8.1

CVSS3.1

CVE-2026-40200 -

An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur during qsort of very large arrays, due to incorrectly implemented double-word primitives. The number of elements must exceed about seven million, i.e., the 32nd Leonardo number on 32-bit platforms (or…

πŸ“… Published: April 10, 2026, midnight πŸ”„ Last Modified: April 10, 2026, 6:16 p.m.

3.5

CVSS3.1

CVE-2026-33551 - Privilege Escalation via Restricted Application Credentials in OpenStack Keystone

An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role m…

πŸ“… Published: April 10, 2026, midnight πŸ”„ Last Modified: April 10, 2026, 2:16 p.m.

8.7

CVSS4.0

CVE-2026-5991 - Tenda F451 WrlExtraSet formWrlExtraSet stack-based overflow

A vulnerability was found in Tenda F451 1.0.0.7. Affected by this issue is the function formWrlExtraSet of the file /goform/WrlExtraSet. The manipulation of the argument GO results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been made public and could be use…

πŸ“… Published: April 9, 2026, 11:45 p.m. πŸ”„ Last Modified: April 9, 2026, 11:45 p.m.

8.7

CVSS4.0

CVE-2026-5990 - Tenda F451 SafeEmailFilter fromSafeEmailFilter stack-based overflow

A vulnerability has been found in Tenda F451 1.0.0.7. Affected by this vulnerability is the function fromSafeEmailFilter of the file /goform/SafeEmailFilter. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclo…

πŸ“… Published: April 9, 2026, 11:30 p.m. πŸ”„ Last Modified: April 9, 2026, 11:30 p.m.

6.3

CVSS4.0

CVE-2026-5460 - Heap Use-After-Free in PQC Hybrid KeyShare Error Cleanup in wolfSSL TLS 1.3

A heap use-after-free exists in wolfSSL's TLS 1.3 post-quantum cryptography (PQC) hybrid KeyShare processing. In the error handling path of TLSX_KeyShare_ProcessPqcHybridClient() in src/tls.c, the inner function TLSX_KeyShare_ProcessPqcClient_ex() frees a KyberKey object upon encountering an error.…

πŸ“… Published: April 9, 2026, 11:29 p.m. πŸ”„ Last Modified: April 9, 2026, 11:29 p.m.

2.3

CVSS4.0

CVE-2026-5448 - 1-2 Byte Buffer Overflow in wolfSSL_X509_notAfter/notBefore

X.509 date buffer overflow in wolfSSL_X509_notAfter / wolfSSL_X509_notBefore. A buffer overflow may occur when parsing date fields from a crafted X.509 certificate via the compatibility layer API. This is only triggered when calling these two APIs directly from an application, and does not affect T…

πŸ“… Published: April 9, 2026, 11:18 p.m. πŸ”„ Last Modified: April 9, 2026, 11:18 p.m.

8.7

CVSS4.0

CVE-2026-5989 - Tenda F451 RouteStatic fromRouteStatic stack-based overflow

A flaw has been found in Tenda F451 1.0.0.7. Affected is the function fromRouteStatic of the file /goform/RouteStatic. Executing a manipulation of the argument page can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been published and may be used.

πŸ“… Published: April 9, 2026, 11:15 p.m. πŸ”„ Last Modified: April 10, 2026, 5:07 p.m.

2.3

CVSS4.0

CVE-2026-5392 - wolfSSL heap OOB read in PKCS7 SignedData streaming

Heap out-of-bounds read in PKCS7 parsing. A crafted PKCS7 message can trigger an OOB read on the heap. The missing bounds check is in the indefinite-length end-of-content verification loop in PKCS7_VerifySignedData().

πŸ“… Published: April 9, 2026, 11:10 p.m. πŸ”„ Last Modified: April 9, 2026, 11:10 p.m.

6.3

CVSS4.0

CVE-2026-5393 - OOB Read in DoTls13CertificateVerify with WOLFSSL_DUAL_ALG_CERTS

Dual-Algorithm CertificateVerify out-of-bounds read. When processing a dual-algorithm CertificateVerify message, an out-of-bounds read can occur on crafted input. This can only occur when --enable-experimental and --enable-dual-alg-certs is used when building wolfSSL.

πŸ“… Published: April 9, 2026, 11:02 p.m. πŸ”„ Last Modified: April 9, 2026, 11:02 p.m.

8.7

CVSS4.0

CVE-2026-5988 - Tenda F451 AdvSetWrlsafeset formWrlsafeset stack-based overflow

A vulnerability was detected in Tenda F451 1.0.0.7. This impacts the function formWrlsafeset of the file /goform/AdvSetWrlsafeset. Performing a manipulation of the argument mit_ssid results in stack-based buffer overflow. The attack can be initiated remotely. The exploit is now public and may be us…

πŸ“… Published: April 9, 2026, 11 p.m. πŸ”„ Last Modified: April 9, 2026, 11 p.m.
Total resulsts: 343926
Page 26 of 34,393
Β« previous page Β» next page
Filters