Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 52 848

Количество 52 848

redhat логотип

CVE-2026-6530

3 месяца назад

DCP-ETSI protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2026-6529

3 месяца назад

iLBC audio codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2026-6528

3 месяца назад

TLS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 allows denial of service

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2026-6527

3 месяца назад

ASN.1 PER protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2026-6526

3 месяца назад

RTSP protocol dissector crash in Wireshark 4.6.0 to 4.6.4

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2026-6525

3 месяца назад

IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.4

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2026-6524

3 месяца назад

MySQL protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2026-6523

3 месяца назад

GNW protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2026-6522

3 месяца назад

RPKI-Router protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2026-6521

3 месяца назад

OpenFlow v5 protocol dissector infinite loops in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2026-6520

3 месяца назад

OpenFlow v6 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2026-6519

3 месяца назад

MBIM protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2026-6507

4 месяца назад

A flaw was found in dnsmasq. A remote attacker could exploit an out-of-bounds write vulnerability by sending a specially crafted BOOTREPLY (Bootstrap Protocol Reply) packet to a dnsmasq server configured with the `--dhcp-split-relay` option. This can lead to memory corruption, causing the dnsmasq daemon to crash and resulting in a denial of service (DoS).

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-65010

9 дней назад

A flaw was found in Hugging Face Datasets through 5.00 in Extractor.extract(). When archive contents are extracted to predictable output paths, the extractor follows pre-planted symlinks instead of confining writes to the intended directory. A local attacker who can place those symlinks can redirect extraction and overwrite arbitrary files, impacting integrity and availability (including possible privilege escalation or code execution in shared-cache setups).

CVSS3: 6.6
EPSS: Низкий
redhat логотип

CVE-2026-6494

4 месяца назад

A flaw was found in the AAP MCP server. An unauthenticated remote attacker can exploit a log injection vulnerability by sending specially crafted input to the `toolsetroute` parameter. This parameter is not properly sanitized before being written to logs, allowing the attacker to inject control characters such as newlines and ANSI escape sequences. This enables the attacker to obscure legitimate log entries and insert forged ones, which could facilitate social engineering attacks, potentially leading to an operator executing dangerous commands or visiting malicious URLs.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2026-64835

10 дней назад

A flaw was found in FFmpeg. A remote attacker could exploit an out-of-bounds memory access vulnerability in the ADX audio decoder by supplying a specially crafted ADX or AAX audio file. This could lead to the attacker triggering both out-of-bounds reads and writes, potentially resulting in arbitrary code execution, information disclosure, or denial of service.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2026-64834

10 дней назад

A flaw was found in FFmpeg. A remote attacker can exploit an infinite loop vulnerability in the RTP/ASF demuxer by sending a specially crafted stream. This vulnerability occurs because the rtp_asf_fix_header function does not properly validate the size of data chunks, preventing the processing loop from advancing. Successful exploitation leads to CPU exhaustion, causing a Denial of Service (DoS) for legitimate users.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-64831

10 дней назад

FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses and adjacent stack frames by supplying a crafted HEVC/H.265 bitstream. Attackers can embed a malicious vps_num_hrd_parameters value exceeding HEVC_MAX_SUB_LAYERS in any supported container format to overflow stack-allocated arrays in the vk_hevc_end_frame function, potentially achieving arbitrary code execution.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2026-6479

3 месяца назад

Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-6478

3 месяца назад

Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 8.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-6530

DCP-ETSI protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVSS3: 6.5
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-6529

iLBC audio codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVSS3: 6.5
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-6528

TLS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 allows denial of service

CVSS3: 6.5
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-6527

ASN.1 PER protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVSS3: 5.5
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-6526

RTSP protocol dissector crash in Wireshark 4.6.0 to 4.6.4

CVSS3: 6.5
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-6525

IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.4

CVSS3: 5.5
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-6524

MySQL protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVSS3: 6.5
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-6523

GNW protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVSS3: 5.5
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-6522

RPKI-Router protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVSS3: 6.5
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-6521

OpenFlow v5 protocol dissector infinite loops in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVSS3: 6.5
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-6520

OpenFlow v6 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVSS3: 6.5
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-6519

MBIM protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVSS3: 6.5
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-6507

A flaw was found in dnsmasq. A remote attacker could exploit an out-of-bounds write vulnerability by sending a specially crafted BOOTREPLY (Bootstrap Protocol Reply) packet to a dnsmasq server configured with the `--dhcp-split-relay` option. This can lead to memory corruption, causing the dnsmasq daemon to crash and resulting in a denial of service (DoS).

CVSS3: 7.5
0%
Низкий
4 месяца назад
redhat логотип
CVE-2026-65010

A flaw was found in Hugging Face Datasets through 5.00 in Extractor.extract(). When archive contents are extracted to predictable output paths, the extractor follows pre-planted symlinks instead of confining writes to the intended directory. A local attacker who can place those symlinks can redirect extraction and overwrite arbitrary files, impacting integrity and availability (including possible privilege escalation or code execution in shared-cache setups).

CVSS3: 6.6
0%
Низкий
9 дней назад
redhat логотип
CVE-2026-6494

A flaw was found in the AAP MCP server. An unauthenticated remote attacker can exploit a log injection vulnerability by sending specially crafted input to the `toolsetroute` parameter. This parameter is not properly sanitized before being written to logs, allowing the attacker to inject control characters such as newlines and ANSI escape sequences. This enables the attacker to obscure legitimate log entries and insert forged ones, which could facilitate social engineering attacks, potentially leading to an operator executing dangerous commands or visiting malicious URLs.

CVSS3: 5.3
0%
Низкий
4 месяца назад
redhat логотип
CVE-2026-64835

A flaw was found in FFmpeg. A remote attacker could exploit an out-of-bounds memory access vulnerability in the ADX audio decoder by supplying a specially crafted ADX or AAX audio file. This could lead to the attacker triggering both out-of-bounds reads and writes, potentially resulting in arbitrary code execution, information disclosure, or denial of service.

CVSS3: 8.8
0%
Низкий
10 дней назад
redhat логотип
CVE-2026-64834

A flaw was found in FFmpeg. A remote attacker can exploit an infinite loop vulnerability in the RTP/ASF demuxer by sending a specially crafted stream. This vulnerability occurs because the rtp_asf_fix_header function does not properly validate the size of data chunks, preventing the processing loop from advancing. Successful exploitation leads to CPU exhaustion, causing a Denial of Service (DoS) for legitimate users.

CVSS3: 7.5
1%
Низкий
10 дней назад
redhat логотип
CVE-2026-64831

FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses and adjacent stack frames by supplying a crafted HEVC/H.265 bitstream. Attackers can embed a malicious vps_num_hrd_parameters value exceeding HEVC_MAX_SUB_LAYERS in any supported container format to overflow stack-allocated arrays in the vk_hevc_end_frame function, potentially achieving arbitrary code execution.

CVSS3: 8.8
0%
Низкий
10 дней назад
redhat логотип
CVE-2026-6479

Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 7.5
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-6478

Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 8.2
1%
Низкий
3 месяца назад

Уязвимостей на страницу