Количество 25 045
Количество 25 045
CVE-2026-35238
CVE-2026-35237
CVE-2026-35236
CVE-2026-35206
Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment
CVE-2026-35201
Discount has an Out-of-bounds Read in rdiscount
CVE-2026-35199
SymCrypt SymCryptXmssSign function - Heap overflow via 64->32-bit leaf-count truncation
CVE-2026-35177
Path traversal issue with zip.vim in Vim
CVE-2026-35093
Libinput: libinput: unauthorized code execution and information disclosure through lua bytecode plugins
CVE-2026-3503
Fault injection attack with ML-DSA and ML-KEM on ARM
CVE-2026-34990
OpenPrinting CUPS: Local print admin token disclosure using temporary printers
CVE-2026-34982
Vim modeline bypass via various options affects Vim < 9.2.0276
CVE-2026-34980
OpenPrinting CUPS: Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network
CVE-2026-34979
OpenPrinting CUPS: Heap overflow in `get_options()`
CVE-2026-34978
OpenPrinting CUPS: Path traversal in RSS notify-recipient-uri enables file write outside CacheDir/rss (and clobbering of job.cache)
CVE-2026-34956
Openvswitch: open vswitch: denial of service via malformed ftp epasv command
CVE-2026-3494
MariaDB Server Audit Plugin Comment Handling Bypass
CVE-2026-34933
Avahi: Reachable assertion in `transport_flags_from_domain()` via conflicting publish flags crashes avahi-daemon
CVE-2026-34876
An issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls_ccm_finish() in library/ccm.c allows attackers to obtain adjacent CCM context data via invocation of the multipart CCM API with an oversized tag_len parameter. This is caused by missing validation of the tag_len parameter against the size of the internal 16-byte authentication buffer. The issue affects the public multipart CCM API in Mbed TLS 3.x, where mbedtls_ccm_finish() can be invoked directly by applications. In Mbed TLS 4.x versions prior to the fix, the same missing validation exists in the internal implementation; however, the function is not exposed as part of the public API. Exploitation requires application-level invocation of the multipart CCM API.
CVE-2026-34875
An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys.
CVE-2026-34874
An issue was discovered in Mbed TLS through 3.6.5 and 4.x through 4.0.0. There is a NULL pointer dereference in distinguished name parsing that allows an attacker to write to address 0.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVSS3: 4.9 | 0% Низкий | 4 месяца назад | ||
CVSS3: 4.9 | 0% Низкий | 4 месяца назад | ||
CVSS3: 4.9 | 0% Низкий | 4 месяца назад | ||
CVE-2026-35206 Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment | 0% Низкий | 4 месяца назад | ||
CVE-2026-35201 Discount has an Out-of-bounds Read in rdiscount | CVSS3: 5.9 | 0% Низкий | 4 месяца назад | |
CVE-2026-35199 SymCrypt SymCryptXmssSign function - Heap overflow via 64->32-bit leaf-count truncation | 0% Низкий | 4 месяца назад | ||
CVE-2026-35177 Path traversal issue with zip.vim in Vim | CVSS3: 4.1 | 0% Низкий | 4 месяца назад | |
CVE-2026-35093 Libinput: libinput: unauthorized code execution and information disclosure through lua bytecode plugins | 0% Низкий | 4 месяца назад | ||
CVE-2026-3503 Fault injection attack with ML-DSA and ML-KEM on ARM | 0% Низкий | 4 месяца назад | ||
CVE-2026-34990 OpenPrinting CUPS: Local print admin token disclosure using temporary printers | 0% Низкий | 4 месяца назад | ||
CVE-2026-34982 Vim modeline bypass via various options affects Vim < 9.2.0276 | CVSS3: 8.2 | 0% Низкий | 4 месяца назад | |
CVE-2026-34980 OpenPrinting CUPS: Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network | 1% Низкий | 4 месяца назад | ||
CVE-2026-34979 OpenPrinting CUPS: Heap overflow in `get_options()` | CVSS3: 5.3 | 0% Низкий | 4 месяца назад | |
CVE-2026-34978 OpenPrinting CUPS: Path traversal in RSS notify-recipient-uri enables file write outside CacheDir/rss (and clobbering of job.cache) | CVSS3: 6.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-34956 Openvswitch: open vswitch: denial of service via malformed ftp epasv command | CVSS3: 5.9 | 0% Низкий | 3 месяца назад | |
CVE-2026-3494 MariaDB Server Audit Plugin Comment Handling Bypass | CVSS3: 4.3 | 0% Низкий | 5 месяцев назад | |
CVE-2026-34933 Avahi: Reachable assertion in `transport_flags_from_domain()` via conflicting publish flags crashes avahi-daemon | CVSS3: 5.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-34876 An issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls_ccm_finish() in library/ccm.c allows attackers to obtain adjacent CCM context data via invocation of the multipart CCM API with an oversized tag_len parameter. This is caused by missing validation of the tag_len parameter against the size of the internal 16-byte authentication buffer. The issue affects the public multipart CCM API in Mbed TLS 3.x, where mbedtls_ccm_finish() can be invoked directly by applications. In Mbed TLS 4.x versions prior to the fix, the same missing validation exists in the internal implementation; however, the function is not exposed as part of the public API. Exploitation requires application-level invocation of the multipart CCM API. | 0% Низкий | 3 месяца назад | ||
CVE-2026-34875 An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys. | 0% Низкий | 3 месяца назад | ||
CVE-2026-34874 An issue was discovered in Mbed TLS through 3.6.5 and 4.x through 4.0.0. There is a NULL pointer dereference in distinguished name parsing that allows an attacker to write to address 0. | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу