Количество 25 045
Количество 25 045
CVE-2026-50293
Windows Internal Task Bar Elevation of Privilege Vulnerability
CVE-2026-50292
In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution
CVE-2026-50265
Rejected reason: This CVE ID was assigned as a duplicate of CVE-2026-50292
CVE-2026-50263
Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free information disclosure in createsaverwindow()
CVE-2026-50262
Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: out-of-bounds read/write in glx changedrawableattributes
CVE-2026-50261
Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in syncchangecounter()
CVE-2026-50260
Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in freecounter()
CVE-2026-50259
Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in xkb setmap request via mapwidths indexing
CVE-2026-50258
Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in xkb key types due to unchecked shift levels
CVE-2026-50257
Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in misyncdestroyfence()
CVE-2026-50256
Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in font alias resolution due to libxfont2 name length mismatch
CVE-2026-50252
Possible cache poisoning attack by mapping source port population per thread
CVE-2026-50251
Attacker supplied '0.0.0.0'/'::' glue triggers defensive full-cache flush
CVE-2026-50248
BOGUS configured primary hostname accepted for XFR in auth/rpz zones
CVE-2026-50243
'response-ip'/'rpz' can rewrite BOGUS answers instead of returning SERVFAIL
CVE-2026-50219
libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,
CVE-2026-50046
Possible heap use-after-free in an error path when a DoT forwarded query is jostled out
CVE-2026-50045
'max-global-quota' reset by DNSSEC validation restarts
CVE-2026-50031
ipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented by a large number of hardware manufacturers to support system management. It is most commonly used for sensor reading (e.g., CPU temperatures through the ipmi-sensors command within FreeIPMI) and remote power control (the ipmipower command). The ipmi-oem client command implements a set of a IPMI OEM commands for specific hardware vendors. If a user has supported hardware, they may wish to use the ipmi-oem command to send a request to a server to retrieve specific information. Two subcommands "ipmi-oem dell get-active-directory-config" and "ipmi-oem fujitsu get-sel-entry-long-text" were found to have exploitable buffer overflows on response messages.
CVE-2026-50012
Squid: Memory corruption in cache_digest reply handling
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-50293 Windows Internal Task Bar Elevation of Privilege Vulnerability | CVSS3: 7.8 | 0% Низкий | 21 день назад | |
CVE-2026-50292 In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution | CVSS3: 7.4 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-50265 Rejected reason: This CVE ID was assigned as a duplicate of CVE-2026-50292 | около 2 месяцев назад | |||
CVE-2026-50263 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free information disclosure in createsaverwindow() | CVSS3: 5.5 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-50262 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: out-of-bounds read/write in glx changedrawableattributes | CVSS3: 5.5 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-50261 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in syncchangecounter() | CVSS3: 7.8 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-50260 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in freecounter() | CVSS3: 6.6 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-50259 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in xkb setmap request via mapwidths indexing | CVSS3: 7.8 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-50258 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in xkb key types due to unchecked shift levels | CVSS3: 7.8 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-50257 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in misyncdestroyfence() | CVSS3: 6.6 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-50256 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in font alias resolution due to libxfont2 name length mismatch | CVSS3: 7.8 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-50252 Possible cache poisoning attack by mapping source port population per thread | 0% Низкий | 13 дней назад | ||
CVE-2026-50251 Attacker supplied '0.0.0.0'/'::' glue triggers defensive full-cache flush | CVSS3: 5.3 | 0% Низкий | 13 дней назад | |
CVE-2026-50248 BOGUS configured primary hostname accepted for XFR in auth/rpz zones | CVSS3: 6.5 | 0% Низкий | 13 дней назад | |
CVE-2026-50243 'response-ip'/'rpz' can rewrite BOGUS answers instead of returning SERVFAIL | 0% Низкий | 13 дней назад | ||
CVE-2026-50219 libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur, | CVSS3: 4.9 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-50046 Possible heap use-after-free in an error path when a DoT forwarded query is jostled out | CVSS3: 5.9 | 0% Низкий | 13 дней назад | |
CVE-2026-50045 'max-global-quota' reset by DNSSEC validation restarts | CVSS3: 5.3 | 0% Низкий | 13 дней назад | |
CVE-2026-50031 ipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented by a large number of hardware manufacturers to support system management. It is most commonly used for sensor reading (e.g., CPU temperatures through the ipmi-sensors command within FreeIPMI) and remote power control (the ipmipower command). The ipmi-oem client command implements a set of a IPMI OEM commands for specific hardware vendors. If a user has supported hardware, they may wish to use the ipmi-oem command to send a request to a server to retrieve specific information. Two subcommands "ipmi-oem dell get-active-directory-config" and "ipmi-oem fujitsu get-sel-entry-long-text" were found to have exploitable buffer overflows on response messages. | CVSS3: 7.5 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-50012 Squid: Memory corruption in cache_digest reply handling | CVSS3: 5.5 | 1% Низкий | 18 дней назад |
Уязвимостей на страницу