8.7
CVE-2024-39847 - Arbitrary File Read and Server Side Request Forgery via XML External Entities in 4D Server SOAP
Unauthenticated attackers can exploit a weakness in the XML parser functionality of the SOAP endpoints in 4D server. This allows them to obtain read access to files on the application server and adjacent network shares, and perform HTTP GET requests to arbitrary services.
7.8
CVE-2026-7270 - Local privilege escalation via execve()
An operator precedence bug in the kernel results in a scenario where a buffer overflow causes attacker-controlled data to overwrite adjacent execve(2) argument buffers. The bug may be exploitable by an unprivileged user to obtain superuser privileges.
8.1
CVE-2026-42511 - Remote code execution via malicious DHCP options
The BOOTP file field is written to the lease file without escaping embedded double-quotes, allowing injection of arbitrary dhclient.conf directives. When the lease file is subsequently re-parsed by dhclient, e.g., after a system restart, an attacker-controlled field from the lease is passed to dhcโฆ
4
CVE-2026-42798 - Integer Overflow in Little CMS ParseCube Function
Little CMS (lcms2) 2.16 through 2.18 before 2.19 has an integer overflow in ParseCube in cmscgats.c.
5.1
CVE-2026-41226 - Open Redirect in Ricoh Web Image Monitor Leading to Phishing
Open redirect vulnerability exists in Multiple laser printers and MFPs which implement Ricoh Web Image Monitor. When accessing a specially crafted URL, the user may be redirected to an arbitrary website. As a result, the user may become a victim of a phishing attack.
5.5
CVE-2026-5409 - Uncontrolled Recursion in Wireshark
Monero protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
5.5
CVE-2026-5408 - Uncontrolled Recursion in Wireshark
BT-DHT protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
5.5
CVE-2026-5406 - Uncontrolled Recursion in Wireshark
FC-SWILS protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
5.5
CVE-2026-5407 - Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
SMB2 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
5.5
CVE-2026-5299 - Uncontrolled Recursion in Wireshark
ICMPv6 PvD protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service