Search

Found 11,014 results in 1684ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-8957 high 8.8 8.8 FIX rheldebian debian sles mozilla 8d ago Important: thunderbird security update
CVE-2026-8955 high 8.8 8.8 FIX rheldebian debian sles mozilla 8d ago Important: thunderbird security update
CVE-2026-8954 high 7.5 7.5 FIX rheldebian debian sles mozilla 8d ago Important: thunderbird security update
CVE-2026-8947 high 7.3 7.3 FIX rheldebian debian sles mozilla 8d ago Important: thunderbird security update
CVE-2026-8946 high 7.5 7.5 FIX rheldebian debian sles mozilla 8d ago Important: thunderbird security update
CVE-2026-34043 high 8.0 FIX rheldebian debianalmalinux almalinux 8d ago RHSA-2026:21291: .NET 8.0 security update (Important)
CVE-2025-70103 high 7.3 7.3 slesdebian debian 8d ago Heap buffer overflow vulnerability in libjxl 0.12.0 via crafted PBM images to the jxl::extras::DecodeImagePNM function in file lib/extras/dec/pnm.cc.
CVE-2026-44983 high 7.3 7.3 FIX debian debian 9d ago smallbitvec is a growable bit-vector for Rust, optimized for size. From 1.0.1 to 2.6.0, an integer overflow in the internal capacity calculation of smallbitvec can lead to an undersized heap allocati…
CVE-2026-42013 high 8.2 8.2 FIX debian debian sles rhel 9d ago RHSA-2026:20612: gnutls security update (Important)
CVE-2026-42012 high 7.1 7.1 FIX debian debian rhelwindows windows 9d ago RHSA-2026:20612: gnutls security update (Important)
CVE-2026-5260 high 8.2 8.2 FIX debian debian sles rhel 9d ago RHSA-2026:20612: gnutls security update (Important)
CVE-2026-9572 low 3.3 3.3 debian debian gpac 9d ago A security vulnerability has been detected in GPAC up to 2.4.0. Affected by this issue is the function Media_GetSample of the file src/isomedia/media.c of the component MP4Box. Such manipulation of t…
CVE-2026-9567 low 3.3 3.3 debian debian 9d ago A security flaw has been discovered in GPAC up to 2.4.0. Affected is the function MergeFragment of the file src/isomedia/isom_intern.c of the component MP4Box. The manipulation results in null pointe…
CVE-2026-48695 high 8.1 8.1 FIX debian debian pavel-odintsov 9d ago FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the MikroTik router integration plugin. The _log() function in src/mikrotik_plugin/fastnetmon_mikrotik.php…
CVE-2026-48694 high 8.1 8.1 FIX debian debian pavel-odintsov 9d ago FastNetMon Community Edition through 1.2.9 contains a configuration injection vulnerability in the Juniper router integration plugin. In src/juniper_plugin/fastnetmon_juniper.php, the $IP_ATTACK vari…
CVE-2026-44728 high 8.2 8.2 slesdebian debian babel 9d ago Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was specifically crafted by an attacker can cause Babel t…
CVE-2026-48864 high 7.8 7.8 debian debian sles rhel opensuseredhat 9d ago A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker ca…
CVE-2026-48697 high 7.4 7.4 debian debian pavel-odintsov 9d ago FastNetMon Community Edition through 1.2.9 does not verify TLS certificates on outbound HTTPS connections. The execute_web_request_secure() function in src/fast_library.cpp creates a boost::asio::ssl…
CVE-2026-48690 high 7.1 7.1 FIX debian debian pavel-odintsov 9d ago FastNetMon Community Edition through 1.2.9 contains an integer overflow vulnerability in the packet capture buffer allocation. In src/packet_storage.hpp, the allocate_buffer() function computes memor…
CVE-2026-48692 high 8.1 8.1 debian debian pavel-odintsov 9d ago FastNetMon Community Edition through 1.2.9 exposes a gRPC API server on port 50052 with no authentication mechanism. The server is initialized with grpc::InsecureServerCredentials() (src/fastnetmon.c…
CVE-2026-48688 high 7.5 7.5 FIX debian debian pavel-odintsov 9d ago FastNetMon Community Edition through 1.2.9 contains multiple out-of-bounds reads in the BGP MP_REACH_NLRI IPv6 attribute decoder. The function decode_mp_reach_ipv6() in src/bgp_protocol.cpp contains …
CVE-2026-40033 high 8.8 8.8 FIX slesdebian debian freerdp 9d ago FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers to write out-of-bounds heap memory. The vulnerability occurs because rectangle v…
CVE-2026-9538 high 7.5 7.5 debian debianwindows windows archive\ 9d ago Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header. _read_tar() reads each entry's payload with $handle->read($$data, $block), …
CVE-2026-42497 high 7.5 7.5 debian debianwindows windows archive\ 9d ago Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory. _make_special_file() passes the tar header's linkname to link() without va…
CVE-2026-8092 high 8.1 8.1 FIX rheldebian debian sles mozilla 9d ago Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of th…
CVE-2026-8090 high 7.3 7.3 FIX rheldebian debian sles mozilla 9d ago Use-after-free in the DOM: Networking component. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2.
CVE-2026-42014 high 8.0 FIX debian debian sles rhel 9d ago RHSA-2026:20612: gnutls security update (Important)
CVE-2026-48852 low 3.7 3.7 FIX debian debian putty 10d ago PuTTY 0.71 before 0.84 has an assertion failure in ECDSA signature verification.
CVE-2026-48851 low 3.1 3.1 FIX debian debian putty 10d ago PuTTY 0.77 before 0.84 uses a copy of the PuTTY icon as a trust indication for TELNET data but the trust status is not cleared between proxy authentication and the main session.
CVE-2026-48848 high 7.2 7.2 FIX debian debian 10d ago Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element…
CVE-2026-48847 low 3.7 3.7 FIX debian debian 10d ago Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass.
CVE-2026-48844 high 7.5 7.5 FIX debian debian 10d ago Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could lead to code injection. (Support for code evaluation has been …
CVE-2026-48843 high 7.2 7.2 FIX debian debian 10d ago Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure,…
CVE-2026-48842 high 8.1 8.1 FIX debian debian 10d ago Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.
CVE-2026-48832 low 3.5 3.5 FIX debian debian 10d ago action/cookie.php in ecrire in SPIP before 4.4.15 is prone to an open redirect vulnerability.
CVE-2026-48829 high 7.5 7.5 FIX debian debian sles 11d ago In GNU SASL before 2.2.3, DIGEST-MD5 has a NULL pointer dereference affecting both clients and servers, via a known token with no accompanying = character. This occurs in lib/digest-md5/getsubopt.c.
CVE-2026-43503 high 8.8 8.8 FIX slesdebian debianwindows windows 12d ago In the Linux kernel, the following vulnerability has been resolved: net: skbuff: propagate shared-frag marker through frag-transfer helpers Two frag-transfer helpers (__pskb_copy_fclone() and skb_s…
CVE-2026-41076 high 8.1 8.1 FIX debian debian 13d ago RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.9 and prior in addition to 6.0.0 through 6.0.2 contain an authentication bypass vulnerability in RT installations…
CVE-2026-41075 high 8.8 8.8 FIX debian debian 13d ago RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 through 5.0.9 and 6.0.0 through 6.0.2 contain an SQL injection vulnerability. An authenticated user can craft i…
CVE-2026-41074 high 7.1 7.1 FIX debian debian 13d ago RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 through 6.0.2 contain a Cross-Site Request Forgery (CSRF) vulnerability. An attacker who can induce a logged-in…
CVE-2026-41071 high 8.1 8.1 debian debian sles struktur 13d ago libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a crafted HEIF sequence file where the saiz box declares more samples than actually exist in the track's chun…
CVE-2026-39824 low 3.3 3.3 FIX debian debianwindows windows 13d ago NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum size of a NTUnicodeString (a 16-bit number of bytes), it returns a truncated strin…
CVE-2026-9256 high 8.1 8.1 FIX slesdebian debianwindows windows 13d ago NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Co…
CVE-2026-9277 high 8.1 8.1 FIX slesdebian debian 13d ago shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-escaped character by character using `/(.)/g`, which …
CVE-2026-46597 high 7.5 7.5 FIX debian debian sleswindows windows golang 13d ago An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
CVE-2026-39829 high 7.5 7.5 FIX debian debian sleswindows windows golang 13d ago The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumptio…
CVE-2026-43502 high 7.8 7.8 FIX slesdebian debianwindows windows 14d ago In the Linux kernel, the following vulnerability has been resolved: net/rds: handle zerocopy send cleanup before the message is queued A zerocopy send can fail after user pages have been pinned but…
CVE-2026-43499 high 7.8 7.8 FIX slesdebian debianwindows windows 14d ago In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter() is used by the slowlock paths, but it is also use…
CVE-2026-43498 high 7.8 7.8 FIX slesdebian debian 14d ago In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Disallow re-exporting imported GEM objects Prevent re-exporting of imported GEM buffers by adding a custom prime_hand…
CVE-2026-43497 high 7.3 7.3 FIX slesdebian debianwindows windows 14d ago In the Linux kernel, the following vulnerability has been resolved: fbdev: udlfb: add vm_ops to dlfb_ops_mmap to prevent use-after-free dlfb_ops_mmap() uses remap_pfn_range() to map vmalloc framebu…
CVE-2026-43495 high 8.8 8.8 FIX slesdebian debianwindows windows 14d ago In the Linux kernel, the following vulnerability has been resolved: net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler t7xx_port_enum_msg_handler() uses the m…
CVE-2026-43494 high 7.8 7.8 FIX slesdebian debianwindows windows 14d ago In the Linux kernel, the following vulnerability has been resolved: net/rds: reset op_nents when zerocopy page pin fails When iov_iter_get_pages2() fails in rds_message_zcopy_from_user(), the pinne…
CVE-2026-42002 high 7.5 7.5 FIX debian debian powerdns 14d ago Concurrency and locking defects in GSS-TSIG
CVE-2026-42001 high 7.5 7.5 FIX debian debian powerdns 14d ago Insufficient Validation of Autoprimary SOA Queries
CVE-2026-42000 high 8.6 8.6 FIX debian debian powerdns 14d ago Insufficient Validation of Names During AXFR
CVE-2026-7837 low 3.7 3.7 FIX slesdebian debian 14d ago A time-of-check time-of-use (TOCTOU) condition in the ad_flush function in Netatalk 3.0.0 through 4.4.2 involves root-privileged file operations, which may allow a remote attacker to cause limited da…
CVE-2026-44075 low 3.7 3.7 FIX slesdebian debian 14d ago A missing break statement in DSI OpenSession processing in Netatalk 1.5.0 through 4.4.2 causes a DSIOPT_ATTNQUANT switch case to fall through into DSIOPT_SERVQUANT, resulting in unintended session op…
CVE-2026-44074 low 3.7 3.7 FIX slesdebian debian 14d ago Netatalk 2.1.0 through 4.4.2 combines multiple errno values using bitwise OR, resulting in incorrect error codes when multiple error conditions occur simultaneously, which may allow a remote attacker…
CVE-2026-44071 low 3.7 3.7 FIX slesdebian debian 14d ago Netatalk 3.1.2 through 4.4.2 is compiled without FORTIFY_SOURCE, which disables built-in buffer overflow detection at runtime, potentially allowing a remote attacker to cause a minor denial of servic…
CVE-2026-44057 low 3.1 3.1 FIX slesdebian debian 14d ago A dead bounds check in the Spotlight RPC unmarshaller in Netatalk 3.0.0 through 4.4.2 results in an unreachable code path that provides no effective bounds protection, which may allow a remote authen…
CVE-2026-7836 low 3.1 3.1 FIX slesdebian debian 14d ago An incorrect calculation in the hextoint macro in Netatalk 2.0.0 through 4.4.2 due to improper uppercase character handling allows a remote authenticated attacker to cause limited data modification v…
CVE-2026-7835 low 3.1 3.1 FIX slesdebian debian 14d ago A format string argument mismatch in Netatalk 3.0.3 through 4.4.2 allows a remote authenticated attacker to cause a minor denial of service via crafted input that triggers incorrect format string pro…
CVE-2026-44072 low 3.0 3.0 FIX slesdebian debian 14d ago Netatalk 2.2.1 through 4.4.2 calls system() after a failed chdir() without properly handling the error condition, which allows a local privileged user to execute unintended commands or cause a minor …
CVE-2026-44070 low 3.1 3.1 FIX slesdebian debian 14d ago An unbounded memory reallocation in the charset conversion code in Netatalk 2.0.0 through 4.4.2 allows a remote authenticated attacker to cause a minor denial of service via crafted character convers…
CVE-2026-44069 low 3.9 3.9 FIX slesdebian debian 14d ago An integer underflow in the volxlate function in Netatalk 3.0.0 through 4.4.2 allows a local privileged user to obtain limited information, modify limited data, or cause a minor service disruption vi…
CVE-2026-44068 high 7.6 7.6 FIX slesdebian debian 14d ago Incomplete sanitization of extended attribute (EA) path components in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated attacker to write to files outside the intended metadata namespace via…
CVE-2026-44066 high 7.1 7.1 FIX slesdebian debian 14d ago Multiple heap out-of-bounds reads in the Spotlight RPC unmarshalling code in Netatalk 3.1.0 through 4.4.2 allow a remote authenticated attacker to obtain sensitive information or cause a minor servic…
CVE-2026-44064 high 7.1 7.1 FIX slesdebian debian 14d ago An out-of-bounds read in ASP session ID handling in Netatalk 1.3 through 4.4.2 allows an adjacent network attacker to obtain limited information or cause a denial of service via a crafted ASP request.
CVE-2026-44062 high 7.5 7.5 FIX slesdebian debian 14d ago A missing output length bounds check in pull_charset_flags() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code or cause a denial of service via crafted …
CVE-2026-44060 high 7.5 7.5 FIX slesdebian debian 14d ago An integer underflow in dsi_writeinit() in Netatalk 1.5.0 through 4.4.2 allows a remote unauthenticated attacker to cause a denial of service via a crafted DSI write request.
CVE-2026-44058 high 7.2 7.2 FIX slesdebian debian 14d ago An authentication bypass vulnerability in Netatalk 2.2.2 through 4.4.2 allows a remote privileged user to authenticate as an arbitrary user via the admin auth user mechanism.
CVE-2026-44055 high 7.5 7.5 FIX slesdebian debian 14d ago A logic error involving bitwise OR operations in Netatalk 3.1.4 through 4.4.2 allows a remote authenticated attacker to inject OS commands and execute arbitrary code.
CVE-2026-44053 high 7.4 7.4 FIX slesdebian debian 14d ago Netatalk 1.5.0 through 4.2.2 uses a broken cryptographic algorithm in the DHCAST128 UAM, which allows a remote attacker to obtain authentication credentials or impersonate a user via cryptanalytic at…
CVE-2026-44052 high 7.5 7.5 FIX slesdebian debian 14d ago Netatalk 2.1.0 through 4.4.2 inserts LDAP simple-bind passwords into log output in cleartext, which allows an attacker with access to the log files to obtain LDAP credentials.
CVE-2026-44051 high 8.1 8.1 FIX slesdebian debian 14d ago An improper link resolution vulnerability in Netatalk 3.0.2 through 4.4.2 allows a remote authenticated attacker to read arbitrary files or overwrite arbitrary files via attacker-controlled symlink c…
CVE-2026-44049 high 7.5 7.5 FIX slesdebian debian 14d ago An out-of-bounds write due to improper null termination in convert_charset() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code or cause a denial of serv…
CVE-2026-44048 high 8.8 8.8 FIX slesdebian debian 14d ago A stack-based buffer overflow via UCS-2 type confusion in convert_charset() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code or cause a denial of servi…
CVE-2026-44047 high 8.8 8.8 FIX slesdebian debian 14d ago An SQL injection vulnerability in the MySQL CNID backend in Netatalk 3.1.0 through 4.4.2 allows a remote authenticated attacker to obtain unauthorized access to data, modify data, or cause a denial o…
CVE-2026-8632 high 7.8 7.8 FIX debian debian sles hp 15d ago A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalation of privileges and/or arbitrary code execution v…
CVE-2026-47373 high 7.5 7.5 FIX debian debian 15d ago Crypt::SaltedHash versions through 0.09 for Perl is susceptible to timing attacks. These versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess the underlying has…
CVE-2026-9126 high 8.8 8.8 FIX debian debianmacos macos linux-kernel google 15d ago Use after free in DOM in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-9123 high 7.5 7.5 FIX debian debian linux-kernelwindows windows google 15d ago Heap buffer overflow in Chromecast in Google Chrome on Android, Linux, ChromeOS prior to 148.0.7778.179 allowed a local attacker to execute arbitrary code inside a sandbox via malicious network traff…
CVE-2026-9121 high 8.8 8.8 FIX debian debianmacos macos linux-kernel google 15d ago Out of bounds read in GPU in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-9120 high 8.8 8.8 FIX debian debianmacos macos linux-kernel google 15d ago Use after free in WebRTC in Google Chrome prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
CVE-2026-9119 high 8.8 8.8 FIX debian debianmacos macos linux-kernel google 15d ago Heap buffer overflow in WebRTC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: H…
CVE-2026-9118 high 8.8 8.8 FIX debian debianmacos macos linux-kernel google 15d ago Use after free in XR in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
CVE-2026-9117 high 7.5 7.5 FIX debian debian linux-kernelwindows windows google 15d ago Type Confusion in GFX in Google Chrome on Linux, ChromeOS prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a craf…
CVE-2026-9114 high 8.8 8.8 FIX debian debianmacos macos linux-kernel google 15d ago Use after free in QUIC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via malicious network traffic. (Chromium security severity: Hig…
CVE-2026-9112 high 8.8 8.8 FIX debian debianmacos macos linux-kernel google 15d ago Use after free in GPU in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Hi…
CVE-2026-9111 high 8.8 8.8 FIX debian debianmacos macos linux-kernel google 15d ago Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
CVE-2026-5946 high 7.5 7.5 FIX debian debian sleswindows windows isc 15d ago Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes…
CVE-2026-3039 high 7.5 7.5 FIX debian debian sleswindows windows isc 15d ago BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption when receiving and processing maliciously-constructed packets. Typ…
CVE-2026-29518 high 7.0 7.0 FIX slesdebian debianwindows windows samba 15d ago Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replac…
CVE-2026-9064 high 7.5 7.5 debian debian sles rhel redhat 15d ago A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated a…
CVE-2026-42959 high 7.5 7.5 FIX slesdebian debianwindows windows nlnetlabs 15d ago NLnet Labs Unbound up to and including version 1.25.0 has a denial of service vulnerability in the DNSSEC validator that can lead to a crash given malicious upstream replies. When Unbound constructs …
CVE-2026-42944 high 7.5 7.5 FIX slesdebian debianwindows windows nlnetlabs 15d ago NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vulnerability that results in heap overflow when encoding multiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options in the re…
CVE-2026-41292 high 7.5 7.5 FIX slesdebian debianwindows windows nlnetlabs 15d ago NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to a degradation of service attack related to parsing long lists of incoming EDNS options. An adversary sending queries with too ma…
CVE-2026-41054 high 7.8 7.8 FIX debian debian sleswindows windows 15d ago In `src/havegecmd.c`, the `socket_handler` function performs a credential check on the abstract UNIX socket (`\0/sys/entropy/haveged`). However, while it detects if the connecting user is not root (`…
CVE-2026-40622 high 7.5 7.5 FIX slesdebian debianwindows windows nlnetlabs 15d ago NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of attacks that could extend the ghost domain window by up to one cached TTL config…
CVE-2026-46640 high 8.0 FIX debian debian 15d ago Twig: Arbitrary PHP code execution via `_self.(<string>)` macro-reference compilation