Количество 25 045
Количество 25 045
CVE-2026-34873
An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session.
CVE-2026-34872
An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory behavior in FFDH due to improper input validation. Using finite-field Diffie-Hellman, the other party can force the shared secret into a small set of values (lack of contributory behavior). This is a problem for protocols that depend on contributory behavior (which is not the case for TLS). The attack can be carried by the peer, or depending on the protocol by an active network attacker (person in the middle).
CVE-2026-34871
An issue was discovered in Mbed TLS before 3.6.6 and 4.x before 4.1.0 and TF-PSA-Crypto before 1.1.0. There is a Predictable Seed in a Pseudo-Random Number Generator (PRNG).
CVE-2026-3479
pkgutil.get_data() does not enforce documented restrictions
CVE-2026-34757
LIBPNG has a yse-after-free in png_set_PLTE, png_set_tRNS and png_set_hIST leading to corrupted chunk data and potential heap information disclosure
CVE-2026-34743
XZ Utils: Buffer overflow in lzma_index_append()
CVE-2026-34714
Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.
CVE-2026-34601
xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion
CVE-2026-34591
Poetry Has Wheel Path Traversal Which Can Lead to Arbitrary File Write
CVE-2026-34481
Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayout
CVE-2026-34480
Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters
CVE-2026-34479
Apache Log4j 1 to Log4j 2 bridge: Silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters
CVE-2026-34477
Apache Log4j Core: verifyHostName attribute silently ignored in TLS configuration, allowing hostname verification bypass
CVE-2026-34446
ONNX: Arbitrary File Read via ExternalData Hardlink Bypass in ONNX load
CVE-2026-34445
ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings.
CVE-2026-34356
Apache HTTP Server: ProxyPassReverseCookieMap buffer overflow
CVE-2026-34355
Apache HTTP Server: mod_proxy_html buffer overflow
CVE-2026-34353
In OCaml through 4.14.3, Bigarray.reshape allows an integer overflow, and resultant reading of arbitrary memory, when untrusted data is processed.
CVE-2026-34351
Windows TCP/IP Elevation of Privilege Vulnerability
CVE-2026-34350
Windows Storport Miniport Driver Denial of Service Vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-34873 An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session. | 0% Низкий | 3 месяца назад | ||
CVE-2026-34872 An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory behavior in FFDH due to improper input validation. Using finite-field Diffie-Hellman, the other party can force the shared secret into a small set of values (lack of contributory behavior). This is a problem for protocols that depend on contributory behavior (which is not the case for TLS). The attack can be carried by the peer, or depending on the protocol by an active network attacker (person in the middle). | 0% Низкий | 3 месяца назад | ||
CVE-2026-34871 An issue was discovered in Mbed TLS before 3.6.6 and 4.x before 4.1.0 and TF-PSA-Crypto before 1.1.0. There is a Predictable Seed in a Pseudo-Random Number Generator (PRNG). | 0% Низкий | 3 месяца назад | ||
CVE-2026-3479 pkgutil.get_data() does not enforce documented restrictions | 0% Низкий | 4 месяца назад | ||
CVE-2026-34757 LIBPNG has a yse-after-free in png_set_PLTE, png_set_tRNS and png_set_hIST leading to corrupted chunk data and potential heap information disclosure | CVSS3: 5.1 | 0% Низкий | 4 месяца назад | |
CVE-2026-34743 XZ Utils: Buffer overflow in lzma_index_append() | 0% Низкий | 4 месяца назад | ||
CVE-2026-34714 Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE. | CVSS3: 8.5 | 1% Низкий | 4 месяца назад | |
CVE-2026-34601 xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion | 0% Низкий | 4 месяца назад | ||
CVE-2026-34591 Poetry Has Wheel Path Traversal Which Can Lead to Arbitrary File Write | 0% Низкий | 3 месяца назад | ||
CVE-2026-34481 Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayout | 1% Низкий | 4 месяца назад | ||
CVE-2026-34480 Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters | 1% Низкий | 4 месяца назад | ||
CVE-2026-34479 Apache Log4j 1 to Log4j 2 bridge: Silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters | 1% Низкий | 4 месяца назад | ||
CVE-2026-34477 Apache Log4j Core: verifyHostName attribute silently ignored in TLS configuration, allowing hostname verification bypass | 0% Низкий | 4 месяца назад | ||
CVE-2026-34446 ONNX: Arbitrary File Read via ExternalData Hardlink Bypass in ONNX load | CVSS3: 4.7 | 0% Низкий | 4 месяца назад | |
CVE-2026-34445 ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings. | CVSS3: 8.6 | 0% Низкий | 4 месяца назад | |
CVE-2026-34356 Apache HTTP Server: ProxyPassReverseCookieMap buffer overflow | 1% Низкий | около 2 месяцев назад | ||
CVE-2026-34355 Apache HTTP Server: mod_proxy_html buffer overflow | 1% Низкий | около 2 месяцев назад | ||
CVE-2026-34353 In OCaml through 4.14.3, Bigarray.reshape allows an integer overflow, and resultant reading of arbitrary memory, when untrusted data is processed. | CVSS3: 5.9 | 0% Низкий | 4 месяца назад | |
CVE-2026-34351 Windows TCP/IP Elevation of Privilege Vulnerability | CVSS3: 7.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-34350 Windows Storport Miniport Driver Denial of Service Vulnerability | CVSS3: 6.5 | 1% Низкий | 3 месяца назад |
Уязвимостей на страницу