Количество 75 967
Количество 75 967
CVE-2026-76887
Crash in the Wireshark dissection engine in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-76886
C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-76885
Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-76884
ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-76883
Catapult DCT2000 file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-76882
Bluetooth Attribute Protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-76881
CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-76880
RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-76879
C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-76878
In OpenStack Aodh before 22.0.1, the alarm list API bypasses project scoping when the all_projects query parameter is set to false. The API checks for the presence of the all_projects key rather than its value; a true value enforces the administrator-only policy, but a false value removes the key and skips the branch that normally restricts results to the caller's project. A non-admin user with the reader role can list alarms from all projects, exposing alarm actions containing trust webhook URLs, Heat signal endpoints, project IDs, and user IDs. The parameter can also be combined with a foreign project_id to target a specific project's alarms. A related concern is that OpenStack Watcher does not apply authorization to its webhook trigger endpoint. Any authenticated user who learns an audit's webhook URL, for example from this leaked Aodh alarm metadata, can start an EVENT audit and its associated action plan regardless of their own project or role. The webhook endpoint has lacked p...
CVE-2026-7666
An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.core.mail.backends.smtp.EmailBackend` in Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake when `fail_silently=True`, which allows on-path network attackers to read email content via cleartext interception. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Kasper Dupont for reporting this issue.
CVE-2026-76641
(Expat through 2.8.3 contains an out-of-bounds read vulnerability that ...)
CVE-2026-76235
(A memory leak flaw was found in cockpit-ws. The login page handler lea ...)
CVE-2026-76222
(GitPython before 3.1.58 fails to validate submodule names from .gitmod ...)
CVE-2026-76221
(GitPython before 3.1.58 contains a config-name injection vulnerability ...)
CVE-2026-76220
(GitPython before 3.1.58 contains a command execution vulnerability in ...)
CVE-2026-76219
(GitPython versions before 3.1.58 contain an arbitrary file overwrite v ...)
CVE-2026-76218
(GitPython before 3.1.58 contains a remote code execution vulnerability ...)
CVE-2026-76217
(GitPython versions before 3.1.58 fail to validate options passed to gi ...)
CVE-2026-76047
Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-76887 Crash in the Wireshark dissection engine in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service | CVSS3: 3.1 | 0% Низкий | 7 дней назад | |
CVE-2026-76886 C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service | CVSS3: 8.1 | 0% Низкий | 7 дней назад | |
CVE-2026-76885 Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service | CVSS3: 3.1 | 0% Низкий | 7 дней назад | |
CVE-2026-76884 ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service | CVSS3: 3.1 | 0% Низкий | 7 дней назад | |
CVE-2026-76883 Catapult DCT2000 file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service | CVSS3: 4.7 | 0% Низкий | 7 дней назад | |
CVE-2026-76882 Bluetooth Attribute Protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service | CVSS3: 4.7 | 0% Низкий | 7 дней назад | |
CVE-2026-76881 CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service | CVSS3: 4.7 | 0% Низкий | 7 дней назад | |
CVE-2026-76880 RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service | CVSS3: 7.5 | 0% Низкий | 7 дней назад | |
CVE-2026-76879 C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service | CVSS3: 7.5 | 0% Низкий | 7 дней назад | |
CVE-2026-76878 In OpenStack Aodh before 22.0.1, the alarm list API bypasses project scoping when the all_projects query parameter is set to false. The API checks for the presence of the all_projects key rather than its value; a true value enforces the administrator-only policy, but a false value removes the key and skips the branch that normally restricts results to the caller's project. A non-admin user with the reader role can list alarms from all projects, exposing alarm actions containing trust webhook URLs, Heat signal endpoints, project IDs, and user IDs. The parameter can also be combined with a foreign project_id to target a specific project's alarms. A related concern is that OpenStack Watcher does not apply authorization to its webhook trigger endpoint. Any authenticated user who learns an audit's webhook URL, for example from this leaked Aodh alarm metadata, can start an EVENT audit and its associated action plan regardless of their own project or role. The webhook endpoint has lacked p... | 0% Низкий | 7 дней назад | ||
CVE-2026-7666 An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.core.mail.backends.smtp.EmailBackend` in Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake when `fail_silently=True`, which allows on-path network attackers to read email content via cleartext interception. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Kasper Dupont for reporting this issue. | CVSS3: 3.1 | 0% Низкий | 3 месяца назад | |
CVE-2026-76641 (Expat through 2.8.3 contains an out-of-bounds read vulnerability that ...) | CVSS3: 7.5 | 0% Низкий | 7 дней назад | |
CVE-2026-76235 (A memory leak flaw was found in cockpit-ws. The login page handler lea ...) | CVSS3: 7.5 | 0% Низкий | 8 дней назад | |
CVE-2026-76222 (GitPython before 3.1.58 fails to validate submodule names from .gitmod ...) | CVSS3: 8.2 | 0% Низкий | 8 дней назад | |
CVE-2026-76221 (GitPython before 3.1.58 contains a config-name injection vulnerability ...) | CVSS3: 8.8 | 0% Низкий | 8 дней назад | |
CVE-2026-76220 (GitPython before 3.1.58 contains a command execution vulnerability in ...) | CVSS3: 8.8 | 0% Низкий | 8 дней назад | |
CVE-2026-76219 (GitPython versions before 3.1.58 contain an arbitrary file overwrite v ...) | CVSS3: 8.1 | 0% Низкий | 8 дней назад | |
CVE-2026-76218 (GitPython before 3.1.58 contains a remote code execution vulnerability ...) | CVSS3: 7.5 | 0% Низкий | 8 дней назад | |
CVE-2026-76217 (GitPython versions before 3.1.58 fail to validate options passed to gi ...) | CVSS3: 6.5 | 0% Низкий | 8 дней назад | |
CVE-2026-76047 Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | CVSS3: 8.8 | 0% Низкий | 8 дней назад |
Уязвимостей на страницу