0.0

CVE-2026-39457 - Stack overflow via select() file descriptor set overflow

When exchanging data over a socket, libnv uses select(2) to wait for data to arrive. However, it does not verify whether the provided socket descriptor fits in select(2)'s file descriptor set size limit of FD_SETSIZE (1024). An attacker who is able to force a libnv application to allocate large f…

πŸ“… Published: April 30, 2026, 8:01 a.m. πŸ”„ Last Modified: April 30, 2026, 8:01 a.m.

0.0

CVE-2026-42512 - Remotely triggerable out-of-bounds heap write in dhclient

As dhclient is building an environment to pass to dhclient-script, it may need to resize the array of string pointers. The code which expands the array incorrectly calculates its new size when requesting memory, resulting in a heap buffer overrun. A specially crafted packet can cause dhclient to …

πŸ“… Published: April 30, 2026, 7:58 a.m. πŸ”„ Last Modified: April 30, 2026, 7:58 a.m.

0.0

CVE-2026-7164 - pf can overflow the stack parsing crafted SCTP packets

Incorrect packet validation allowed unbounded recursion parsing SCTP chunk parameters. This can eventually result in a stack overflow and panic. Remote attackers can craft packets which cause affected systems to panic. This affects any system where pf is configured to process traffic, independen…

πŸ“… Published: April 30, 2026, 7:23 a.m. πŸ”„ Last Modified: April 30, 2026, 7:23 a.m.

8.7

CVSS4.0

CVE-2024-39847 - Arbitrary File Read and Server Side Request Forgery via XML External Entities in 4D Server SOAP

Unauthenticated attackers can exploit a weakness in the XML parser functionality of the SOAP endpoints in 4D server. This allows them to obtain read access to files on the application server and adjacent network shares, and perform HTTP GET requests to arbitrary services.

πŸ“… Published: April 30, 2026, 7:10 a.m. πŸ”„ Last Modified: May 5, 2026, 2:51 a.m.

0.0

CVE-2026-7270 - Local privilege escalation via execve()

An operator precedence bug in the kernel results in a scenario where a buffer overflow causes attacker-controlled data to overwrite adjacent execve(2) argument buffers. The bug may be exploitable by an unprivileged user to obtain superuser privileges.

πŸ“… Published: April 30, 2026, 7:02 a.m. πŸ”„ Last Modified: April 30, 2026, 7:02 a.m.

0.0

CVE-2026-42511 - Remote code execution via malicious DHCP options

The BOOTP file field is written to the lease file without escaping embedded double-quotes, allowing injection of arbitrary dhclient.conf directives. When the lease file is subsequently re-parsed by dhclient, e.g., after a system restart, an attacker-controlled field from the lease is passed to dhc…

πŸ“… Published: April 30, 2026, 6:56 a.m. πŸ”„ Last Modified: April 30, 2026, 6:56 a.m.

4

CVSS3.1

CVE-2026-42798 -

Little CMS (lcms2) 2.16 through 2.18 before 2.19 has an integer overflow in ParseCube in cmscgats.c.

πŸ“… Published: April 30, 2026, 6:34 a.m. πŸ”„ Last Modified: April 30, 2026, 6:49 a.m.

5.1

CVSS4.0

CVE-2026-41226 -

Open redirect vulnerability exists in Multiple laser printers and MFPs which implement Ricoh Web Image Monitor. When accessing a specially crafted URL, the user may be redirected to an arbitrary website. As a result, the user may become a victim of a phishing attack.

πŸ“… Published: April 30, 2026, 6:08 a.m. πŸ”„ Last Modified: April 30, 2026, 6:08 a.m.

5.5

CVSS3.1

CVE-2026-5409 - Uncontrolled Recursion in Wireshark

Monero protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

πŸ“… Published: April 30, 2026, 5:41 a.m. πŸ”„ Last Modified: May 1, 2026, 7:27 p.m.

5.5

CVSS3.1

CVE-2026-5408 - Uncontrolled Recursion in Wireshark

BT-DHT protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

πŸ“… Published: April 30, 2026, 5:40 a.m. πŸ”„ Last Modified: May 1, 2026, 7:25 p.m.
Total resulsts: 348395
Page 111 of 34,840
Β« previous page Β» next page
Filters