Количество 25 045
Количество 25 045
CVE-2026-37459
An integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.
CVE-2026-37458
Missing input validation in the MP_REACH_NLRI component of FRRouting (FRR) stable/10.0 to stable/10.6 allows authenticated attackers to cause a Denial of Service (DoS) via supplying a crafted UPDATE message.
CVE-2026-37457
An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component.
CVE-2026-3731
libssh SFTP Extension Name sftp.c sftp_extensions_get_data out-of-bounds
CVE-2026-3713
pnggroup libpng pnm2png pnm2png.c do_pnm2png heap-based overflow
CVE-2026-3644
Incomplete control character validation in http.cookies
CVE-2026-3634
Libsoup: libsoup: http header injection and response splitting via crlf injection in content-type header
CVE-2026-3633
Libsoup: libsoup: header and http request injection via crlf injection
CVE-2026-3632
Libsoup: libsoup: http smuggling and server-side request forgery via malformed hostnames
CVE-2026-3593
Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation
CVE-2026-3592
Amplification vulnerabilities via self-pointed glue records
CVE-2026-3591
A stack use-after-return flaw in SIG(0) handling code may enable ACL bypass
CVE-2026-3580
Compiler-induced timing leak in sp_256_get_entry_256_9 on RISC-V
CVE-2026-3579
Non-constant time multiplication subroutine __muldi3 on RISC-V RV32I
CVE-2026-35611
Addressable has a Regular Expression Denial of Service in Addressable templates
CVE-2026-35579
CoreDNS TSIG authentication bypass on gRPC, QUIC, DoH, and DoH3 transports
CVE-2026-35549
CVE-2026-35535
CVE-2026-3549
ECH parsing heap buffer overflow
CVE-2026-3548
Buffer overflow in CRL number parsing in wolfSSL
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-37459 An integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message. | 0% Низкий | 3 месяца назад | ||
CVE-2026-37458 Missing input validation in the MP_REACH_NLRI component of FRRouting (FRR) stable/10.0 to stable/10.6 allows authenticated attackers to cause a Denial of Service (DoS) via supplying a crafted UPDATE message. | 0% Низкий | 3 месяца назад | ||
CVE-2026-37457 An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component. | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-3731 libssh SFTP Extension Name sftp.c sftp_extensions_get_data out-of-bounds | CVSS3: 5.3 | 1% Низкий | 5 месяцев назад | |
CVE-2026-3713 pnggroup libpng pnm2png pnm2png.c do_pnm2png heap-based overflow | 0% Низкий | 5 месяцев назад | ||
CVE-2026-3644 Incomplete control character validation in http.cookies | 0% Низкий | 5 месяцев назад | ||
CVE-2026-3634 Libsoup: libsoup: http header injection and response splitting via crlf injection in content-type header | 0% Низкий | 5 месяцев назад | ||
CVE-2026-3633 Libsoup: libsoup: header and http request injection via crlf injection | 0% Низкий | 5 месяцев назад | ||
CVE-2026-3632 Libsoup: libsoup: http smuggling and server-side request forgery via malformed hostnames | 0% Низкий | 5 месяцев назад | ||
CVE-2026-3593 Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation | CVSS3: 7.4 | 2% Низкий | 3 месяца назад | |
CVE-2026-3592 Amplification vulnerabilities via self-pointed glue records | 0% Низкий | 3 месяца назад | ||
CVE-2026-3591 A stack use-after-return flaw in SIG(0) handling code may enable ACL bypass | CVSS3: 5.4 | 0% Низкий | 4 месяца назад | |
CVE-2026-3580 Compiler-induced timing leak in sp_256_get_entry_256_9 on RISC-V | 0% Низкий | 4 месяца назад | ||
CVE-2026-3579 Non-constant time multiplication subroutine __muldi3 on RISC-V RV32I | 0% Низкий | 4 месяца назад | ||
CVE-2026-35611 Addressable has a Regular Expression Denial of Service in Addressable templates | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-35579 CoreDNS TSIG authentication bypass on gRPC, QUIC, DoH, and DoH3 transports | 1% Низкий | 3 месяца назад | ||
0% Низкий | 4 месяца назад | |||
CVSS3: 7.4 | 0% Низкий | 4 месяца назад | ||
CVE-2026-3549 ECH parsing heap buffer overflow | 0% Низкий | 4 месяца назад | ||
CVE-2026-3548 Buffer overflow in CRL number parsing in wolfSSL | 0% Низкий | 4 месяца назад |
Уязвимостей на страницу