2026-31884
A division by zero flaw has been discovered in FreeRDP. This division by zero exists in the MS-ADPCM and IMA-ADPCM decoders when nBlockAlign is 0, leading to a crash. In libfreerdp/codec/dsp.c, both ADPCM decoders use size % block_size where block_size = context->common.format.nBlockAlign. The nBlockAlign value comes from the Server Audio Formats PDU on the RDPSND channel. The value 0 is not validated anywhere before reaching the decoder. When nBlockAlign = 0, the modulo operation causes a SIGFPE (floating point exception) crash.
CVE-2026-31883
No description is available for this CVE.
CVE-2026-31870
A flaw was found in cpp-httplib. A remote attacker, acting as a malicious server or through a man-in-the-middle position, can send a specially crafted HTTP response with a malformed Content-Length header. This lack of input validation and exception handling causes the client application to crash, resulting in a Denial of Service (DoS).
CVE-2026-31853
A flaw was found in ImageMagick. An overflow on 32-bit systems in the SFW decoder can lead to a crash when processing extremely large images. This vulnerability could allow an attacker to cause a Denial of Service (DoS) by providing a specially crafted large image.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-3202 NTS-KE protocol dissector crash in Wireshark 4.6.0 to 4.6.3 allows denial of service | CVSS3: 5.5 | 0% Низкий | 30 дней назад | |
CVE-2026-3201 USB HID protocol dissector memory exhaustion in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service | CVSS3: 5.5 | 0% Низкий | 30 дней назад | |
CVE-2026-3196 An integer overflow vulnerability was found in the virtio-snd device via PCM_INFO requests from the guest. A malicious guest can provide out-of-bounds stream counts, potentially leading to unbounded memory allocation on the host and a denial of service condition. | CVSS3: 5.5 | около 1 месяца назад | ||
CVE-2026-31965 A flaw was found in HTSlib, a library for reading and writing bioinformatics file formats. This vulnerability, an out-of-bounds read, occurs in the `cram_decode_slice()` function when processing CRAM (Compressed Reference-oriented Alignment Map) records due to delayed validation of the reference ID field. A remote attacker could exploit this by providing a specially crafted CRAM file, potentially leading to the disclosure of two memory values or causing the program to crash, resulting in a Denial of Service (DoS). | CVSS3: 5.6 | 0% Низкий | 9 дней назад | |
CVE-2026-31964 A flaw was found in HTSlib, a library for reading and writing bioinformatics file formats. When processing specially crafted CRAM (Compressed Reference-aligned Alignment Map) data, specifically records that omit sequence or quality data using the CONST, XPACK, or XRLE encodings, the library attempts to write to a NULL pointer. This NULL pointer dereference can cause the program to crash, leading to a Denial of Service (DoS). | CVSS3: 5 | 0% Низкий | 9 дней назад | |
CVE-2026-31963 A flaw was found in HTSlib, a library for reading and writing bioinformatics file formats. When processing CRAM (Compressed Reference-oriented Alignment Map) files, an out-by-one error in feature decoding can cause a heap buffer overflow. This vulnerability allows an attacker to craft a malicious CRAM file which, when opened by a user, could lead to a program crash, data corruption, or potentially arbitrary code execution. | CVSS3: 7.3 | 0% Низкий | 9 дней назад | |
CVE-2026-31962 A flaw was found in htslib, a library for reading and writing bioinformatics file formats. A local user could exploit a heap buffer overflow vulnerability by opening a specially crafted CRAM file. This flaw occurs due to incorrect handling of certain CRAM format records, leading to reading and writing a single byte beyond a heap allocation. Successful exploitation could result in a program crash, data corruption, or potentially arbitrary code execution. | CVSS3: 7.3 | 0% Низкий | 9 дней назад | |
CVE-2026-3195 A flaw was found in QEMU. When reading input audio in the virtio-snd device input callback, the `virtio_snd_pcm_in_cb` function did not check whether the iov could fit the data buffer, potentially leading to a heap out-of-bounds write. This issue exists due to an incomplete fix for CVE-2024-7730. | CVSS3: 7.4 | около 1 месяца назад | ||
CVE-2026-31958 A flaw was found in tornado-python. A remote attacker can exploit this vulnerability by sending a specially crafted, very large multipart body with numerous parts. Because the parsing of these large bodies occurs synchronously on the main thread, it can consume excessive resources, leading to a denial of service (DoS) for the application. | CVSS3: 5.3 | 0% Низкий | 15 дней назад | |
CVE-2026-31938 A flaw was found in jsPDF, a JavaScript library for generating PDFs. A remote attacker can exploit this vulnerability by providing malicious input to the `options` argument of the `output` function. When a victim creates and opens a PDF using this unsanitized input, arbitrary HTML, including scripts, can be injected and executed within the victim's browser context. This Cross-Site Scripting (XSS) vulnerability allows the attacker to extract or modify sensitive information from the victim's browser. | CVSS3: 8.1 | 0% Низкий | 9 дней назад | |
CVE-2026-3190 A flaw was found in Keycloak. The User-Managed Access (UMA) 2.0 Protection API endpoint for permission tickets fails to enforce the `uma_protection` role check. This allows any authenticated user with a token issued for a resource server client, even without the `uma_protection` role, to enumerate all permission tickets in the system. This vulnerability partial leads to information disclosure. | CVSS3: 4.3 | 30 дней назад | ||
CVE-2026-31899 A flaw was found in CairoSVG, an SVG converter. A remote attacker could exploit this vulnerability by submitting a specially crafted SVG file that contains recursive `<use>` elements. This can lead to an exponential increase in processing time and CPU exhaustion, resulting in a Denial of Service (DoS) for the system. | CVSS3: 7.5 | 0% Низкий | 13 дней назад | |
CVE-2026-31898 A flaw was found in jsPDF, a JavaScript library used for generating PDF documents. This vulnerability allows a remote attacker to inject arbitrary PDF objects, including JavaScript actions, into a generated PDF. This can occur if unsanitized user input is provided to the `createAnnotation` method's `color` parameter. When a user opens or interacts with the specially crafted PDF, these injected actions may execute, potentially leading to arbitrary code execution or sensitive information disclosure. | CVSS3: 8.1 | 0% Низкий | 9 дней назад | |
CVE-2026-31897 An out of bounds read flaw has been discovered in FreeRDP. This Out-of-bounds read exists in the `freerdp_bitmap_decompress_planar` function when SrcSize is 0. This flaw may allow an attcker to read of 1 byte from heap memory in some situation. The more common and expected impact is a crash when the read hits an unmapped page. | CVSS3: 3.1 | 0% Низкий | 14 дней назад | |
CVE-2026-31892 A flaw was found in Argo Workflows. A user with privileges to submit workflows can bypass security settings defined in a WorkflowTemplate by including a `podSpecPatch` field in their workflow submission. This allows them to circumvent restrictions, even when `templateReferencing: Strict` is configured, potentially leading to unauthorized resource access or privilege escalation. | CVSS3: 9.9 | 0% Низкий | 16 дней назад | |
CVE-2026-31885 An out of bounds read flaw has been discovered in FreeRDP. This out-of-bounds read exists in the MS-ADPCM and IMA-ADPCM decoders due to unchecked predictor and step_index values from input data. An attacker may be able to leverage this weakness to leak global data. | CVSS3: 6.5 | 0% Низкий | 14 дней назад | |
CVE-2026-31884 A division by zero flaw has been discovered in FreeRDP. This division by zero exists in the MS-ADPCM and IMA-ADPCM decoders when nBlockAlign is 0, leading to a crash. In libfreerdp/codec/dsp.c, both ADPCM decoders use size % block_size where block_size = context->common.format.nBlockAlign. The nBlockAlign value comes from the Server Audio Formats PDU on the RDPSND channel. The value 0 is not validated anywhere before reaching the decoder. When nBlockAlign = 0, the modulo operation causes a SIGFPE (floating point exception) crash. | CVSS3: 6.5 | 0% Низкий | 14 дней назад | |
CVE-2026-31883 No description is available for this CVE. | 0% Низкий | 14 дней назад | ||
CVE-2026-31870 A flaw was found in cpp-httplib. A remote attacker, acting as a malicious server or through a man-in-the-middle position, can send a specially crafted HTTP response with a malformed Content-Length header. This lack of input validation and exception handling causes the client application to crash, resulting in a Denial of Service (DoS). | CVSS3: 7.5 | 0% Низкий | 16 дней назад | |
CVE-2026-31853 A flaw was found in ImageMagick. An overflow on 32-bit systems in the SFW decoder can lead to a crash when processing extremely large images. This vulnerability could allow an attacker to cause a Denial of Service (DoS) by providing a specially crafted large image. | CVSS3: 5.5 | 0% Низкий | 16 дней назад |
Уязвимостей на страницу