Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 79 713

Количество 79 713

ubuntu логотип

CVE-2026-19668

4 дня назад

(A BIND recursive resolver may experience excessive resource consumptio ...)

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2026-19667

4 дня назад

(If an attacker-controlled authoritative server can produce a negative ...)

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-19666

4 дня назад

(On a resolver configured to use ``dns64``, if an applicable answer fro ...)

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-19662

4 дня назад

(An attacker may be able to cause a `named` resolver to abort. The atta ...)

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2026-1965

6 месяцев назад

libcurl can in some circumstances reuse the wrong connection when asked to do an Negotiate-authenticated HTTP or HTTPS request. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection a range of criterion must first be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different credentials. One underlying reason being that Negotiate sometimes authenticates *connections* and not *requests*, contrary to how HTTP is designed to work. An application that allows Negotiate authentication to a server (that responds wanting Negotiate) with `user1:password1` and then does another operation to the same server also using Negotiate but with `user2:password2` (while the previous connection is still alive) - the second request wrongly reused the same connection and since it t...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2026-19654

около 1 месяца назад

A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp and the default imptcp framing modes are not affected.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-19624

6 дней назад

A flaw was found in NetworkManager-l2tp. The plugin writes attacker-controlled VPN connection properties (vpn.data and vpn.secrets values) unescaped into a generated ipsec.conf file that pluto loads as root. A local unprivileged user can create and activate their own L2TP VPN profile containing a newline-injected leftupdown directive; pluto executes that command as root when the IKE security association is established, resulting in local privilege escalation. This is the same bug class as CVE-2018-10900 (NetworkManager-vpnc).

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2026-19617

около 1 месяца назад

A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration with deeply nested structures. This could lead to uncontrolled recursion in the libdm configuration file parser, exhausting the stack and causing any LVM command reading the metadata to crash. This vulnerability results in a Denial of Service (DoS) for affected systems.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2026-19614

13 дней назад

The API is prone to XML external entity (XXE) injection. By default, XML external entity support is enabled. This issue affects NanoXML: 2.2.3.

EPSS: Низкий
ubuntu логотип

CVE-2026-19607

4 дня назад

(A flaw was found in the first-broker-login flow of the keycloak-servic ...)

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2026-19588

около 1 месяца назад

Integer Overflow to Buffer Overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2026-19587

около 1 месяца назад

Uncontrolled Resource Consumption vulnerability in Samsung Open Source rlottie allows Excessive Allocation.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2026-19582

около 1 месяца назад

Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is false due to upstream security policy.

EPSS: Низкий
ubuntu логотип

CVE-2026-19566

около 1 месяца назад

Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion and malformed set ranges via unbounded IPv6 prefix lengths. The _encode method accepts any prefix length matching `(0|[1-9][0-9]*)` and passes it to _width2bits(), which builds the mask as `'1' x ($width + 8)`, one character per bit. The _inc() method then unpacks the packed mask into a Perl array of one scalar per byte, so the prefix length alone sets the allocation size: `::/100000000` builds a 100 MB string and a 12.5 million element array. The value being tested is parsed, not just the configured ranges: contains() builds a set from its argument, and _guess_coder() tries the IPv4 coder and then the IPv6 coder, so an IPv4-only set expands an oversized IPv6 prefix length before the mixed address width check rejects it. Any caller that passes untrusted input to contains() or add() can exhaust process memory. A prefix length above 128 is also stored as a range that does not match the requested block: 2001:db8::/129...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-19560

около 1 месяца назад

Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2026-19559

около 1 месяца назад

Use after free in HTML in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2026-19558

около 1 месяца назад

Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: High)

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-19557

около 1 месяца назад

Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.3
EPSS: Низкий
ubuntu логотип

CVE-2026-19556

около 1 месяца назад

Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2026-19550

около 1 месяца назад

A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rather than a trust-administration permission, allowing an authenticated, non-privileged IPA user to trigger a privileged Active Directory trust refresh using an attacker-supplied server and credentials, resulting in unauthorized, attacker-controlled modification of trusted-domain and ID-range identity data in the IPA LDAP directory.

CVSS3: 8.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-19668

(A BIND recursive resolver may experience excessive resource consumptio ...)

CVSS3: 5.3
0%
Низкий
4 дня назад
ubuntu логотип
CVE-2026-19667

(If an attacker-controlled authoritative server can produce a negative ...)

CVSS3: 7.5
0%
Низкий
4 дня назад
ubuntu логотип
CVE-2026-19666

(On a resolver configured to use ``dns64``, if an applicable answer fro ...)

CVSS3: 7.5
0%
Низкий
4 дня назад
ubuntu логотип
CVE-2026-19662

(An attacker may be able to cause a `named` resolver to abort. The atta ...)

CVSS3: 5.9
0%
Низкий
4 дня назад
ubuntu логотип
CVE-2026-1965

libcurl can in some circumstances reuse the wrong connection when asked to do an Negotiate-authenticated HTTP or HTTPS request. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection a range of criterion must first be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different credentials. One underlying reason being that Negotiate sometimes authenticates *connections* and not *requests*, contrary to how HTTP is designed to work. An application that allows Negotiate authentication to a server (that responds wanting Negotiate) with `user1:password1` and then does another operation to the same server also using Negotiate but with `user2:password2` (while the previous connection is still alive) - the second request wrongly reused the same connection and since it t...

CVSS3: 6.5
0%
Низкий
6 месяцев назад
ubuntu логотип
CVE-2026-19654

A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp and the default imptcp framing modes are not affected.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
ubuntu логотип
CVE-2026-19624

A flaw was found in NetworkManager-l2tp. The plugin writes attacker-controlled VPN connection properties (vpn.data and vpn.secrets values) unescaped into a generated ipsec.conf file that pluto loads as root. A local unprivileged user can create and activate their own L2TP VPN profile containing a newline-injected leftupdown directive; pluto executes that command as root when the IKE security association is established, resulting in local privilege escalation. This is the same bug class as CVE-2018-10900 (NetworkManager-vpnc).

CVSS3: 7.8
0%
Низкий
6 дней назад
ubuntu логотип
CVE-2026-19617

A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration with deeply nested structures. This could lead to uncontrolled recursion in the libdm configuration file parser, exhausting the stack and causing any LVM command reading the metadata to crash. This vulnerability results in a Denial of Service (DoS) for affected systems.

CVSS3: 5.5
0%
Низкий
около 1 месяца назад
ubuntu логотип
CVE-2026-19614

The API is prone to XML external entity (XXE) injection. By default, XML external entity support is enabled. This issue affects NanoXML: 2.2.3.

0%
Низкий
13 дней назад
ubuntu логотип
CVE-2026-19607

(A flaw was found in the first-broker-login flow of the keycloak-servic ...)

CVSS3: 5.3
1%
Низкий
4 дня назад
ubuntu логотип
CVE-2026-19588

Integer Overflow to Buffer Overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
ubuntu логотип
CVE-2026-19587

Uncontrolled Resource Consumption vulnerability in Samsung Open Source rlottie allows Excessive Allocation.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
ubuntu логотип
CVE-2026-19582

Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is false due to upstream security policy.

около 1 месяца назад
ubuntu логотип
CVE-2026-19566

Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion and malformed set ranges via unbounded IPv6 prefix lengths. The _encode method accepts any prefix length matching `(0|[1-9][0-9]*)` and passes it to _width2bits(), which builds the mask as `'1' x ($width + 8)`, one character per bit. The _inc() method then unpacks the packed mask into a Perl array of one scalar per byte, so the prefix length alone sets the allocation size: `::/100000000` builds a 100 MB string and a 12.5 million element array. The value being tested is parsed, not just the configured ranges: contains() builds a set from its argument, and _guess_coder() tries the IPv4 coder and then the IPv6 coder, so an IPv4-only set expands an oversized IPv6 prefix length before the mixed address width check rejects it. Any caller that passes untrusted input to contains() or add() can exhaust process memory. A prefix length above 128 is also stored as a range that does not match the requested block: 2001:db8::/129...

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
ubuntu логотип
CVE-2026-19560

Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
0%
Низкий
около 1 месяца назад
ubuntu логотип
CVE-2026-19559

Use after free in HTML in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
0%
Низкий
около 1 месяца назад
ubuntu логотип
CVE-2026-19558

Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: High)

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
ubuntu логотип
CVE-2026-19557

Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.3
0%
Низкий
около 1 месяца назад
ubuntu логотип
CVE-2026-19556

Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
0%
Низкий
около 1 месяца назад
ubuntu логотип
CVE-2026-19550

A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rather than a trust-administration permission, allowing an authenticated, non-privileged IPA user to trigger a privileged Active Directory trust refresh using an attacker-supplied server and credentials, resulting in unauthorized, attacker-controlled modification of trusted-domain and ID-range identity data in the IPA LDAP directory.

CVSS3: 8.2
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу