Количество 77 240
Количество 77 240
CVE-2026-52489
Buffer Overflow vulnerability in gpac 31becc9e08b88e525a4a62013a4000de1c0f8fd9 allows an attacker to execute arbitrary code via the svgNameToImplementationName() function
CVE-2026-5246
A vulnerability was determined in Cesanta Mongoose up to 7.20. Affected is the function mg_tls_verify_cert_signature of the file mongoose.c of the component P-384 Public Key Handler. Executing a manipulation can lead to authorization bypass. The attack can be executed remotely. Attacks of this nature are highly complex. The exploitability is told to be difficult. The exploit has been publicly disclosed and may be utilized. Upgrading to version 7.21 is able to address this issue. This patch is called 0d882f1b43ff2308b7486a56a9d60cd6dba8a3f1. The affected component should be upgraded. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
CVE-2026-5245
A vulnerability was found in Cesanta Mongoose up to 7.20. This impacts the function handle_mdns_record of the file mongoose.c of the component mDNS Record Handler. Performing a manipulation of the argument buf results in stack-based buffer overflow. Remote exploitation of the attack is possible. A high degree of complexity is needed for the attack. The exploitability is said to be difficult. The exploit has been made public and could be used. Upgrading to version 7.21 will fix this issue. The patch is named 0d882f1b43ff2308b7486a56a9d60cd6dba8a3f1. You should upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
CVE-2026-5244
A vulnerability has been found in Cesanta Mongoose up to 7.20. This affects the function mg_tls_recv_cert of the file mongoose.c of the component TLS 1.3 Handler. Such manipulation of the argument pubkey leads to heap-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 7.21 mitigates this issue. The name of the patch is 0d882f1b43ff2308b7486a56a9d60cd6dba8a3f1. It is advisable to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
CVE-2026-52295
(Buffer Overflow vulnerability in Ffmpeg v.7.0 and after allows an atta ...)
CVE-2026-5223
Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The severity of the vulnerability is **medium** for users of third-party registries. Users of crates.io are **not affected**, as crates.io forbids uploading crates containing any symlink.
CVE-2026-5222
Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. If a hosting provider allowed multiple registries to be hosted with arbitrary names within the same domain, an attacker able to publish crates in a registry could obtain the credentials of others users of the same registry. The severity of the vulnerability is **low**, due to the extremely niche requirements needed to achieve the attack.
CVE-2026-52132
(llama.cpp through commit 97f06e9, when started with the --reranking fl ...)
CVE-2026-52131
(llama.cpp b5693 and before has a Reachable Assertion via the gguf_read ...)
CVE-2026-52130
(llama.cpp b5693 and before is vulnerable to Uncontrolled Recursion in ...)
CVE-2026-52079
[ENET_IRQHandler RX descriptor not re-owned on error -- RX ring stall]
CVE-2026-52078
[opendir() stack overflow via wcscat on MAX_PATH path]
CVE-2026-52076
[cyw_spi_tx SPI alignment padding indexes uint32_t* buffer with byte offset]
CVE-2026-52075
[mg_random rand() fallback used for TLS secrets]
CVE-2026-52073
[ppp_handle_ipcp attacker-controlled IPCP length -- OOB read]
CVE-2026-52072
[mg_tls_client_recv_hello size_t underflow in ext_len bounds check / mg_tls_client_recv_hello ext_len fixed-offset OOB read]
CVE-2026-52071
[mg_tls_verify_cert_signature OOB read for short ECDSA integers]
CVE-2026-52070
[rx_ndp_ns ICMPv6 NS minimum length insufficient -- OOB read]
CVE-2026-52069
[rx_dhcp_client 32-bit overflow in DHCP lease millisecond conversion]
CVE-2026-52068
[rx_ndp_na NDP NA missing option length check -- OOB read]
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-52489 Buffer Overflow vulnerability in gpac 31becc9e08b88e525a4a62013a4000de1c0f8fd9 allows an attacker to execute arbitrary code via the svgNameToImplementationName() function | CVSS3: 7.8 | 0% Низкий | 13 дней назад | |
CVE-2026-5246 A vulnerability was determined in Cesanta Mongoose up to 7.20. Affected is the function mg_tls_verify_cert_signature of the file mongoose.c of the component P-384 Public Key Handler. Executing a manipulation can lead to authorization bypass. The attack can be executed remotely. Attacks of this nature are highly complex. The exploitability is told to be difficult. The exploit has been publicly disclosed and may be utilized. Upgrading to version 7.21 is able to address this issue. This patch is called 0d882f1b43ff2308b7486a56a9d60cd6dba8a3f1. The affected component should be upgraded. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product. | CVSS3: 5.6 | 1% Низкий | 5 месяцев назад | |
CVE-2026-5245 A vulnerability was found in Cesanta Mongoose up to 7.20. This impacts the function handle_mdns_record of the file mongoose.c of the component mDNS Record Handler. Performing a manipulation of the argument buf results in stack-based buffer overflow. Remote exploitation of the attack is possible. A high degree of complexity is needed for the attack. The exploitability is said to be difficult. The exploit has been made public and could be used. Upgrading to version 7.21 will fix this issue. The patch is named 0d882f1b43ff2308b7486a56a9d60cd6dba8a3f1. You should upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product. | CVSS3: 5.6 | 1% Низкий | 5 месяцев назад | |
CVE-2026-5244 A vulnerability has been found in Cesanta Mongoose up to 7.20. This affects the function mg_tls_recv_cert of the file mongoose.c of the component TLS 1.3 Handler. Such manipulation of the argument pubkey leads to heap-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 7.21 mitigates this issue. The name of the patch is 0d882f1b43ff2308b7486a56a9d60cd6dba8a3f1. It is advisable to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product. | CVSS3: 7.3 | 1% Низкий | 5 месяцев назад | |
CVE-2026-52295 (Buffer Overflow vulnerability in Ffmpeg v.7.0 and after allows an atta ...) | 0% Низкий | 5 дней назад | ||
CVE-2026-5223 Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The severity of the vulnerability is **medium** for users of third-party registries. Users of crates.io are **not affected**, as crates.io forbids uploading crates containing any symlink. | CVSS3: 5.3 | 0% Низкий | 4 месяца назад | |
CVE-2026-5222 Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. If a hosting provider allowed multiple registries to be hosted with arbitrary names within the same domain, an attacker able to publish crates in a registry could obtain the credentials of others users of the same registry. The severity of the vulnerability is **low**, due to the extremely niche requirements needed to achieve the attack. | CVSS3: 6.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-52132 (llama.cpp through commit 97f06e9, when started with the --reranking fl ...) | CVSS3: 7.5 | 0% Низкий | 5 дней назад | |
CVE-2026-52131 (llama.cpp b5693 and before has a Reachable Assertion via the gguf_read ...) | CVSS3: 7.5 | 0% Низкий | 5 дней назад | |
CVE-2026-52130 (llama.cpp b5693 and before is vulnerable to Uncontrolled Recursion in ...) | CVSS3: 7.5 | 0% Низкий | 5 дней назад | |
CVE-2026-52079 [ENET_IRQHandler RX descriptor not re-owned on error -- RX ring stall] | 25 дней назад | |||
CVE-2026-52078 [opendir() stack overflow via wcscat on MAX_PATH path] | 25 дней назад | |||
CVE-2026-52076 [cyw_spi_tx SPI alignment padding indexes uint32_t* buffer with byte offset] | 25 дней назад | |||
CVE-2026-52075 [mg_random rand() fallback used for TLS secrets] | 25 дней назад | |||
CVE-2026-52073 [ppp_handle_ipcp attacker-controlled IPCP length -- OOB read] | 25 дней назад | |||
CVE-2026-52072 [mg_tls_client_recv_hello size_t underflow in ext_len bounds check / mg_tls_client_recv_hello ext_len fixed-offset OOB read] | 25 дней назад | |||
CVE-2026-52071 [mg_tls_verify_cert_signature OOB read for short ECDSA integers] | 25 дней назад | |||
CVE-2026-52070 [rx_ndp_ns ICMPv6 NS minimum length insufficient -- OOB read] | 25 дней назад | |||
CVE-2026-52069 [rx_dhcp_client 32-bit overflow in DHCP lease millisecond conversion] | 25 дней назад | |||
CVE-2026-52068 [rx_ndp_na NDP NA missing option length check -- OOB read] | 25 дней назад |
Уязвимостей на страницу