8.5

CVSS4.0

CVE-2026-29126 - World-Writable, Root Owned/Run `/etc/udhcpc/default.script` in IDC SFX2100 Satellite Receiver Leads…

Incorrect permission assignment (world-writable file) in /etc/udhcpc/default.script in International Data Casting (IDC) SFX2100 Satellite Receiver allows a local unprivileged attacker to potentially execute arbitrary commands with root privileges (local privilege escalation and persistence) via mod…

📅 Published: March 5, 2026, 1:51 a.m. 🔄 Last Modified: April 16, 2026, 1 p.m.

9.1

CVSS3.1

CVE-2025-40931 - Apache::Session::Generate::MD5 versions through 1.94 for Perl create insecure session id

Apache::Session::Generate::MD5 versions through 1.94 for Perl create insecure session id. Apache::Session::Generate::MD5 generates session ids insecurely. The default session id generator returns a MD5 hash seeded with the built-in rand() function, the epoch time, and the PID. The PID will come fr…

📅 Published: March 5, 2026, 1:41 a.m. 🔄 Last Modified: April 20, 2026, 5:30 p.m.

7.1

CVSS4.0

CVE-2026-29125 - IDC SFX2100 Satellite Receiver allows unprivileged modification of DNS configuration due to world-w…

IDC SFX2100 Satalite Recievers set the `/etc/resolv.conf` file to be world-writable by any local user, allowing DNS resolver tampering that can redirect network communications, facilitate man-in-the-middle attacks, and cause denial of service.

📅 Published: March 5, 2026, 1:38 a.m. 🔄 Last Modified: April 16, 2026, 1 p.m.

9.8

CVSS3.1

CVE-2026-3257 - UnQLite versions through 0.06 for Perl uses a potentially insecure version of the UnQLite library

UnQLite versions through 0.06 for Perl uses a potentially insecure version of the UnQLite library. UnQLite for Perl embeds the UnQLite library. Version 0.06 and earlier of the Perl module uses a version of the library from 2014 that may be vulnerable to a heap-based overflow.

📅 Published: March 5, 2026, 1:35 a.m. 🔄 Last Modified: April 16, 2026, 1 p.m.

9.8

CVSS3.1

CVE-2026-3381 - Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib

Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib. Compress::Raw::Zlib includes a copy of the zlib library. Compress::Raw::Zlib version 2.220 includes zlib 1.3.2, which addresses findings fron the 7ASecurity audit of zlib. The includes fixs for CVE-2026-…

📅 Published: March 5, 2026, 1:28 a.m. 🔄 Last Modified: April 16, 2026, 5:45 a.m.

9.8

CVSS3.1

CVE-2025-40926 - Plack::Middleware::Session::Simple versions before 0.05 for Perl generates session ids insecurely

Plack::Middleware::Session::Simple versions before 0.05 for Perl generates session ids insecurely. The default session id generator returns a SHA-1 hash seeded with the built-in rand function, the epoch time, and the PID. The PID will come from a small set of numbers, and the epoch time may be gue…

📅 Published: March 5, 2026, 1:24 a.m. 🔄 Last Modified: April 22, 2026, 11:30 a.m.

8.6

CVSS4.0

CVE-2026-29124 - Multiple SUID Root Binaries in `monitor` User Home Directory Leading to Potential Local Privilege E…

Multiple SUID root-owned binaries are found in /home/monitor/terminal, /home/monitor/kore-terminal, /home/monitor/IDE-DPack/terminal-dpack, and /home/monitor/IDE-DPack/terminal-dpack2 in International Data Casting (IDC) SFX2100 Satellite Receiver, which may lead to local privlidge escalation from t…

📅 Published: March 5, 2026, 1:23 a.m. 🔄 Last Modified: April 17, 2026, 1 p.m.

8.6

CVSS4.0

CVE-2026-29123 - Multiple SUID Root Binaries in `xd` User Home Directory Leading to Potential Local Privilege Escala…

A SUID root-owned binary in /home/xd/terminal/XDTerminal in International Data Casting (IDC) SFX2100 on Linux allows a local actor to potentially preform local privilege escalation depending on conditions of the system via execution of the affected SUID binary. This can be via PATH hijacking, symli…

📅 Published: March 5, 2026, 1:18 a.m. 🔄 Last Modified: April 18, 2026, 10 a.m.

8.3

CVSS4.0

CVE-2026-29122 - `/bin/date` Binary given SETUID Permissions on IDC SFX2100 Leading to Potential LPE

International Data Casting (IDC) SFX2100 satellite receiver comes with the `/bin/date` utility installed with the setuid bit set. This configuration grants elevated privileges to any local user who can execute the binary. A local actor is able to use the GTFObins resource to preform privileged file…

📅 Published: March 5, 2026, 12:53 a.m. 🔄 Last Modified: April 17, 2026, 1 p.m.

8.3

CVSS4.0

CVE-2026-29121 - `/sbin/ip` Binary given SETUID Permissions on IDC SFX2100 Leading to Potential LPE

International Data Casting (IDC) SFX2100 satellite receiver comes with the `/sbin/ip` utility installed with the setuid bit set. This configuration grants elevated privileges to any local user who can execute the binary. A local actor is able to use the GTFObins resource to preform privileged file …

📅 Published: March 5, 2026, 12:48 a.m. 🔄 Last Modified: April 16, 2026, 1:15 p.m.
Total resulsts: 349182
Page 1334 of 34,919
« previous page » next page
Filters