7.4

CVSS3.1

CVE-2026-42800 - Deference after null check in ims_client sip

NULL pointer dereference vulnerability in ASR1903 in ASR Lapwing_Linux on Linux (ims_client modules) allows Pointer Manipulation. This vulnerability is associated with program files sip/utils/src/sipuri.c.

πŸ“… Published: April 30, 2026, 8:52 a.m. πŸ”„ Last Modified: May 5, 2026, 2:54 a.m.

7.4

CVSS3.1

CVE-2026-42799 - Out-of-bounds read in ulp

Out-of-bounds read vulnerability in ASR Kestrel (nr_fw modules) allows Overflow Buffers. This vulnerability is associated with program files Code/Nr/nr_fw/RA/src/NrPwrCtrl.C. This issue affects Kestrel: before 2026/02/10.

πŸ“… Published: April 30, 2026, 8:36 a.m. πŸ”„ Last Modified: May 5, 2026, 2:53 a.m.

7.1

CVSS3.1

CVE-2026-22070 - ColorOS Assistant Path Traversal Vulnerability

ColorOS Assistant has an unauthenticated start-download channel, leading to file path traversal.

πŸ“… Published: April 30, 2026, 8:27 a.m. πŸ”„ Last Modified: May 5, 2026, 2:53 a.m.

0.0

CVE-2026-35547 - Heap overflow in libnv

When processing the header of an incoming message, libnv failed to properly validate the message size. The lack of validation allows a malicious program to write outside the bounds of a heap allocation. This can trigger a crash or system panic, and it may be possible for an unprivileged user to e…

πŸ“… Published: April 30, 2026, 8:08 a.m. πŸ”„ Last Modified: April 30, 2026, 8:08 a.m.

0.0

CVE-2026-39457 - Stack overflow via select() file descriptor set overflow

When exchanging data over a socket, libnv uses select(2) to wait for data to arrive. However, it does not verify whether the provided socket descriptor fits in select(2)'s file descriptor set size limit of FD_SETSIZE (1024). An attacker who is able to force a libnv application to allocate large f…

πŸ“… Published: April 30, 2026, 8:01 a.m. πŸ”„ Last Modified: April 30, 2026, 8:01 a.m.

0.0

CVE-2026-42512 - Remotely triggerable out-of-bounds heap write in dhclient

As dhclient is building an environment to pass to dhclient-script, it may need to resize the array of string pointers. The code which expands the array incorrectly calculates its new size when requesting memory, resulting in a heap buffer overrun. A specially crafted packet can cause dhclient to …

πŸ“… Published: April 30, 2026, 7:58 a.m. πŸ”„ Last Modified: April 30, 2026, 7:58 a.m.

0.0

CVE-2026-7164 - pf can overflow the stack parsing crafted SCTP packets

Incorrect packet validation allowed unbounded recursion parsing SCTP chunk parameters. This can eventually result in a stack overflow and panic. Remote attackers can craft packets which cause affected systems to panic. This affects any system where pf is configured to process traffic, independen…

πŸ“… Published: April 30, 2026, 7:23 a.m. πŸ”„ Last Modified: April 30, 2026, 7:23 a.m.

8.7

CVSS4.0

CVE-2024-39847 - Arbitrary File Read and Server Side Request Forgery via XML External Entities in 4D Server SOAP

Unauthenticated attackers can exploit a weakness in the XML parser functionality of the SOAP endpoints in 4D server. This allows them to obtain read access to files on the application server and adjacent network shares, and perform HTTP GET requests to arbitrary services.

πŸ“… Published: April 30, 2026, 7:10 a.m. πŸ”„ Last Modified: May 5, 2026, 2:51 a.m.

0.0

CVE-2026-7270 - Local privilege escalation via execve()

An operator precedence bug in the kernel results in a scenario where a buffer overflow causes attacker-controlled data to overwrite adjacent execve(2) argument buffers. The bug may be exploitable by an unprivileged user to obtain superuser privileges.

πŸ“… Published: April 30, 2026, 7:02 a.m. πŸ”„ Last Modified: April 30, 2026, 7:02 a.m.

0.0

CVE-2026-42511 - Remote code execution via malicious DHCP options

The BOOTP file field is written to the lease file without escaping embedded double-quotes, allowing injection of arbitrary dhclient.conf directives. When the lease file is subsequently re-parsed by dhclient, e.g., after a system restart, an attacker-controlled field from the lease is passed to dhc…

πŸ“… Published: April 30, 2026, 6:56 a.m. πŸ”„ Last Modified: April 30, 2026, 6:56 a.m.
Total resulsts: 348389
Page 110 of 34,839
Β« previous page Β» next page
Filters