Export limit exceeded: 10124 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 23396 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (23396 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-92531 | 1 Bugtracker.net | 1 Bugtracker.net | 2026-10-07 | N/A |
| Operating system command injection vulnerability in the SVN integration component of BugTracker.NET. The application incorporates the value of the field corresponding to the repository into an svn.exe command without properly validating it. An authenticated user with administrator privileges could store manipulated arguments in the database and subsequently cause them to be processed by the revision comparison functionality. A successful exploit could allow the execution of arbitrary commands with the privileges of the account used by the application. To exploit this vulnerability, svn.exe must be installed and capable of being invoked by the service. | ||||
| CVE-2026-106057 | 1 Wummel | 1 Patool | 2026-10-07 | 7.8 High |
| patool before 4.0.6 contains an OS command injection vulnerability on Windows because shell_quote_nt fails to escape cmd.exe metacharacters or embedded double quotes in archive filenames. Attackers can supply crafted filenames like report&calc.gz for single-file formats run with shell=True to execute commands with patool process privileges. | ||||
| CVE-2026-102120 | 2 Accellion, Kiteworks | 2 Kiteworks, Core | 2026-10-07 | 8.8 High |
| A privilege escalation vulnerability in Kiteworks could have allowed an attacker who had already obtained code execution on one node of a clustered Kiteworks deployment to run operating system commands with elevated privileges on another node of the same cluster. Insufficient input validation in an internal cluster management function let attacker-supplied values reach a privileged execution context; exploitation requires existing access to a node in the cluster, and the affected function is not reachable from outside the cluster. | ||||
| CVE-2026-102114 | 2 Accellion, Kiteworks | 2 Kiteworks, Core | 2026-10-07 | 7.2 High |
| A command injection vulnerability in Kiteworks could allow a high-privileged authenticated administrator to execute arbitrary operating-system commands as root on the affected appliance node. Successful exploitation requires an administrative account with elevated privileges. | ||||
| CVE-2026-102112 | 2 Accellion, Kiteworks | 2 Kiteworks, Core | 2026-10-07 | 7.8 High |
| A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained code execution as an unprivileged backend service account on the appliance to escalate to root and run arbitrary commands with the highest privileges. Exploitation requires existing local access to that service account. | ||||
| CVE-2026-106401 | 1 Google | 1 Chrome | 2026-10-07 | 9.6 Critical |
| Out of bounds write in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-102096 | 2 Accellion, Kiteworks | 2 Kiteworks, Core | 2026-10-07 | 7.2 High |
| Kiteworks Core before version 9.5.0 is vulnerable to OS Command Injection that allows an authenticated administrator to upload a configuration package whose contents were not sufficiently validated before being processed. A crafted package could cause the underlying system to execute arbitrary operating-system commands, potentially with elevated privileges, on the affected appliance. | ||||
| CVE-2026-49878 | 1 Google | 1 Android | 2026-10-07 | 7.2 High |
| In wpas_handle_robust_av_scs_recv_action of robust_av.c, there is a possible out-of-bounds write due to a logic error in the code. This could lead to remote code execution with System execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-93520 | 2026-10-07 | 7.8 High | ||
| A flaw was found in xorg-x11-server. In the X Keyboard Extension (XKB), key name memory is allocated with an insufficient buffer size compared to the maximum supported range. An authenticated local client can exploit this flaw by sending requests that modify the keycode range, triggering a heap-based buffer overflow. This vulnerability can lead to arbitrary code execution or cause a Denial of Service (DoS) by crashing the X server. | ||||
| CVE-2026-93521 | 2026-10-07 | 7.8 High | ||
| A flaw was found in xorg-x11-server. The X server incorrectly calculates buffer sizes and memory offsets when prepending or appending data to RandR (Resize and Rotate extension) provider properties. A local attacker can exploit this vulnerability by sending specially crafted property update requests, causing memory corruption. This flaw could allow an attacker to escalate privileges or cause a denial of service (DoS) by crashing the X server. | ||||
| CVE-2026-93518 | 2026-10-07 | 7.8 High | ||
| A flaw was found in xorg-x11-server. Due to an integer truncation issue during memory allocation calculations within the X Keyboard Extension (XKB), the server allocates an undersized buffer when resizing key types. An authenticated local client can exploit this vulnerability by sending specially crafted XKB requests, causing a heap-based buffer overflow. This can result in arbitrary code execution or a denial of service (DoS). | ||||
| CVE-2026-93523 | 2026-10-07 | 7.8 High | ||
| A flaw was found in xorg-x11-server. A local authenticated client can exploit this flaw by sending a crafted input device ungrab request with an unvalidated modifier value. This lack of validation causes the server to perform an out-of-bounds write on the heap, resulting in memory corruption that can lead to a denial of service (DoS) or potential arbitrary code execution. | ||||
| CVE-2026-93519 | 2026-10-07 | 7.8 High | ||
| A flaw was found in xorg-x11-server. The server writes pointer barrier events into a fixed-size buffer without properly validating boundaries. An authenticated client can trigger this issue by configuring excessive pointer barriers and generating cursor motion events, causing a buffer overflow. This vulnerability may lead to arbitrary code execution or cause the server to crash, resulting in a Denial of Service (DoS). | ||||
| CVE-2026-106452 | 1 Yawkat | 1 Lz4-java | 2026-10-07 | 5.3 Medium |
| yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, net.jpountz.lz4.LZ4BlockInputStream refill() validates that the compressedLen field in a legacy LZ4Block header is nonnegative but allocates a compressed-input buffer of that attacker-controlled size before reading payload data, allowing a header-only stream to request a near-2 GiB allocation and exhaust the JVM heap. Canonical writers emit raw blocks when compression is not smaller than the original block, but vulnerable readers accept non-canonical oversized compressed blocks. This issue is fixed in version 1.11.2. | ||||
| CVE-2026-98318 | 1 Linux | 1 Linux Kernel | 2026-10-07 | 7.8 High |
| In the Linux kernel, the following vulnerability has been resolved: smb: client: validate absolute native symlink targets before NT fixups With symlinkroot unset, an absolute target is copied without conversion to an NT drive path. Later code still assumes an NT prefix is present when modifying the target and calculating the print name length. For "/ab", this causes two failures: sym[5] and path[5] are written past their allocations, and plen -= 2 * poff subtracts an assumed 8-byte prefix from a 6-byte UTF-16 target, wrapping u16 plen to 65534. That underflow causes another overflow: memcpy() copies 65534 bytes into a 24-byte buffer. A user with write access to a mounted share can trigger these bugs with default settings. Validate the NT drive prefix, including an ASCII drive letter, before accessing fixed offsets or subtracting the prefix length. | ||||
| CVE-2026-98323 | 1 Linux | 1 Linux Kernel | 2026-10-07 | 9.8 Critical |
| In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Bound fragmented header copies by the remaining length siw_get_hdr() can receive an extended DDP/RDMAP header across more than one TCP callback. The first callback may receive most of the header, while the next one still limits the copy to hdrlen - MIN_DDP_HDR instead of the number of missing bytes. This makes the destination move past the end of the header and overwrite the receive state, including fpdu_part_rcvd. A later callback can then use a negative fpdu_part_rcvd value as a copy offset, which creates an OOB write. Use the number of header bytes already received when calculating the next copy length. | ||||
| CVE-2026-77178 | 1 Oracle | 1 Virtualbox | 2026-10-07 | 9.1 Critical |
| Oracle VM VirtualBox before 7.2.8 allows guest OS users to cause an out-of-bounds write in the host OS in pcnetReceiveNoSync in DevPCNet.cpp in the PCNet (Am79C970A) network device model. | ||||
| CVE-2026-98371 | 1 Linux | 1 Linux Kernel | 2026-10-07 | 5.5 Medium |
| In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: fix runt reassembly panic from short inner tot_len When the start of an inner packet is split across two outer packets such that fewer than 4 bytes land at the end of the first one, __input_process_payload() saves those bytes as a runt and skips the iplen/iphlen validation performed for in-place packets. When the continuation packet arrives, iptfs_reassem_cont() only requires the declared inner length to be >= sizeof(ra_runt) (6) before allocating the reassembly skb with that attacker-controlled length. However, __iptfs_iphlen() always returns the fixed minimum IP header size (20 for IPv4, 40 for IPv6), so for an inner IPv4 tot_len in [6, 19] the header-completion copy writes past the declared packet length, and the subsequent "ipremain -= copylen" underflows to ~4GB, leaving the payload copy length bounded only by blkoff (up to 64KB). At runtime the skb_put() tailroom check turns this into skb_over_panic(), i.e. an unprivileged kernel panic (DoS), reachable locally via userns+netns IPTFS SAs and remotely against IPTFS VPN gateways when the decrypted outer skb is linear (e.g. AF_PACKET taps, tun/tap delivery). Align the runt path with the normal path by requiring the declared inner length to cover at least the IP header size. This also subsumes the previous >= sizeof(ra_runt) check, since the minimum IP header is always larger than the runt buffer. This issue was found by the autokbug dynamic kernel fuzzer at Tencent Yunding Lab. | ||||
| CVE-2026-73570 | 2 Synacor, Zimbra | 2 Zimbra Collaboration Suite, Collaboration | 2026-10-07 | 8.9 High |
| A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user. | ||||
| CVE-2026-77050 | 1 Djangoproject | 1 Django | 2026-10-07 | 5.3 Medium |
| An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. `django.utils.translation.get_supported_language_variant()` is subject to a potential denial-of-service attack when processing many distinct, very long language codes, which are retained as keys in an in-memory cache and consume process memory. Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected. Django would like to thank Gleb Lizunov for reporting this issue. | ||||