Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 10

Количество 10

github логотип

GHSA-v7jp-vmx6-5429

2 месяца назад

libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly updates metadata list pointers when freeing non-head default metadata entries. Attackers can trigger this vulnerability by submitting crafted YANG XML documents with specific metadata attributes to applications parsing untrusted XML data, causing process crashes or potential code execution.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2026-41401

2 месяца назад

libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly updates metadata list pointers when freeing non-head default metadata entries. Attackers can trigger this vulnerability by submitting crafted YANG XML documents with specific metadata attributes to applications parsing untrusted XML data, causing process crashes or potential code execution.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2026-41401

2 месяца назад

libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly updates metadata list pointers when freeing non-head default metadata entries. Attackers can trigger this vulnerability by submitting crafted YANG XML documents with specific metadata attributes to applications parsing untrusted XML data, causing process crashes or potential code execution.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-41401

2 месяца назад

libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly updates metadata list pointers when freeing non-head default metadata entries. Attackers can trigger this vulnerability by submitting crafted YANG XML documents with specific metadata attributes to applications parsing untrusted XML data, causing process crashes or potential code execution.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2026-41401

2 месяца назад

libyang - Heap Use-After-Free Write in XML Metadata Parsing

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2026-41401

2 месяца назад

libyang before 5.2.6 contains a heap use-after-free write vulnerabilit ...

CVSS3: 6.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21113-1

около 2 месяцев назад

Security update for libyang

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2337-1

около 2 месяцев назад

Security update for libyang

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2335-1

около 2 месяцев назад

Security update for libyang

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2334-1

около 2 месяцев назад

Security update for libyang

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-v7jp-vmx6-5429

libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly updates metadata list pointers when freeing non-head default metadata entries. Attackers can trigger this vulnerability by submitting crafted YANG XML documents with specific metadata attributes to applications parsing untrusted XML data, causing process crashes or potential code execution.

CVSS3: 6.5
1%
Низкий
2 месяца назад
ubuntu логотип
CVE-2026-41401

libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly updates metadata list pointers when freeing non-head default metadata entries. Attackers can trigger this vulnerability by submitting crafted YANG XML documents with specific metadata attributes to applications parsing untrusted XML data, causing process crashes or potential code execution.

CVSS3: 6.5
1%
Низкий
2 месяца назад
redhat логотип
CVE-2026-41401

libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly updates metadata list pointers when freeing non-head default metadata entries. Attackers can trigger this vulnerability by submitting crafted YANG XML documents with specific metadata attributes to applications parsing untrusted XML data, causing process crashes or potential code execution.

CVSS3: 6.5
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-41401

libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly updates metadata list pointers when freeing non-head default metadata entries. Attackers can trigger this vulnerability by submitting crafted YANG XML documents with specific metadata attributes to applications parsing untrusted XML data, causing process crashes or potential code execution.

CVSS3: 6.5
1%
Низкий
2 месяца назад
msrc логотип
CVE-2026-41401

libyang - Heap Use-After-Free Write in XML Metadata Parsing

CVSS3: 6.5
1%
Низкий
2 месяца назад
debian логотип
CVE-2026-41401

libyang before 5.2.6 contains a heap use-after-free write vulnerabilit ...

CVSS3: 6.5
1%
Низкий
2 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21113-1

Security update for libyang

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:2337-1

Security update for libyang

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:2335-1

Security update for libyang

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:2334-1

Security update for libyang

около 2 месяцев назад

Уязвимостей на страницу