2.3

CVSS3.1

CVE-2026-34764 - Electron has a use-after-free in offscreen shared texture release() callback

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 33.0.0-alpha.1 to before 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, apps that use offscreen rendering with GPU shared textures may be vulnerable to a use-after-free. Under certain condition…

πŸ“… Published: April 6, 2026, 3:46 p.m. πŸ”„ Last Modified: April 7, 2026, 4 p.m.

6.5

CVSS3.1

CVE-2026-34756 - vLLM Affected by Unauthenticated OOM Denial of Service via Unbounded `n` Parameter in OpenAI API Se…

vLLM is an inference and serving engine for large language models (LLMs). From 0.1.0 to before 0.19.0, a Denial of Service vulnerability exists in the vLLM OpenAI-compatible API server. Due to the lack of an upper bound validation on the n parameter in the ChatCompletionRequest and CompletionReques…

πŸ“… Published: April 6, 2026, 3:40 p.m. πŸ”„ Last Modified: April 7, 2026, 2:17 p.m.

6.5

CVSS3.1

CVE-2026-34755 - vLLM Affected by Denial of Service via Unbounded Frame Count in video/jpeg Base64 Processing

vLLM is an inference and serving engine for large language models (LLMs). From 0.7.0 to before 0.19.0, the VideoMediaIO.load_base64() method at vllm/multimodal/media/video.py splits video/jpeg data URLs by comma to extract individual JPEG frames, but does not enforce a frame count limit. The num_fr…

πŸ“… Published: April 6, 2026, 3:38 p.m. πŸ”„ Last Modified: April 7, 2026, 1:20 p.m.

5.4

CVSS3.1

CVE-2026-34753 - vLLM affected by Server-Side Request Forgery (SSRF) in `download_bytes_from_url `

vLLM is an inference and serving engine for large language models (LLMs). From 0.16.0 to before 0.19.0, a server-side request forgery (SSRF) vulnerability in download_bytes_from_url allows any actor who can control batch input JSON to make the vLLM batch runner issue arbitrary HTTP/HTTPS requests f…

πŸ“… Published: April 6, 2026, 3:36 p.m. πŸ”„ Last Modified: April 7, 2026, 2:15 p.m.

7.8

CVSS3.1

CVE-2026-21382 - Buffer Copy Without Checking Size of Input in Power Management IC

Memory Corruption when handling power management requests with improperly sized input/output buffers.

πŸ“… Published: April 6, 2026, 3:33 p.m. πŸ”„ Last Modified: April 9, 2026, 8:28 a.m.

7.6

CVSS3.1

CVE-2026-21381 - Buffer Over-read in WLAN Firmware

Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood awareness network protocol connection.

πŸ“… Published: April 6, 2026, 3:33 p.m. πŸ”„ Last Modified: April 9, 2026, 8:28 a.m.

7.8

CVSS3.1

CVE-2026-21380 - Use After Free in DSP Service

Memory Corruption when using deprecated DMABUF IOCTL calls to manage video memory.

πŸ“… Published: April 6, 2026, 3:33 p.m. πŸ”„ Last Modified: April 9, 2026, 8:28 a.m.

7.8

CVSS3.1

CVE-2026-21378 - Buffer Over-read in Camera

Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.

πŸ“… Published: April 6, 2026, 3:33 p.m. πŸ”„ Last Modified: April 9, 2026, 8:28 a.m.

7.8

CVSS3.1

CVE-2026-21376 - Buffer Over-read in Camera

Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.

πŸ“… Published: April 6, 2026, 3:33 p.m. πŸ”„ Last Modified: April 9, 2026, 8:28 a.m.

7.8

CVSS3.1

CVE-2026-21375 - Buffer Over-read in Camera

Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.

πŸ“… Published: April 6, 2026, 3:33 p.m. πŸ”„ Last Modified: April 9, 2026, 8:28 a.m.
Total resulsts: 345119
Page 261 of 34,512
Β« previous page Β» next page
Filters