Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 77 337

Количество 77 337

ubuntu логотип

CVE-2026-5244

5 месяцев назад

A vulnerability has been found in Cesanta Mongoose up to 7.20. This affects the function mg_tls_recv_cert of the file mongoose.c of the component TLS 1.3 Handler. Such manipulation of the argument pubkey leads to heap-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 7.21 mitigates this issue. The name of the patch is 0d882f1b43ff2308b7486a56a9d60cd6dba8a3f1. It is advisable to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

CVSS3: 7.3
EPSS: Низкий
ubuntu логотип

CVE-2026-52295

6 дней назад

(Buffer Overflow vulnerability in Ffmpeg v.7.0 and after allows an atta ...)

EPSS: Низкий
ubuntu логотип

CVE-2026-5223

4 месяца назад

Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The severity of the vulnerability is **medium** for users of third-party registries. Users of crates.io are **not affected**, as crates.io forbids uploading crates containing any symlink.

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2026-5222

4 месяца назад

Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. If a hosting provider allowed multiple registries to be hosted with arbitrary names within the same domain, an attacker able to publish crates in a registry could obtain the credentials of others users of the same registry. The severity of the vulnerability is **low**, due to the extremely niche requirements needed to achieve the attack.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2026-52132

6 дней назад

(llama.cpp through commit 97f06e9, when started with the --reranking fl ...)

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-52131

6 дней назад

(llama.cpp b5693 and before has a Reachable Assertion via the gguf_read ...)

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-52130

6 дней назад

(llama.cpp b5693 and before is vulnerable to Uncontrolled Recursion in ...)

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-52079

26 дней назад

[ENET_IRQHandler RX descriptor not re-owned on error -- RX ring stall]

EPSS: Низкий
ubuntu логотип

CVE-2026-52078

26 дней назад

[opendir() stack overflow via wcscat on MAX_PATH path]

EPSS: Низкий
ubuntu логотип

CVE-2026-52076

26 дней назад

[cyw_spi_tx SPI alignment padding indexes uint32_t* buffer with byte offset]

EPSS: Низкий
ubuntu логотип

CVE-2026-52075

26 дней назад

[mg_random rand() fallback used for TLS secrets]

EPSS: Низкий
ubuntu логотип

CVE-2026-52073

26 дней назад

[ppp_handle_ipcp attacker-controlled IPCP length -- OOB read]

EPSS: Низкий
ubuntu логотип

CVE-2026-52072

26 дней назад

[mg_tls_client_recv_hello size_t underflow in ext_len bounds check / mg_tls_client_recv_hello ext_len fixed-offset OOB read]

EPSS: Низкий
ubuntu логотип

CVE-2026-52071

26 дней назад

[mg_tls_verify_cert_signature OOB read for short ECDSA integers]

EPSS: Низкий
ubuntu логотип

CVE-2026-52070

26 дней назад

[rx_ndp_ns ICMPv6 NS minimum length insufficient -- OOB read]

EPSS: Низкий
ubuntu логотип

CVE-2026-52069

26 дней назад

[rx_dhcp_client 32-bit overflow in DHCP lease millisecond conversion]

EPSS: Низкий
ubuntu логотип

CVE-2026-52068

26 дней назад

[rx_ndp_na NDP NA missing option length check -- OOB read]

EPSS: Низкий
ubuntu логотип

CVE-2026-52067

26 дней назад

[rx_ip truncated DHCP options size_t underflow OOB read]

EPSS: Низкий
ubuntu логотип

CVE-2026-52066

26 дней назад

[TLS certificate notAfter validated against hardcoded 2025-01-01 string]

EPSS: Низкий
ubuntu логотип

CVE-2026-52065

26 дней назад

[mg_tls_client_recv_hello key_share extension OOB read]

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-5244

A vulnerability has been found in Cesanta Mongoose up to 7.20. This affects the function mg_tls_recv_cert of the file mongoose.c of the component TLS 1.3 Handler. Such manipulation of the argument pubkey leads to heap-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 7.21 mitigates this issue. The name of the patch is 0d882f1b43ff2308b7486a56a9d60cd6dba8a3f1. It is advisable to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

CVSS3: 7.3
1%
Низкий
5 месяцев назад
ubuntu логотип
CVE-2026-52295

(Buffer Overflow vulnerability in Ffmpeg v.7.0 and after allows an atta ...)

0%
Низкий
6 дней назад
ubuntu логотип
CVE-2026-5223

Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The severity of the vulnerability is **medium** for users of third-party registries. Users of crates.io are **not affected**, as crates.io forbids uploading crates containing any symlink.

CVSS3: 5.3
0%
Низкий
4 месяца назад
ubuntu логотип
CVE-2026-5222

Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. If a hosting provider allowed multiple registries to be hosted with arbitrary names within the same domain, an attacker able to publish crates in a registry could obtain the credentials of others users of the same registry. The severity of the vulnerability is **low**, due to the extremely niche requirements needed to achieve the attack.

CVSS3: 6.5
0%
Низкий
4 месяца назад
ubuntu логотип
CVE-2026-52132

(llama.cpp through commit 97f06e9, when started with the --reranking fl ...)

CVSS3: 7.5
0%
Низкий
6 дней назад
ubuntu логотип
CVE-2026-52131

(llama.cpp b5693 and before has a Reachable Assertion via the gguf_read ...)

CVSS3: 7.5
0%
Низкий
6 дней назад
ubuntu логотип
CVE-2026-52130

(llama.cpp b5693 and before is vulnerable to Uncontrolled Recursion in ...)

CVSS3: 7.5
0%
Низкий
6 дней назад
ubuntu логотип
CVE-2026-52079

[ENET_IRQHandler RX descriptor not re-owned on error -- RX ring stall]

26 дней назад
ubuntu логотип
CVE-2026-52078

[opendir() stack overflow via wcscat on MAX_PATH path]

26 дней назад
ubuntu логотип
CVE-2026-52076

[cyw_spi_tx SPI alignment padding indexes uint32_t* buffer with byte offset]

26 дней назад
ubuntu логотип
CVE-2026-52075

[mg_random rand() fallback used for TLS secrets]

26 дней назад
ubuntu логотип
CVE-2026-52073

[ppp_handle_ipcp attacker-controlled IPCP length -- OOB read]

26 дней назад
ubuntu логотип
CVE-2026-52072

[mg_tls_client_recv_hello size_t underflow in ext_len bounds check / mg_tls_client_recv_hello ext_len fixed-offset OOB read]

26 дней назад
ubuntu логотип
CVE-2026-52071

[mg_tls_verify_cert_signature OOB read for short ECDSA integers]

26 дней назад
ubuntu логотип
CVE-2026-52070

[rx_ndp_ns ICMPv6 NS minimum length insufficient -- OOB read]

26 дней назад
ubuntu логотип
CVE-2026-52069

[rx_dhcp_client 32-bit overflow in DHCP lease millisecond conversion]

26 дней назад
ubuntu логотип
CVE-2026-52068

[rx_ndp_na NDP NA missing option length check -- OOB read]

26 дней назад
ubuntu логотип
CVE-2026-52067

[rx_ip truncated DHCP options size_t underflow OOB read]

26 дней назад
ubuntu логотип
CVE-2026-52066

[TLS certificate notAfter validated against hardcoded 2025-01-01 string]

26 дней назад
ubuntu логотип
CVE-2026-52065

[mg_tls_client_recv_hello key_share extension OOB read]

26 дней назад

Уязвимостей на страницу