Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 35

Количество 35

msrc логотип

CVE-2026-5928

3 месяца назад

Static buffer overflow in deprecated nis_local_principal

EPSS: Низкий
debian логотип

CVE-2026-5928

3 месяца назад

Calling the ungetwc function on a FILE stream with wide characters enc ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-6238

3 месяца назад

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory. These functions are for application debugging only and hence not in the path of code executed by the DNS resolver. Further, they have been deprecated since version 2.34 and should not be used by any new applications. Applications should consider porting away from these interfaces since they may be removed in future versions.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2026-6238

3 месяца назад

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory. These functions are for application debugging only and hence not in the path of code executed by the DNS resolver. Further, they have been deprecated since version 2.34 and should not be used by any new applications. Applications should consider porting away from these interfaces since they may be removed in future versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-6238

3 месяца назад

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory. These functions are for application debugging only and hence not in the path of code executed by the DNS resolver. Further, they have been deprecated since version 2.34 and should not be used by any new applications. Applications should consider porting away from these interfaces since they may be removed in future versions.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2026-6238

3 месяца назад

Buffer overread in ns_printrrf with corrupted RDATA field

EPSS: Низкий
debian логотип

CVE-2026-6238

3 месяца назад

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-829p-mc9m-7xhr

3 месяца назад

Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash. A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious ma...

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20260708-73-0038

23 дня назад

Уязвимость glibc

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-h8wx-jcwq-g3cp

3 месяца назад

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to validate the RDATA content against the RDATA length in a DNS response when processing LOC, CERT, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory. These functions are for application debugging only and hence not in the path of code executed by the DNS resolver. Further, they have been deprecated since version 2.34 and should not be used by any new applications. Applications should consider porting away from these interfaces since they may be removed in future versions.

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2026-10480

3 месяца назад

Уязвимость функции ns_printrrf, ns_printrr и fp_nquery системной библиотеки GNU C Library, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 6.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20764-1

2 месяца назад

Security update for glibc

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2440-1

около 1 месяца назад

Security update for glibc

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2333-1

около 2 месяцев назад

Security update for glibc

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2231-1

около 2 месяцев назад

Security update for glibc

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVE-2026-5928

Static buffer overflow in deprecated nis_local_principal

0%
Низкий
3 месяца назад
debian логотип
CVE-2026-5928

Calling the ungetwc function on a FILE stream with wide characters enc ...

CVSS3: 7.5
0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-6238

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory. These functions are for application debugging only and hence not in the path of code executed by the DNS resolver. Further, they have been deprecated since version 2.34 and should not be used by any new applications. Applications should consider porting away from these interfaces since they may be removed in future versions.

CVSS3: 6.5
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-6238

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory. These functions are for application debugging only and hence not in the path of code executed by the DNS resolver. Further, they have been deprecated since version 2.34 and should not be used by any new applications. Applications should consider porting away from these interfaces since they may be removed in future versions.

CVSS3: 6.5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-6238

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory. These functions are for application debugging only and hence not in the path of code executed by the DNS resolver. Further, they have been deprecated since version 2.34 and should not be used by any new applications. Applications should consider porting away from these interfaces since they may be removed in future versions.

CVSS3: 6.5
0%
Низкий
3 месяца назад
msrc логотип
CVE-2026-6238

Buffer overread in ns_printrrf with corrupted RDATA field

0%
Низкий
3 месяца назад
debian логотип
CVE-2026-6238

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the ...

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-829p-mc9m-7xhr

Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash. A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious ma...

CVSS3: 7.5
0%
Низкий
3 месяца назад
redos логотип
ROS-20260708-73-0038

Уязвимость glibc

CVSS3: 6.5
0%
Низкий
23 дня назад
github логотип
GHSA-h8wx-jcwq-g3cp

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to validate the RDATA content against the RDATA length in a DNS response when processing LOC, CERT, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory. These functions are for application debugging only and hence not in the path of code executed by the DNS resolver. Further, they have been deprecated since version 2.34 and should not be used by any new applications. Applications should consider porting away from these interfaces since they may be removed in future versions.

CVSS3: 6.5
0%
Низкий
3 месяца назад
fstec логотип
BDU:2026-10480

Уязвимость функции ns_printrrf, ns_printrr и fp_nquery системной библиотеки GNU C Library, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 6.5
0%
Низкий
3 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20764-1

Security update for glibc

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2440-1

Security update for glibc

около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2333-1

Security update for glibc

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:2231-1

Security update for glibc

около 2 месяцев назад

Уязвимостей на страницу