Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 10

Количество 10

fstec логотип

BDU:2026-12832

5 месяцев назад

Уязвимость библиотеки для работы с usb устройствами libusb, связанная с чтением за допустимыми границами буфера данных, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 6.2
EPSS: Низкий
ubuntu логотип

CVE-2026-23679

4 месяца назад

libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash.

CVSS3: 6.2
EPSS: Низкий
redhat логотип

CVE-2026-23679

4 месяца назад

libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash.

CVSS3: 6.2
EPSS: Низкий
nvd логотип

CVE-2026-23679

4 месяца назад

libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash.

CVSS3: 6.2
EPSS: Низкий
msrc логотип

CVE-2026-23679

4 месяца назад

libusb < 1.0.30 NULL Pointer Dereference in parse_interface()

EPSS: Низкий
debian логотип

CVE-2026-23679

4 месяца назад

libusb before version 1.0.30 contains a NULL pointer dereference vulne ...

CVSS3: 6.2
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:4080-1

13 дней назад

Security update for libusb-1_0

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:4050-1

14 дней назад

Security update for libusb-1_0

EPSS: Низкий
github логотип

GHSA-jp69-qvgm-mqwx

4 месяца назад

libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash.

CVSS3: 6.2
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21783-1

14 дней назад

Security update for libusb-1_0

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-12832

Уязвимость библиотеки для работы с usb устройствами libusb, связанная с чтением за допустимыми границами буфера данных, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 6.2
0%
Низкий
5 месяцев назад
ubuntu логотип
CVE-2026-23679

libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash.

CVSS3: 6.2
0%
Низкий
4 месяца назад
redhat логотип
CVE-2026-23679

libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash.

CVSS3: 6.2
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-23679

libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash.

CVSS3: 6.2
0%
Низкий
4 месяца назад
msrc логотип
CVE-2026-23679

libusb < 1.0.30 NULL Pointer Dereference in parse_interface()

0%
Низкий
4 месяца назад
debian логотип
CVE-2026-23679

libusb before version 1.0.30 contains a NULL pointer dereference vulne ...

CVSS3: 6.2
0%
Низкий
4 месяца назад
suse-cvrf логотип
SUSE-SU-2026:4080-1

Security update for libusb-1_0

0%
Низкий
13 дней назад
suse-cvrf логотип
SUSE-SU-2026:4050-1

Security update for libusb-1_0

0%
Низкий
14 дней назад
github логотип
GHSA-jp69-qvgm-mqwx

libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash.

CVSS3: 6.2
0%
Низкий
4 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21783-1

Security update for libusb-1_0

14 дней назад

Уязвимостей на страницу