Количество 77 337
Количество 77 337
CVE-2026-52064
[DNS transaction ID is sequential -- enables response injection]
CVE-2026-52062
[NDP RA allows any value for MTU]
CVE-2026-52061
[mg_tls_recv_cert certificate chain length unchecked -- OOB read]
CVE-2026-52060
[TLS certificate notAfter validated against hardcoded 2025-01-01 string]
CVE-2026-52059
[RSA-PSS CertificateVerify checks only 0xbc trailer]
CVE-2026-52058
[mg_der_to_tlv long-form DER length OOB read]
CVE-2026-52057
[mg_der_find_oid unbounded recursion on constructed DER tags]
CVE-2026-52056
[skip_chunk off-by-one OOB read in chunked HTTP CRLF check]
CVE-2026-52055
[mg_der_to_tlv long-form DER length OOB read]
CVE-2026-52054
[find_opt zero-length PPP option -- infinite loop]
CVE-2026-52053
[rx_ip6 IPv6 extension header OOB read; 16-bit len wrap]
CVE-2026-52052
[mg_tls_parse_cert_der pubkey BIT STRING length underflow -- OOB read]
CVE-2026-52051
[mg_tls_server_recv_hello session_id_len OOB read]
CVE-2026-52050
[precompute_slide_window NULL deref on OOM / more_comps NULL deref after failed calloc / bi_initialize / alloc NULL deref on OOM]
CVE-2026-52048
[MQTT v5 properties bounds check uses relative offset against absolute position]
CVE-2026-52047
[w5100_rx wraparound RX path copies n instead of r bytes]
CVE-2026-52023
(An issue in kamailio v.6.1.1 and before allows a remote attacker to ca ...)
CVE-2026-52022
(An issue in kamailio v.6.1.1 and before allows a remote attacker to ca ...)
CVE-2026-5201
A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component counts when processing a specially crafted JPEG image. A remote attacker can exploit this flaw without user interaction, for example, via thumbnail generation. Successful exploitation leads to application crashes and denial of service (DoS) conditions.
CVE-2026-5194
Missing hash/digest size and OID checks allow digests smaller than allowed when verifying ECDSA certificates, or smaller than is appropriate for the relevant key type, to be accepted by signature verification functions. This could lead to reduced security of ECDSA certificate-based authentication if the public CA key used is also known. This affects ECDSA/ECC verification when EdDSA or ML-DSA is also enabled.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-52064 [DNS transaction ID is sequential -- enables response injection] | 26 дней назад | |||
CVE-2026-52062 [NDP RA allows any value for MTU] | 26 дней назад | |||
CVE-2026-52061 [mg_tls_recv_cert certificate chain length unchecked -- OOB read] | 26 дней назад | |||
CVE-2026-52060 [TLS certificate notAfter validated against hardcoded 2025-01-01 string] | 26 дней назад | |||
CVE-2026-52059 [RSA-PSS CertificateVerify checks only 0xbc trailer] | 26 дней назад | |||
CVE-2026-52058 [mg_der_to_tlv long-form DER length OOB read] | 26 дней назад | |||
CVE-2026-52057 [mg_der_find_oid unbounded recursion on constructed DER tags] | 26 дней назад | |||
CVE-2026-52056 [skip_chunk off-by-one OOB read in chunked HTTP CRLF check] | 26 дней назад | |||
CVE-2026-52055 [mg_der_to_tlv long-form DER length OOB read] | 26 дней назад | |||
CVE-2026-52054 [find_opt zero-length PPP option -- infinite loop] | 26 дней назад | |||
CVE-2026-52053 [rx_ip6 IPv6 extension header OOB read; 16-bit len wrap] | 26 дней назад | |||
CVE-2026-52052 [mg_tls_parse_cert_der pubkey BIT STRING length underflow -- OOB read] | 26 дней назад | |||
CVE-2026-52051 [mg_tls_server_recv_hello session_id_len OOB read] | 26 дней назад | |||
CVE-2026-52050 [precompute_slide_window NULL deref on OOM / more_comps NULL deref after failed calloc / bi_initialize / alloc NULL deref on OOM] | 26 дней назад | |||
CVE-2026-52048 [MQTT v5 properties bounds check uses relative offset against absolute position] | 26 дней назад | |||
CVE-2026-52047 [w5100_rx wraparound RX path copies n instead of r bytes] | 26 дней назад | |||
CVE-2026-52023 (An issue in kamailio v.6.1.1 and before allows a remote attacker to ca ...) | 0% Низкий | 6 дней назад | ||
CVE-2026-52022 (An issue in kamailio v.6.1.1 and before allows a remote attacker to ca ...) | CVSS3: 7.5 | 0% Низкий | 6 дней назад | |
CVE-2026-5201 A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component counts when processing a specially crafted JPEG image. A remote attacker can exploit this flaw without user interaction, for example, via thumbnail generation. Successful exploitation leads to application crashes and denial of service (DoS) conditions. | CVSS3: 7.5 | 1% Низкий | 5 месяцев назад | |
CVE-2026-5194 Missing hash/digest size and OID checks allow digests smaller than allowed when verifying ECDSA certificates, or smaller than is appropriate for the relevant key type, to be accepted by signature verification functions. This could lead to reduced security of ECDSA certificate-based authentication if the public CA key used is also known. This affects ECDSA/ECC verification when EdDSA or ML-DSA is also enabled. | CVSS3: 9.1 | 0% Низкий | 5 месяцев назад |
Уязвимостей на страницу