Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 57 154

Количество 57 154

redhat логотип

CVE-2026-76956

29 дней назад

In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2026-76928

29 дней назад

X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2026-76927

29 дней назад

H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2026-76925

30 дней назад

A flaw was found in Flatpak. A Time-of-check to time-of-use (TOCTOU) race condition exists in the `org.freedesktop.Flatpak.SystemHelper` component. This vulnerability occurs because a privileged `chmod` operation executes before the OSTree repository validation within the `Deploy()` function. An attacker can exploit this timing window to redirect symlinks to arbitrary files, potentially leading to unauthorized file manipulation or information disclosure.

CVSS3: 5.8
EPSS: Низкий
redhat логотип

CVE-2026-76924

29 дней назад

Kerberos protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2026-76923

29 дней назад

Bluetooth HFP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2026-76922

29 дней назад

Bluetooth BR/EDR FHS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2026-76920

29 дней назад

3gpp phone log file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 4.7
EPSS: Низкий
redhat логотип

CVE-2026-76919

29 дней назад

ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2026-76918

29 дней назад

SSH protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2026-76917

29 дней назад

Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2026-76905

27 дней назад

kin-openapi is a Go project for handling OpenAPI files. From 0.10.0 until 0.141.0, openapi3filter.convertParseError in openapi3filter/validation_error_encoder.go dereferences e.Parameter.In without checking whether e.Parameter is nil. A malformed non-string scalar field in a multipart/form-data request body produces a nested ParseError with a nil RequestError.Parameter, and applications that render the validation error through openapi3filter.ConvertErrors or ValidationErrorEncoder panic. An unauthenticated client can repeatedly send such requests to deny service when the application lacks a recovery boundary. JSON request bodies and applications that do not use these error-rendering helpers are not affected. This issue is fixed in version 0.141.0.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2026-76891

29 дней назад

Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 3.1
EPSS: Низкий
redhat логотип

CVE-2026-76889

29 дней назад

UMTS FP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 4.7
EPSS: Низкий
redhat логотип

CVE-2026-76888

29 дней назад

RDP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 3.1
EPSS: Низкий
redhat логотип

CVE-2026-76887

29 дней назад

Crash in the Wireshark dissection engine in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 3.1
EPSS: Низкий
redhat логотип

CVE-2026-76886

29 дней назад

C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2026-76885

29 дней назад

Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 3.1
EPSS: Низкий
redhat логотип

CVE-2026-76884

29 дней назад

ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2026-76883

29 дней назад

Catapult DCT2000 file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 4.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-76956

In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content.

CVSS3: 5.9
0%
Низкий
29 дней назад
redhat логотип
CVE-2026-76928

X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 6.5
0%
Низкий
29 дней назад
redhat логотип
CVE-2026-76927

H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 6.5
0%
Низкий
29 дней назад
redhat логотип
CVE-2026-76925

A flaw was found in Flatpak. A Time-of-check to time-of-use (TOCTOU) race condition exists in the `org.freedesktop.Flatpak.SystemHelper` component. This vulnerability occurs because a privileged `chmod` operation executes before the OSTree repository validation within the `Deploy()` function. An attacker can exploit this timing window to redirect symlinks to arbitrary files, potentially leading to unauthorized file manipulation or information disclosure.

CVSS3: 5.8
0%
Низкий
30 дней назад
redhat логотип
CVE-2026-76924

Kerberos protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 5.5
0%
Низкий
29 дней назад
redhat логотип
CVE-2026-76923

Bluetooth HFP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 5.5
0%
Низкий
29 дней назад
redhat логотип
CVE-2026-76922

Bluetooth BR/EDR FHS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 5.5
0%
Низкий
29 дней назад
redhat логотип
CVE-2026-76920

3gpp phone log file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 4.7
0%
Низкий
29 дней назад
redhat логотип
CVE-2026-76919

ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 6.5
0%
Низкий
29 дней назад
redhat логотип
CVE-2026-76918

SSH protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 5.5
0%
Низкий
29 дней назад
redhat логотип
CVE-2026-76917

Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 5.5
0%
Низкий
29 дней назад
redhat логотип
CVE-2026-76905

kin-openapi is a Go project for handling OpenAPI files. From 0.10.0 until 0.141.0, openapi3filter.convertParseError in openapi3filter/validation_error_encoder.go dereferences e.Parameter.In without checking whether e.Parameter is nil. A malformed non-string scalar field in a multipart/form-data request body produces a nested ParseError with a nil RequestError.Parameter, and applications that render the validation error through openapi3filter.ConvertErrors or ValidationErrorEncoder panic. An unauthenticated client can repeatedly send such requests to deny service when the application lacks a recovery boundary. JSON request bodies and applications that do not use these error-rendering helpers are not affected. This issue is fixed in version 0.141.0.

CVSS3: 5.3
0%
Низкий
27 дней назад
redhat логотип
CVE-2026-76891

Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 3.1
0%
Низкий
29 дней назад
redhat логотип
CVE-2026-76889

UMTS FP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 4.7
0%
Низкий
29 дней назад
redhat логотип
CVE-2026-76888

RDP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 3.1
0%
Низкий
29 дней назад
redhat логотип
CVE-2026-76887

Crash in the Wireshark dissection engine in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 3.1
0%
Низкий
29 дней назад
redhat логотип
CVE-2026-76886

C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 5.3
0%
Низкий
29 дней назад
redhat логотип
CVE-2026-76885

Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 3.1
0%
Низкий
29 дней назад
redhat логотип
CVE-2026-76884

ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 3.3
0%
Низкий
29 дней назад
redhat логотип
CVE-2026-76883

Catapult DCT2000 file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 4.7
0%
Низкий
29 дней назад

Уязвимостей на страницу