Export limit exceeded: 23378 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (23378 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-104019 | 1 Aws | 1 Sagemaker-distribution | 2026-10-09 | 9 Critical |
| OS command injection in the Studio Space startup validation script in Amazon SageMaker Distribution 2.x before 2.14.12, 3.x before 3.9.12, 4.0.x before 4.0.11, 4.1.x before 4.1.11, 4.2.x before 4.2.8, 4.3.x before 4.3.5, and 4.4.x before 4.4.3, as used by Amazon SageMaker Unified Studio, might allow an authenticated remote user with project contributor permissions to execute arbitrary commands in another project member's Studio Space and obtain that member's temporary execution role credentials via a crafted connection resource property that is interpolated into a shell invocation without neutralization. To remediate this issue, users should upgrade to version 2.14.12, 3.9.12, 4.0.11, 4.1.11, 4.2.8, 4.3.5, or 4.4.3, as applicable to the minor line in use. Users on minor lines that have reached end of support must move to a supported minor line, because no patched version will be released for those lines. In Amazon SageMaker Unified Studio, Studio Spaces adopt the latest patch of their minor line on restart once the patched images are deployed, so no version selection is required. | ||||
| CVE-2026-82335 | 1 Ibm | 1 Guardium Data Protection | 2026-10-09 | 8.1 High |
| IBM Guardium Data Protection 12.0, 12.1, 12.2 is vulnerable to a heap-based buffer overflow in the MongoDB protocol parser. A remote attacker could send a specially crafted MongoDB SCRAM username containing an excessive length and cause memory corruption, potentially resulting in denial of service or arbitrary code execution. | ||||
| CVE-2026-107815 | 2026-10-09 | 8.5 High | ||
| MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, the CONNECT engine's DOS table type used an incorrect boundary check that permitted a one-byte null write beyond a stack buffer at an attacker-controlled offset. An authenticated user able to use the CONNECT engine could cause a crash and potentially remote code execution. This issue is fixed in versions 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2. | ||||
| CVE-2026-103005 | 1 Elastic | 1 Elasticsearch | 2026-10-09 | 6.5 Medium |
| Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with connector management privileges could cause the cluster to allocate an uncontrolled amount of memory when connector resources with an excessively large `description` field are created and subsequently accessed, exhausting available heap memory and crashing the affected node. | ||||
| CVE-2026-107704 | 1 Jtescher | 1 Image Optimizer | 2026-10-09 | 9.8 Critical |
| The image_optimizer Ruby gem 1.3.0 through 1.9.0 contains an OS command injection vulnerability in ImageOptimizer#identify_format that allows attackers to execute commands by supplying a crafted image path when the identify option is enabled. Attackers controlling the path, such as an uploaded file name, can append shell metacharacters like ';' that are executed via Ruby backticks with the Ruby process privileges. | ||||
| CVE-2026-20528 | 2 Mediatek, Mediatek, Inc. | 21 Mt2735, Mt2735 Firmware, Mt2737 and 18 more | 2026-10-09 | 6.7 Medium |
| In ccci, there is a possible out of bounds write and read due to a missing bounds check. This could lead to local information disclosure, memory corruption, crashes, or privilege escalation if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: ALPS11428950 (Note: For MT6880, MT6890) / ALPS10563453 (Note: For MT6980D, MT6990, MT6986, MT6986D, MT6813, MT6988) / AUTO00858766 (Note: For MT2735, MT2737); Issue ID: MSV-9893. | ||||
| CVE-2026-20529 | 2 Mediatek, Mediatek, Inc. | 57 Mt6761, Mt6761 Firmware, Mt6765 and 54 more | 2026-10-09 | 6.7 Medium |
| In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11276677; Issue ID: MSV-9217. | ||||
| CVE-2026-98272 | 1 Linux | 1 Linux Kernel | 2026-10-09 | 5.5 Medium |
| In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: prevent buffer overflow in page_pool allocation The per‑processor buffering scheme is supported only if the number of pools (nrxqs * 2) does not exceed MVPP2_BM_MAX_POOLS (8). This is already checked in mvpp2_probe() during the initial activation of percpu_pools. However, mvpp2_change_mtu() may later call mvpp2_bm_switch_buffers(priv, true) without this check, which can lead to an out-of-bounds access in the priv->page_pool array in mvpp2_bm_init(). The array is sized to hold MVPP2_PORT_MAX_RXQ entries, and mvpp2_get_nrxqs() may return exactly that value. The per-CPU scheme then doubles it to nrxqs * 2, exceeding the array bounds. Check that the hardware version is MVPP22 or newer and that the number of pools (nrxqs * 2) does not exceed MVPP2_BM_MAX_POOLS before switching to per-CPU mode. Found by Linux Verification Center (linuxtesting.org) with SVACE. | ||||
| CVE-2026-20530 | 2 Mediatek, Mediatek, Inc. | 23 Mt2718, Mt2718 Firmware, Mt6991 and 20 more | 2026-10-09 | 6.7 Medium |
| In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11292777; Issue ID: MSV-9195. | ||||
| CVE-2026-108106 | 1 Xerial | 1 Snappy-java | 2026-10-09 | 7.5 High |
| Xerial snappy-java before 1.1.10.9 contains an unbounded memory allocation vulnerability that allows attackers to exhaust JVM memory by declaring a large uncompressed length in compressed input. Attackers can supply a few crafted bytes to Snappy.uncompress, uncompressString, SnappyInputStream or SnappyFramedInputStream to force allocations up to 2 GB, causing OutOfMemoryError and denial of service. | ||||
| CVE-2026-12109 | 1 Ibm | 4 Security Verify Access, Security Verify Access Container, Verify Identity Access and 1 more | 2026-10-09 | 5.5 Medium |
| IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow an attacker with administrative privileges and access to the local management interface to execute arbitrary code due to an unbounded write to a fixed-size stack buffer. | ||||
| CVE-2026-82344 | 1 Ibm | 1 Guardium Data Protection | 2026-10-09 | 8.1 High |
| IBM Guardium Data Protection 12.0, 12.1 is vulnerable to a heap-based buffer overflow in the S-TAP TrafficTap TDS login reassembly functionality. An unauthenticated remote attacker can send crafted TDS login fragments that exceed the fixed-size reassembly buffer, potentially resulting in denial of service or arbitrary code execution on the affected system. | ||||
| CVE-2026-46569 | 1 Tuxera | 1 Ntfs-3g | 2026-10-09 | 7.7 High |
| In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ib_copy_tail(), in libntfs-3g/index.c, that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by extending a directory, e.g., by creating a file. | ||||
| CVE-2026-105401 | 1 Imagemagick | 1 Imagemagick | 2026-10-09 | 5.3 Medium |
| This CVE ID has been rejected as a duplicate. | ||||
| CVE-2026-105398 | 1 Imagemagick | 1 Imagemagick | 2026-10-09 | 5.1 Medium |
| This CVE ID has been rejected as a duplicate. | ||||
| CVE-2026-25273 | 1 Qualcomm | 103 Congo, Congo Firmware, Cq8845s and 100 more | 2026-10-09 | 6.7 Medium |
| Memory Corruption when processing camera operations due to out-of-bounds write during driver updates. | ||||
| CVE-2026-25272 | 1 Qualcomm | 311 Cologne, Cologne Firmware, Cq2390m and 308 more | 2026-10-09 | 6.7 Medium |
| Memory Corruption when processing camera CRE driver operations with improper handling of buffer limits during hardware update preparation. | ||||
| CVE-2026-25270 | 1 Qualcomm | 407 Cologne, Cologne Firmware, Congo and 404 more | 2026-10-09 | 6.7 Medium |
| Memory corruption when processing command buffer requests with invalid length parameters in the Android Camera driver. | ||||
| CVE-2026-25269 | 1 Qualcomm | 313 Cologne, Cologne Firmware, Cq2390m and 310 more | 2026-10-09 | 6.7 Medium |
| Memory corruption when processing camera requests with excessive batch and IO buffer configurations exceeds allocated memory size. | ||||
| CVE-2026-25263 | 1 Qualcomm | 333 5g Fixed Wireless Access Platform, 5g Fixed Wireless Access Platform Firmware, 9205 Lte Modem and 330 more | 2026-10-09 | 6.6 Medium |
| Memory corruption while processing IOCTL command called from user space to the kernel with invalid parameters. | ||||