'Gripping' Netflix thriller with near-perfect Rotten Tomatoes score leaves viewers in tears with new series ending txtify archive
Tragedy after mother gave son, 10, huge dose of Benadryl to deal with his behavioral issues, deputies say txtify archive
Anne's special role at the late Queen's centenary - as the hardworking Princess Royal remembers the life of her beloved mother txtify archive
Eric Holder accuses GOP of 'stealing seats' while defending 'fair' Democratic redistricting push txtify archive
Louisiana gunman's disturbing phone call to parents about wife's divorce demand shortly before he executed his seven children and nephew txtify archive
Audit of Meghan Markle's 'royal tour' wardrobe exposes a worrying truth… this is everything the Palace always feared: JANE TIPPETT txtify archive
'Unbothered' Aussie steals the show from Harry and Meghan after footage captured priceless moment at the beach: 'Give her a medal' txtify archive
Discovering my toddler has dementia was the worst moment of my life... so when a test revealed her unborn sibling also had the disease we had no choice but to terminate my pregnancy txtify archive
Michael Jordan stuns NASCAR fans again as he grabs co-owner's throat... months after viral interaction with driver's six-year-old son txtify archive
WNBA star Paige Bueckers breaks her silence after Dallas drafted her girlfriend to become new teammate txtify archive
Charles Barkley derails 'Inside the NBA' with wild Ice Spice rant after her McDonald's brawl... leaving co-hosts stunned txtify archive
Madman who shoved commuter into path of train says SORRY at sentencing and reveals why he did it txtify archive
Beloved teacher, 65, who devoted her life to helping disabled children had terrible secret, prosecutors say txtify archive
Meghan 'very frustrated' by MasterChef: Duchess was unhappy when co-stars called her 'royalty' on camera - as she made appearance on show during their 'private' Australian tour txtify archive
Top NFL prospect's draft status revealed by league insider after shock arrest threw his future into doubt txtify archive
Coachella 2026 WORST dressed: Paris Hilton and James Charles among stars making the biggest fashion faux pas on weekend two txtify archive
'80s movie queen Jami Gertz, 60, who acted with Robert Downey Jr and is now worth $8bn, makes rare outing txtify archive
Hunt for mysterious white pickup truck that's terrifying women on Montana's empty highways txtify archive
Search for 11 missing nuclear scientists escalates as top lawmakers reveal NEW 'national security' fears txtify archive
FedEx driver Tanner Horner sang 'Jingle Bell Rock' while killing seven-year-old Athena Strand in back of his truck after abducting her txtify archive
Former Army National Guardsman who killed EIGHT kids in horror Louisiana rampage was father to some of the victims txtify archive
FBI Director Kash Patel SUES The Atlantic magazine over 'defamatory' article claiming he has serious alcohol problem txtify archive
Hawaii tourist charged with attempted murder, accused of stabbing veteran boat captain on snorkel tour txtify archive
Biggest celebrity freeloaders named by industry snitches: The TV star 'desperate for cash'... 'thirsty' divorcee... and A-lister who declared best thing about being famous is 'free s***' txtify archive
Trump's shocking Iran nuclear retreat after screaming at top generals in hours-long meltdown txtify archive
The late Queen and Prince Philip were a 'double act' who embraced a blended Royal Family, claims expert ahead of centenary txtify archive
Dark truth about Coachella brand houses and activations... as festival snitches name and shame influencers txtify archive
Russian commander forces refusenik soldier to crawl like a dog, eat dirt and threatens to strap a landmine to him in leaked torture footage txtify archive
Do YOU know what the royals really sound like? You know their faces so well, now try our interactive quiz to see if you could pick out their voices in a crowd txtify archive
Lena Dunham is not a genius or an inspiration. She's a morbidly obese, self-obsessed mediocrity... with a very disturbing past: MAUREEN CALLAHAN txtify archive
Days Of Our Lives star Patrick Muldoon dies aged 57: Melrose Place actor passes away after suffering a heart attack at home txtify archive
Madonna fans rush to her defence as they praise 'iconic' singer, 67, for 'keeping up' with Sabrina Carpenter, 26, during Coachella performance following 'ageist and misogynistic' backlash and cruel calls to retire txtify archive
San Francisco 49ers star agrees huge $50MILLION contract amid fears they'd be forced to trade him txtify archive
College football skydiver reveals cause of his horrifying accident... and what saved him from certain death txtify archive
Sarah Ferguson weighs up £1.3million tell-all TV documentary as she 'needs the money' - after being found hiding away in £2,000-a-night Austrian health clinic txtify archive
Supreme Court to hear Catholic parish's challenge after Colorado barred schools from universal pre-K program txtify archive
Spain throws open its doors to undocumented migrants: Huge queues continue to form after socialist government granted citizenship to 500,000 people txtify archive
Tsunami alert for Japan after 7.5-magnitude earthquake - with 10ft waves expected and coastal regions told to evacuate txtify archive
My sources very close to key Supreme Court justices spill their secret summer resignation plans: JAMES ROSEN txtify archive
Horrifying moment fan falls down the stands at WrestleMania to leave onlookers stunned txtify archive
The varied fates of the Little Miss Sunshine cast: From Oscar nominations to a high-profile showbiz feud and a tragic death - as film marks 20th anniversary txtify archive
The fungus that could contaminate Mars: Scientists discover spore that can survive trip to the Red Planet - and NASA's ultra-sanitised cleanrooms aren't enough to stop it txtify archive
Reauthorization of Small Business Innovation Research and Technology Transfer Programs txtify archive
A US tech agenda focused on Latin America to outcompete the People’s Republic of China txtify archive
Millionaire parents and their two sons aged 28 and 30 die in private plane crash while flying home to Alabama mansion txtify archive
Jude Law is praised for 'Oscar-worthy' depiction of Vladimir Putin in The Wizard of the Kremlin - as critics laud 'bonkers but brilliant' casting and 'ex-pretty boy's' gritty career renaissance txtify archive
Can walnuts truly be crowned 'the healthiest nut'? How the brain-shaped kernels can lower cholesterol, help to protect against depression AND prevent mindless snacking txtify archive
Humiliation for Nike as it's forced to take down Boston Marathon sign after furious backlash txtify archive
Eagles superstar AJ Brown is 'likely' to be traded to the Patriots, bombshell report claims txtify archive
Unfiltered confessions of a secret mistress: My affair with an older cowboy was electric... but this is what no one dares tell you about being the 'other woman' txtify archive
I found proof my beautiful wife was cheating while inspecting her laundry... now I need a plan to get back the $150k I used to pay off her debts txtify archive
Stunning countryside mansion with ties to Henry VIII and its own castle ruins goes on sale for £2.25million txtify archive
The world's most family-friendly landmarks revealed - with six UK spots making the top 50 txtify archive
Wild moment brawl breaks out in front of shocked customers at Sydney hairdressers - and the ridiculous reason that allegedly sparked it txtify archive
I loved to wind down with a couple of glasses of wine every night - until I was told I had liver disease at just 47. I gave up alcohol for a year and lost three stone - but this is how I REVERSED my condition txtify archive
Lutheran minister and House candidate under fire after recounting her part in satanist couple's wedding txtify archive
Distress call captures tanker under fire as Iran shuts Strait of Hormuz and more top headlines txtify archive
Tiger Woods' 'desperate' stance on return to golf revealed as Vanessa Trump stands by embattled star's side txtify archive
Rebel Wilson's claims against actress are 'malicious concoctions', Australian court hears txtify archive
EasyJet chief for southern Europe warns of jet fuel uncertainty in 'three or four weeks' as Iran war hits British holidaymakers txtify archive
GOP Senate hopeful Michele Tafoya accuses Walz, Ellison of ignoring Minnesota fraud scheme txtify archive
Devastating bodycam footage shows final moments of Chicago police officer before she was shot by her own partner txtify archive
Paula R-AI-dcliffe! Watch the moment a robot wins the Beijing half marathon - beating the human record by almost 7 minutes txtify archive
Meghan Markle 'was snubbed by Irwin family during Australian tour because they're loyal to William' txtify archive
Eric Dane makes first posthumous appearance on Euphoria season three in scenes filmed months before his death from ALS txtify archive
Euphoria fans APPALLED at Sydney Sweeney being 'degraded' in new X-rated fetish scenes txtify archive
Researchers Detect ZionSiphon Malware Targeting Israeli Water, Desalination OT Systems txtify archive
Daughter of woman who vanished off boat in Bahamas says stepfather 'probably preplanned' tragic event txtify archive
Greece ditches fingerprint and facial scans for Britons after new EU travel rules sparked border chaos across Europe txtify archive
Frontier AI Is Collapsing the Exploit Window. Here’s How Defenders Must Respond. txtify archive
'I set up a bedroom camera to capture my daughter's night seizures. Then my husband walked in...' The video was so shocking it brought police to tears. Now PAULA VIGIL shares her story so awful it forced a change in the law txtify archive
Aussie plus-sized model divides fans with her welcome party wedding dress: 'That is so odd' txtify archive
Man's brazen trick for stealing and reselling Lego is exposed as he's accused of getting away with scheme at least 70 times before arrest txtify archive
Carolyn Bessette's best friend reveals how she and JFK Jr 'acted like crazy people'… the racist incident he never got apology for… and his tragic warning she ignored txtify archive
WWE icon Brock Lesnar retires immediately after WrestleMania 42 defeat as he bursts into tears txtify archive
Terrifying moment San Diego Padres star is struck in the face by 96MPH pitch... but miraculously stays in game txtify archive
Australian man faces eight years in United States jail after attacking officer at LAX Airport txtify archive
Rob Gronkowski teases shock career move for Tom Brady... amid NFL legend's feud with WWE star Logan Paul ahead of WrestleMania 42 txtify archive
ISC Stormcast For Monday, April 20th, 2026 https://isc.sans.edu/podcastdetail/9898, (Mon, Apr 20th) txtify archive
Pennsylvania man accused of stealing over 100 sets of human remains appears in court in ‘horror movie’ case txtify archive
Distress call captures tanker under fire, Iran shuts Hormuz trapping thousands of sailors txtify archive
Scottie Scheffler suffers agonizing playoff defeat at $20m PGA Tour event... one week after crushing Masters near-miss txtify archive
82-year-old woman found dead after she went missing with her Dalmatian dog two weeks ago txtify archive
Former NFL star turns on 'dumb and petty' cops over top draft prospect's arrest: 'Little ego battle' txtify archive
'They told me he was dead': Children born near army base learn truth about UK soldier dads txtify archive
Survey finds nearly one-third of Long Island residents say Jews should 'move on' from the Holocaust txtify archive
Hezbollah ‘human shield’ strategy behind Lebanon ambush, bomb detonation - Macron drawn in txtify archive
Tehran will never cede control of Strait of Hormuz, senior Iranian politician tells BBC txtify archive
Slain Iranian nuclear scientists raises alarm over uranium, expertise reaching black market txtify archive
UK chief rabbi says Jews targeted by ‘sustained campaign of violence and intimidation' after string of attacks txtify archive
Police identify suspect who killed eight kids, most believed to be his own, after multi scene domestic rampage txtify archive
Feds arrest Iranian woman at LAX for allegedly brokering weapons sales for Islamic regime txtify archive
Several University of Iowa students wounded in downtown shooting after fight erupts near campus txtify archive
Brit tourists who screamed vile abuse at Israelis in Vietnam seen in new videos 'chasing around' visibly Jewish holidaymakers txtify archive
Cold case breakthrough solves teen killing after suspect lived free for decades: 'Better be afraid' txtify archive
Trump criticizes Spain amid Iran, NATO rift as PM Sanchez faces questions over political motives txtify archive
Hundreds of activists face pepper spray in violent clash with deputies at Wisconsin beagle research facility txtify archive
Trump renews bridge, power plant threat against Iran in push for deal, mocks 'tough guy' IRGC txtify archive
String of scientist deaths, vanishings fuels expert talks of shadow ops and silenced secrets: 'Very serious' txtify archive
Vance says he's 'grateful' for Pope Leo's statement on not wanting public debate with Trump txtify archive
CVE-2026-4786 Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open() txtify archive
CVE-2026-6100 Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure txtify archive
CVE-2026-33056 tar-rs: unpack_in can chmod arbitrary directories by following symlinks txtify archive
Chernobyl disaster zone - four decades on: Inside the abandoned town reclaimed by nature and sealed off from the world txtify archive
Obama, Mamdani sing ‘Wheels on the Bus’ with Bronx kids during first joint appearance: video txtify archive
The little Ohio girl crushed to death by a car seat… and how the tragedy could upend the industry txtify archive
NYC teen shot dead on Queens basketball court as bystanders filmed; police searching for gunman txtify archive
Moscow-born gunman dead after Kyiv shooting rampage leaves at least 6 dead, 14 wounded: Zelenskyy txtify archive
Pope Leo says remarks about world being 'ravaged by a handful of tyrants' were not aimed at Trump: report txtify archive
Airline worker stole plane, performed barrel roll before deadly crash: Inside final moments txtify archive
Walz rips Trump and Vance in Europe, says 'feeble-minded, trigger-happy president' has no exit plan for Iran txtify archive
Ilhan Omar's office says she's ‘not a millionaire’ after $30M filing revised down to under $100K: report txtify archive
US Navy releases photos of 'fresh meals,' pushes back on reports of food shortages on Middle East warships txtify archive
Newsom administration allegedly knew of $2B California budget error for months: report txtify archive
NAKIVO v11.2: Ransomware Defense, Faster Replication, vSphere 9, and Proxmox VE 9.0 Support txtify archive
Trump signs executive order directing FDA to review psychedelics designated as breakthrough therapy drugs txtify archive
Kagan screamed so loudly at liberal ally after Dobbs leak the ‘wall was shaking,' book claims txtify archive
Orange Crush festival returns to Tybee Island as police brace for 50,000 partiers after teen takeover, gunfire txtify archive
Renowned physicist alarmed by 'unheard of' number of scientists dying or vanishing now on White House's radar txtify archive
Boston mayor denies funding LGBTQ migrant ‘wellness’ perks after program touts up to $500 benefits txtify archive
Trump’s favorite field marshal: Who is Pakistan’s powerful army chief Asim Munir with deep intel ties txtify archive
Dems sidestep past ‘refuse illegal orders’ demands as they challenge Trump’s Iran war authority txtify archive
Air Force Academy’s ‘CULEX’ puts thousands of cadets through realistic 24-hour combat simulation txtify archive
Alleged Irish cartel boss arrested in covert operation on organized crime charges after years-long manhunt txtify archive
Skeletal remains found by hikers in Washington state woods identified as woman missing since 2024 txtify archive
Two boys dead after illegal immigrant from Mexico allegedly drove drunk and hit them on a sidewalk txtify archive
Escaped wolf Neukgu returned to South Korean zoo after nine-day search involving thermal imaging drones txtify archive
Bride’s sister-in-law douses her in black paint moments before ceremony in horrifying ‘revenge’ attack txtify archive
Banque de France Governor François Villeroy de Galhau: ‘Europe and America will either win together or fall together’ txtify archive
The Strait of Hormuz is ‘open,’ but the US blockade remains in place. Here’s what that means. txtify archive
Fox News True Crime Newsletter: Brian Hooker's release, Tyler Robinson's ATF report, DNA in Guthrie case txtify archive
Commerce Secretary Lutnick Says Trade Deal With Canada, Mexico Needs to Be ‘Reconsidered’ txtify archive
Video shows teen snatched at bus stop – but victim slips SOS at gas station to escape repeat offender suspect txtify archive
Daughter of missing American in Bahamas says Brian Hooker using mother's illness as 'excuse' to leave country txtify archive
Bank of Canada to Track Longer-Term CPI Expectations For Guidance on Rates, Macklem Says txtify archive
Protein Is Hotter Than Ever. So Why Is the Owner of Quest and Atkins on a Cold Streak? txtify archive
Australia's most decorated veteran walks free on bail on war crimes charges related to Afghan deaths txtify archive
CVE-2026-40179 Prometheus: Stored XSS via metric names and label values in web UI tooltips and metrics explorer txtify archive
CVE-2025-14821 Libssh: libssh: insecure default configuration leads to local man-in-the-middle attacks on windows txtify archive
CVE-2026-39956 jq: Missing runtime type checks for _strindices lead to crash and limited memory disclosure txtify archive
CVE-2026-35199 SymCrypt SymCryptXmssSign function - Heap overflow via 64->32-bit leaf-count truncation txtify archive
CVE-2026-39979 jq: Out-of-Bounds Read in jv_parse_sized() Error Formatting for Non-NUL-Terminated Counted Buffers txtify archive
CVE-2026-33948 jq: Embedded-NUL Truncation in CLI JSON Input Path Causes Prefix-Only Validation of Malformed Input txtify archive
CVE-2026-33947 jq: Unbounded Recursion in jv_setpath(), jv_getpath() and delpaths_sorted() txtify archive
CVE-2026-32316 jq: Integer overflow in jvp_string_append() allows Heap-based Buffer Overflow txtify archive
ISC Stormcast For Friday, April 17th, 2026 https://isc.sans.edu/podcastdetail/9896, (Fri, Apr 17th) txtify archive
A beast of a Booster 19 successfully static fires on Pad 2 - here's some footage from various angles. comments txtify archive
Statement from Chairman of the Afghanistan Withdrawal Special Review Panel Sean Parnell txtify archive
‘Best drone’ innovation winner developing enemy drone recovery system with the Army Research Lab txtify archive
Space-based missile defense may cost too much for Golden Dome’s 12-figure spending plan txtify archive
[Guest Diary] Compromised DVRs and Finding Them in the Wild, (Thu, Apr 16th) txtify archive
Former Virginia Lt. Gov. Justin Fairfax Kills Wife, Self in Apparent Murder-Suicide, Police Say txtify archive
Dispatch from Geneva: Uyghur communities need cross-border protection from China’s ongoing atrocities txtify archive
South African ex-police chief gets tissue stuck on forehead while sweating during corruption inquiry txtify archive
NASA has selected SpaceX’s Falcon Heavy rocket to launch ESA’s Rosalind Franklin Mars rover mission from Launch Complex 39A, no earlier than late 2028. comments txtify archive
Pope says the world is being ravaged by a handful of tyrants and condemns leaders who spend billions on wars - after Trump's social media attacks txtify archive
Secretary of War Pete Hegseth and Chairman of the Joint Chiefs of Staff Gen. Dan Caine Hold a Press Briefing txtify archive
Europe Has Around Six Weeks of Jet Fuel Left as Iran War Strains Supply, IEA’s Birol Says txtify archive
Trump predicted Israel-Lebanon leaders would speak ‘tomorrow’ — Beirut shut it down as ceasefire emerges txtify archive
CVE-2026-32223 Windows USB Printing Stack (usbprint.sys) Elevation of Privilege Vulnerability txtify archive
ThreatsDay Bulletin: Defender 0-Day, SonicWall Brute-Force, 17-Year-Old Excel RCE and 15 More Stories txtify archive
ISC Stormcast For Thursday, April 16th, 2026 https://isc.sans.edu/podcastdetail/9894, (Thu, Apr 16th) txtify archive
Space Force’s 2040 vision: a larger force to contend with larger Chinese, Russian threats txtify archive
Allies rush thousands of drones to Ukraine as Russia unleashes deadly missile barrages txtify archive
UN filing accuses UK of forced displacement as Diego Garcia tensions and security fears grow txtify archive
Iran shifts 20M barrels through ‘dark’ offshore oil network bypassing US port blockade, firm says txtify archive
Defense Business Brief: Robotic arms + satellite refueling | Iran war costs | Unmasking shadow fleets…from space txtify archive
The Islamic Republic of Iran should be held accountable for aiding Russia’s crimes against Ukraine txtify archive
April Patch Tuesday Fixes Critical Flaws Across SAP, Adobe, Microsoft, Fortinet, and More txtify archive
CVE-2026-34757 LIBPNG has a yse-after-free in png_set_PLTE, png_set_tRNS and png_set_hIST leading to corrupted chunk data and potential heap information disclosure txtify archive
CVE-2026-27143 Missing bound checks can lead to memory corruption in safe Go in cmd/compile txtify archive
CVE-2026-32282 TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix txtify archive
CVE-2026-27144 Miscompilation allows memory corruption via CONVNOP-wrapped array copy in cmd/compile txtify archive
CVE-2026-32283 Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls txtify archive
CVE-2026-28390 Possible NULL Dereference When Processing CMS KeyTransportRecipientInfo txtify archive
CVE-2026-33056 tar-rs: unpack_in can chmod arbitrary directories by following symlinks txtify archive
CVE-2026-2646 Heap buffer overflow in session parsing with wolfSSL_d2i_SSL_SESSION() function txtify archive
CVE-2026-2645 Acceptance of CertificateVerify Message before ClientKeyExchange in TLS 1.2 txtify archive
CVE-2026-35611 Addressable has a Regular Expression Denial of Service in Addressable templates txtify archive
CVE-2026-35093 Libinput: libinput: unauthorized code execution and information disclosure through lua bytecode plugins txtify archive
CVE-2026-34601 xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion txtify archive
CVE-2026-4176 Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib txtify archive
CVE-2026-27171 zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition. txtify archive
CVE-2025-14523 Libsoup: libsoup: duplicate host header handling causes host-parsing discrepancy (first- vs last-value wins) txtify archive
CVE-2026-33940 Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial txtify archive
CVE-2025-61729 Excessive resource consumption when printing error string for host certificate validation in crypto/x509 txtify archive
CVE-2026-33939 Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation txtify archive
CVE-2026-33941 Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options txtify archive
CVE-2026-33938 Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block txtify archive
CVE-2026-33891 Forge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input txtify archive
CVE-2026-33896 Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation) txtify archive
CVE-2026-1519 Excessive NSEC3 iterations cause high CPU load during insecure delegation validation txtify archive
CVE-2026-33416 LIBPNG has use-after-free via pointer aliasing in `png_set_tRNS` and `png_set_PLTE` txtify archive
CVE-2025-30258 In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a "verification DoS." txtify archive
CVE-2026-40175 Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain txtify archive
CVE-2026-34480 Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters txtify archive
CVE-2026-34479 Apache Log4j 1 to Log4j 2 bridge: Silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters txtify archive
CVE-2026-34481 Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayout txtify archive
CVE-2026-5460 Heap Use-After-Free in PQC Hybrid KeyShare Error Cleanup in wolfSSL TLS 1.3 txtify archive
CVE-2026-5778 Integer underflow leads to out-of-bounds access in sniffer ChaCha decrypt path. txtify archive
CVE-2026-5295 Stack Buffer Overflow in wolfSSL PKCS7 wc_PKCS7_DecryptOri() via Oversized OID txtify archive
CVE-2026-5503 out-of-bounds write in TLSX_EchChangeSNI via attacker-controlled publicName txtify archive
CVE-2026-5501 Improper Certificate Signature Verification in X.509 Chain Validation Allows Forged Leaf Certificates txtify archive
CVE-2026-5500 Improper Validation of AES-GCM Authentication Tag Length in PKCS#7 Envelope Allows Authentication Bypass txtify archive
ISC Stormcast For Wednesday, April 15th, 2026 https://isc.sans.edu/podcastdetail/9892, (Wed, Apr 15th) txtify archive
15 charts that explain why the Strait of Hormuz shutdown matters for the global economy txtify archive
Charai for The Jerusalem Strategic Tribune: Lebanon and Israel Have Opened a Historic Door. Washington Must Not Let Iran Shut It txtify archive
The IEA’s Fatih Birol: Oil prices will soon begin ‘reflecting the severity’ of the energy crisis txtify archive
What the Taiwanese opposition leader’s recent China visit means for Taipei, Beijing, and Washington txtify archive
CVE-2026-23653 GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability txtify archive
CVE-2026-25184 Applocker Filter Driver (applockerfltr.sys) Elevation of Privilege Vulnerability txtify archive
CVE-2026-23670 Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability txtify archive
CVE-2026-26155 Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability txtify archive
CVE-2026-26174 Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability txtify archive
CVE-2026-26183 Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability txtify archive
CVE-2026-27908 Windows TDI Translation Driver (tdx.sys) Elevation of Privilege Vulnerability txtify archive
CVE-2026-27917 Windows WFP NDIS Lightweight Filter Driver (wfplwfs.sys) Elevation of Privilege Vulnerability txtify archive
CVE-2026-27921 Windows TDI Translation Driver (tdx.sys) Elevation of Privilege Vulnerability txtify archive
CVE-2026-27926 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability txtify archive
CVE-2026-27929 Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability txtify archive
CVE-2026-32071 Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability txtify archive
CVE-2026-32073 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-32082 Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability txtify archive
CVE-2026-32083 Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability txtify archive
CVE-2026-32087 Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability txtify archive
CVE-2026-32093 Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability txtify archive
CVE-2026-32181 Connected User Experiences and Telemetry Service Denial of Service Vulnerability txtify archive
CVE-2026-32184 Microsoft High Performance Compute (HPC) Pack Elevation of Privilege Vulnerability txtify archive
CVE-2026-32216 Windows Redirected Drive Buffering System Denial of Service Vulnerability txtify archive
CVE-2026-32223 Windows USB Printing Stack (usbprint.sys) Elevation of Privilege Vulnerability txtify archive
CVE-2026-32224 Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability txtify archive
CVE-2026-33098 Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability txtify archive
CVE-2026-33116 .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability txtify archive
CVE-2026-32212 Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability txtify archive
CVE-2026-32631 GitHub: CVE-2026-32631 'git clone' from manipulated repositories can leak NTLM hashes txtify archive
CVE-2026-21637 HackerOne: CVE-2026-21637 TLS PSK/ALPN Callback Exceptions Bypass Error Handlers txtify archive
CVE-2026-26153 Windows Encrypted File System (EFS) Elevation of Privilege Vulnerability txtify archive
CVE-2026-26168 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-26173 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-26176 Windows Client Side Caching driver (csc.sys) Elevation of Privilege Vulnerability txtify archive
CVE-2026-26177 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-26178 Windows Advanced Rasterization Platform Elevation of Privilege Vulnerability txtify archive
CVE-2026-26182 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-27922 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-32068 Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability txtify archive
CVE-2026-32070 Windows Common Log File System Driver Elevation of Privilege Vulnerability txtify archive
CVE-2026-32086 Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability txtify archive
CVE-2026-32150 Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability txtify archive
CVE-2026-33099 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-33100 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-33103 Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability txtify archive
CVE-2026-33824 Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability txtify archive
CVE-2026-32214 Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability txtify archive
CVE-2026-32187 Microsoft Edge (Chromium-based) Defense in Depth Vulnerability - Rejected txtify archive
CVE-2026-28390 Possible NULL Dereference When Processing CMS KeyTransportRecipientInfo txtify archive
CVE-2026-3184 Util-linux: util-linux: access control bypass due to improper hostname canonicalization txtify archive
CVE-2026-27456 util-linux: TOCTOU Race Condition in util-linux mount(8) - Loop Device Setup txtify archive
CVE-2026-0967 Libssh: libssh: denial of service via inefficient regular expression processing txtify archive
CVE-2026-0965 Libssh: libssh: denial of service via improper configuration file handling txtify archive
CVE-2026-4647 Binutils: out-of-bounds read in xcoff relocation processing in gnu binutils bfd library txtify archive
CVE-2025-69649 GNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a crafted ELF binary with malformed header fields. During relocation processing, an invalid or null section pointer may be passed into display_relocations(), resulting in a segmentation fault (SIGSEGV) and abrupt termination. No evidence of memory corruption beyond the null pointer dereference, nor any possibility of code execution, was observed. txtify archive
CVE-2025-69645 Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). The issue was observed in binutils 2.44. A local attacker can trigger the crash by supplying a malicious input file. txtify archive
CVE-2025-69652 GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate into DWARF attribute parsing routines. When certain malformed attributes result in an unexpected data length of zero, byte_get_little_endian() triggers a fatal abort. No evidence of memory corruption or code execution was observed; the impact is limited to denial of service. txtify archive
CVE-2025-69646 Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis. txtify archive
108 Malicious Chrome Extensions Steal Google and Telegram Data, Affecting 20,000 Users txtify archive
CVE-2026-31428 netfilter: nfnetlink_log: fix uninitialized padding leak in NFULA_PAYLOAD txtify archive
CVE-2026-31427 netfilter: nf_conntrack_sip: fix use of uninitialized rtp_addr in process_sdp txtify archive
CVE-2026-31424 netfilter: x_tables: restrict xt_check_match/xt_check_target extensions for NFPROTO_ARP txtify archive
April 2026 Patch Tuesday: Two Zero-Days and Eight Critical Vulnerabilities Among 164 CVEs txtify archive
ISC Stormcast For Tuesday, April 14th, 2026 https://isc.sans.edu/podcastdetail/9890, (Tue, Apr 14th) txtify archive
Secretary of War Hegseth Hosted Bilateral Meeting With Indonesian Defense Minister Sjafrie txtify archive
HASC chair: Trillion-dollar defense budgets are the ‘new normal.’ Reconciliation is less certain. txtify archive
Readout of Secretary of War Pete Hegseth's Meeting with Indonesian Minister of Defense Sjafrie Sjamsoeddin txtify archive
Experts react: Hungary just voted out Viktor Orbán. Here’s what to expect in Europe and beyond. txtify archive
Inside the IMF-World Bank Spring Meetings as leaders grapple with war and supply shocks txtify archive
⚡ Weekly Recap: Fiber Optic Spying, Windows Rootkit, AI Vulnerability Hunting and More txtify archive
CVE-2026-39856 osslsigncode has an Out-of-Bounds Read via Unvalidated Section Bounds in PE Page Hash Calculation txtify archive
CVE-2026-39855 osslsigncode has an Integer Underflow in PE Page Hash Calculation Can Cause Out-of-Bounds Read txtify archive
CVE-2026-39853 osslsigncode has a Stack Buffer Overflow via Unbounded Digest Copy During Signature Verification txtify archive
CVE-2026-28390 Possible NULL Dereference When Processing CMS KeyTransportRecipientInfo txtify archive
CVE-2026-34757 LIBPNG has a yse-after-free in png_set_PLTE, png_set_tRNS and png_set_hIST leading to corrupted chunk data and potential heap information disclosure txtify archive
CVE-2026-35206 Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment txtify archive
Starship Gazer: “Starship 39 rolling out to Starbase Massey's test site tonight with lots of new additions on the leeward side.” comments txtify archive
CVE-2026-4878 Libcap: libcap: privilege escalation via toctou race condition in cap_set_file() txtify archive
CVE-2026-33810 Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509 txtify archive
CVE-2026-27143 Missing bound checks can lead to memory corruption in safe Go in cmd/compile txtify archive
CVE-2026-32282 TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix txtify archive
CVE-2026-27144 Miscompilation allows memory corruption via CONVNOP-wrapped array copy in cmd/compile txtify archive
CVE-2026-32283 Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls txtify archive
CVE-2026-29181 OpenTelemetry-Go multi-value `baggage` header extraction causes excessive allocations (remote dos amplification) txtify archive
CVE-2026-39882 OpenTelemetry-Go OTLP HTTP exporters read unbounded HTTP response bodies txtify archive
CVE-2026-28390 Possible NULL Dereference When Processing CMS KeyTransportRecipientInfo txtify archive
CVE-2026-35611 Addressable has a Regular Expression Denial of Service in Addressable templates txtify archive
CVE-2026-28810 Predictable DNS Transaction IDs Enable Cache Poisoning in Built-in Resolver txtify archive
CVE-2026-39316 CUPS has a use-after-free in `cupsdDeleteTemporaryPrinters` via dangling subscription pointer txtify archive
CVE-2026-39314 CUPS has an integer underflow in `_ppdCreateFromIPP` causes root cupsd crash via negative `job-password-supported` txtify archive
Secretary Hegseth to Host Honor Cordon and Meeting with Indonesian Minister of Defense, April 13 txtify archive
Chhangani cited in House of Saud article on how Iran avoids US sanctions and sell oil to China txtify archive
AC Front Page event with World Bank Group President Ajay Banga featured in Reuters article on slower global growth and heightened inflation brought on by Middle East conflict. txtify archive
Tannebaum cited in Politico article on risks to shipping companies transiting Hormuz, and the waterway’s indispensability to the global economy. txtify archive
FINRA Launches Financial Intelligence Fusion Center to Combat Cybersecurity and Fraud Threats txtify archive
Media Invitation Announced for United States v. Khalid Shaikh Mohammad et al. Pre-Trial Hearing txtify archive
CVE-2026-32241 Flannel vulnerable to cross-node remote code execution via extension backend BackendData injection txtify archive
US Deputy Secretary of State Christopher Landau: The old chapter on US foreign policy is ‘coming to a close’ txtify archive
Matchett in AFP, France 24, and Arab News on the consequences of bombing Iran’s power plants txtify archive
Matchett in The Economic Times, Hindustan Times, Nepal News, The Express Tribune, on warning against US striking Iranian critical infrastructure txtify archive
Chhangani cited in FT article on the banks and financial institutions willing to launder dollar payments for Iran txtify archive
Egypt’s foreign minister: One cannot secure waterways ‘while ignoring the political order of the states’ along the shore txtify archive
It’s so weird that when whichever actors run these campaigns that they don’t at least try to vary the tweet at least a little bit. txtify archive
CVE-2026-4897 Polkit: polkit: denial of service via unbounded input processing through standard input txtify archive
CVE-2026-34445 ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings. txtify archive
CVE-2026-34446 ONNX: Arbitrary File Read via ExternalData Hardlink Bypass in ONNX load txtify archive
CVE-2026-35093 Libinput: libinput: unauthorized code execution and information disclosure through lua bytecode plugins txtify archive
CVE-2026-39314 CUPS has an integer underflow in `_ppdCreateFromIPP` causes root cupsd crash via negative `job-password-supported` txtify archive
CVE-2026-39316 CUPS has a use-after-free in `cupsdDeleteTemporaryPrinters` via dangling subscription pointer txtify archive
CVE-2026-34990 OpenPrinting CUPS: Local print admin token disclosure using temporary printers txtify archive
CVE-2026-34980 OpenPrinting CUPS: Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network txtify archive
CVE-2026-34978 OpenPrinting CUPS: Path traversal in RSS notify-recipient-uri enables file write outside CacheDir/rss (and clobbering of job.cache) txtify archive
CVE-2026-34933 Avahi: Reachable assertion in `transport_flags_from_domain()` via conflicting publish flags crashes avahi-daemon txtify archive
When repeated traffic comes from a government ASN, what can you actually infer before it turns into fiction? txtify archive
Secretary of War Pete Hegseth and Chairman of the Joint Chiefs Air Force Gen. Dan Caine Hold a Press Briefing txtify archive
Ajay Banga on responding to this economic crisis: ‘Focus on policies’ that ‘create jobs’ txtify archive
Sanctions waivers on Russian and Iranian oil are set to expire. Here’s what Trump should do next. txtify archive
I know that Google keeps IP logs for 9 to 18 months when I'm not signed in or using Safari, but specifically how long does Google keep search queries linked to a specific device or IP address when I am not signed in? Also what browser do you recommend as an alternative that is more secure for OSINT? txtify archive
Full Sail University to Open IBM Cyber Defense Range Powered by AWS and Cloud Range on Campus txtify archive
Lipsky quoted in Reuters article on China’s role in Iran’s military and drone production process, and how Trump is unlikely to follow through with threatened tariffs on Beijing txtify archive
Pluralsight Launches SecureReady to Help Organizations Build Job-Ready Cybersecurity Teams txtify archive
CVE-2026-4645 Github.com/antchfx/xpath: xpath: denial of service via crafted boolean xpath expressions txtify archive
CVE-2006-10003 XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack txtify archive
CVE-2026-5201 Gdk-pixbuf: gdk-pixbuf: denial of service via heap-based buffer overflow when processing a specially crafted jpeg image txtify archive
CVE-2026-33936 python-ecdsa: Denial of Service via improper DER length validation in crafted private keys txtify archive
CVE-2026-32241 Flannel vulnerable to cross-node remote code execution via extension backend BackendData injection txtify archive
DOW Awards Lompoc Unified School District a $45.4M Grant for Manzanita Public Charter School at Vandenberg Space Force Base, California txtify archive
The World Bank Group’s Ajay Banga: Expect higher inflation, lower growth from this global crisis txtify archive
Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure txtify archive
CVE-2026-27456 util-linux: TOCTOU Race Condition in util-linux mount(8) - Loop Device Setup txtify archive
CVE-2026-34990 OpenPrinting CUPS: Local print admin token disclosure using temporary printers txtify archive
CVE-2026-27447 OpenPrinting CUPS: Authorization bypass via case-insensitive group-member lookup txtify archive
CVE-2026-34978 OpenPrinting CUPS: Path traversal in RSS notify-recipient-uri enables file write outside CacheDir/rss (and clobbering of job.cache) txtify archive
CVE-2026-34980 OpenPrinting CUPS: Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network txtify archive
CVE-2026-3184 Util-linux: util-linux: access control bypass due to improper hostname canonicalization txtify archive
CVE-2026-31408 Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold txtify archive
NASA's Moon ship and rocket seem to be working well, so what about the landers? comments txtify archive
Chhangani and Kumar cited in 2025 ECA report discussing advancement of regional integration in Africa using frontier technologies and innovation txtify archive
Lipsky cited in Bloomberg article detailing why the Iran war may impact Trump’s goal of lowering interest rates txtify archive
Nikoladze joined the Embassy of the Republic of Poland to launch and discuss findings from the organizations’ new report txtify archive
Nikoladze joined The Warcast podcast to discuss the complications of the U.S. suspension of Russian and Iranian oil sanctions txtify archive
Washington Post cites GeoEconomics research on China’s cross-border digital currency platform mBridge txtify archive
From alignment to action: Building a durable US-Argentina critical minerals partnership txtify archive
Charai for The Jerusalem Strategic Tribune: The Iran War’s First Lesson: American Leadership, Israeli Resolve txtify archive
Anthropic Claude Mythos Preview: The More Capable AI Becomes, the More Security It Needs txtify archive
CVE-2026-27456 util-linux: TOCTOU Race Condition in util-linux mount(8) - Loop Device Setup txtify archive
CVE-2026-34990 OpenPrinting CUPS: Local print admin token disclosure using temporary printers txtify archive
CVE-2026-27447 OpenPrinting CUPS: Authorization bypass via case-insensitive group-member lookup txtify archive
CVE-2026-34978 OpenPrinting CUPS: Path traversal in RSS notify-recipient-uri enables file write outside CacheDir/rss (and clobbering of job.cache) txtify archive
CVE-2026-34980 OpenPrinting CUPS: Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network txtify archive
When an Attacker Meets a Group of Agents: Navigating Amazon Bedrock's Multi-Agent Applications txtify archive
Elon Musk: Next flight of Starship and first flight of V3 ship & booster is 4 to 6 weeks away comments txtify archive
CVE-2026-4897 Polkit: polkit: denial of service via unbounded input processing through standard input txtify archive
CVE-2026-2100 P11-kit: p11-kit: null dereference via c_derivekey with specific null parameters txtify archive
CVE-2026-5107 FRRouting FRR EVPN Type-2 Route bgp_evpn.c process_type2_route access control txtify archive
CVE-2026-34073 cryptography has incomplete DNS name constraint enforcement on peer names txtify archive
Quick question-If you've completed the Basel Institute free cert, how long did it take you? txtify archive
Space Systems Command Awards Task Orders to Launch Missile Tracking Space Vehicles [2x F9 launches] comments txtify archive
Matchett for War on the Rocks on threats to desalination plants and preparedness for attacks in the Gulf txtify archive
CVE-2026-26135 Azure Custom Locations Resource Provider (RP) Elevation of Privilege Vulnerability txtify archive
CVE-2026-33105 Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability txtify archive
CVE-2026-34043 Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects txtify archive
CVE-2026-33542 Incus does not verify combined fingerprint when downloading images from simplestreams servers txtify archive
CVE-2026-33936 python-ecdsa: Denial of Service via improper DER length validation in crafted private keys txtify archive
CVE-2026-33750 brace-expansion: Zero-step sequence causes process hang and memory exhaustion txtify archive
CVE-2026-0967 Libssh: libssh: denial of service via inefficient regular expression processing txtify archive
CVE-2026-0965 Libssh: libssh: denial of service via improper configuration file handling txtify archive
CVE-2026-5107 FRRouting FRR EVPN Type-2 Route bgp_evpn.c process_type2_route access control txtify archive
CVE-2026-2739 This affects versions of the package bn.js before 5.2.3. Calling maskn(0) on any BN instance corrupts the internal state, causing toString(), divmod(), and other methods to enter an infinite loop, hanging the process indefinitely. txtify archive
CVE-2026-33416 LIBPNG has use-after-free via pointer aliasing in `png_set_tRNS` and `png_set_PLTE` txtify archive
CVE-2026-2436 Libsoup: libsoup: denial of service via use-after-free in soupserver during tls handshake txtify archive
CVE-2026-4897 Polkit: polkit: denial of service via unbounded input processing through standard input txtify archive
CVE-2026-2100 P11-kit: p11-kit: null dereference via c_derivekey with specific null parameters txtify archive
CVE-2026-5119 Libsoup: libsoup: information disclosure via cleartext transmission of cookies during https tunnel establishment txtify archive
CVE-2026-5121 Libarchive: libarchive: arbitrary code execution via integer overflow in iso9660 image processing txtify archive
CVE-2026-5201 Gdk-pixbuf: gdk-pixbuf: denial of service via heap-based buffer overflow when processing a specially crafted jpeg image txtify archive
CVE-2026-4176 Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib txtify archive
Matchett quoted in ABC News on the threat of Iranian attacks on Gulf desalination plants txtify archive
Department of War Forges Landmark Agreement to Triple PAC-3 Seeker Production, Bolstering the Arsenal of Freedom txtify archive
CVE-2026-33542 Incus does not verify combined fingerprint when downloading images from simplestreams servers txtify archive
CVE-2026-33750 brace-expansion: Zero-step sequence causes process hang and memory exhaustion txtify archive
CVE-2026-0967 Libssh: libssh: denial of service via inefficient regular expression processing txtify archive
CVE-2026-0965 Libssh: libssh: denial of service via improper configuration file handling txtify archive
CVE-2026-4645 Github.com/antchfx/xpath: xpath: denial of service via crafted boolean xpath expressions txtify archive
CVE-2026-34043 Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects txtify archive
CVE-2026-4176 Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib txtify archive
Weaponizing the Protectors: TeamPCP’s Multi-Stage Supply Chain Attack on Security Infrastructure txtify archive
Secretary of War Pete Hegseth and Chairman of the Joint Chiefs Air Force Gen. Dan Caine Hold a Press Briefing txtify archive
Department of War Releases Its Annual Report on Suicide in the Military for Calendar Year 2024 txtify archive
North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack txtify archive
CVE-2026-33416 LIBPNG has use-after-free via pointer aliasing in `png_set_tRNS` and `png_set_PLTE` txtify archive
CVE-2026-25645 Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function txtify archive
CVE-2026-33940 Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial txtify archive
CVE-2026-33939 Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation txtify archive
CVE-2026-33916 Handlebars.js has Prototype Pollution Leading to XSS through Partial Template Injection txtify archive
CVE-2026-33941 Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options txtify archive
CVE-2026-33938 Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block txtify archive
CVE-2026-33542 Incus does not verify combined fingerprint when downloading images from simplestreams servers txtify archive
CVE-2026-33936 python-ecdsa: Denial of Service via improper DER length validation in crafted private keys txtify archive
CVE-2026-33891 Forge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input txtify archive
CVE-2026-33896 Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation) txtify archive
CVE-2026-33750 brace-expansion: Zero-step sequence causes process hang and memory exhaustion txtify archive
CVE-2026-0967 Libssh: libssh: denial of service via inefficient regular expression processing txtify archive
CVE-2026-0965 Libssh: libssh: denial of service via improper configuration file handling txtify archive
Explosive Misinformation: A Guide to Mushroom Clouds, ‘Sonic Weapons’ and Disintegration txtify archive
CVE-2026-33672 Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching txtify archive
CVE-2026-23399 nf_tables: nft_dynset: fix possible stateful expression memleak in error path txtify archive
CVE-2026-25645 Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function txtify archive
CVE-2026-33416 LIBPNG has use-after-free via pointer aliasing in `png_set_tRNS` and `png_set_PLTE` txtify archive
CVE-2026-3591 A stack use-after-return flaw in SIG(0) handling code may enable ACL bypass txtify archive
CVE-2026-3119 Authenticated query containing a TKEY record may cause named to terminate unexpectedly txtify archive
CVE-2026-33936 python-ecdsa: Denial of Service via improper DER length validation in crafted private keys txtify archive
CVE-2026-32241 Flannel vulnerable to cross-node remote code execution via extension backend BackendData injection txtify archive
CVE-2026-1519 Excessive NSEC3 iterations cause high CPU load during insecure delegation validation txtify archive
CVE-2026-4645 Github.com/antchfx/xpath: xpath: denial of service via crafted boolean xpath expressions txtify archive
CVE-2026-2369 Libsoup: libsoup: buffer overread due to integer underflow when handling zero-length resources txtify archive
CVE-2026-3547 wolfSSL: out-of-bounds read (DoS) in ALPN parsing due to incomplete validation txtify archive
CVE-2026-23227 drm/exynos: vidi: use ctx->lock to protect struct vidi_context member variables related to memory alloc/free txtify archive
CVE-2026-27135 nghttp2 Denial of service: Assertion failure due to the missing state validation txtify archive
CVE-2026-23267 f2fs: fix IS_CHECKPOINTED flag inconsistency issue caused by concurrent atomic commit and checkpoint writes txtify archive
CVE-2025-66413 Git for Windows leaks NTLM hash when cloning from an attacker-controlled server txtify archive
CVE-2026-23327 cxl/mbox: validate payload size before accessing contents in cxl_payload_from_user_allowed() txtify archive
CVE-2026-23386 gve: fix incorrect buffer cleanup in gve_tx_clean_pending_packets for QPL txtify archive
CVE-2026-23325 wifi: mt76: mt7996: Fix possible oob access in mt7996_mac_write_txwi_80211() txtify archive
CVE-2026-4645 Github.com/antchfx/xpath: xpath: denial of service via crafted boolean xpath expressions txtify archive
CVE-2026-4775 Libtiff: libtiff: arbitrary code execution or denial of service via signed integer overflow in tiff file processing txtify archive
CVE-2026-4647 Binutils: out-of-bounds read in xcoff relocation processing in gnu binutils bfd library txtify archive
CVE-2025-71109 MIPS: ftrace: Fix memory corruption when kernel is located beyond 32 bits txtify archive
Converging Interests: Analysis of Threat Clusters Targeting a Southeast Asian Government txtify archive
I've been mapping every verified strike in the Iran-Israel war since Day 1. Here's what 27 days of data looks like txtify archive
CVE-2026-3381 Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib txtify archive
CVE-2025-66413 Git for Windows leaks NTLM hash when cloning from an attacker-controlled server txtify archive
CVE-2026-27142 URLs in meta content attribute actions are not escaped in html/template txtify archive
CVE-2024-45336 Sensitive headers incorrectly sent after cross-domain redirect in net/http txtify archive
CVE-2026-23284 net: ethernet: mtk_eth_soc: Reset prog ptr to old_prog in case of error in mtk_xdp_setup() txtify archive
CVE-2026-23324 can: usb: etas_es58x: correctly anchor the urb in the read bulk callback txtify archive
CVE-2026-23327 cxl/mbox: validate payload size before accessing contents in cxl_payload_from_user_allowed() txtify archive
CVE-2026-23310 bpf/bonding: reject vlan+srcmac xmit_hash_policy change when XDP is loaded txtify archive
CVE-2026-23386 gve: fix incorrect buffer cleanup in gve_tx_clean_pending_packets for QPL txtify archive
CVE-2026-23340 net: sched: avoid qdisc_reset_all_tx_gt() vs dequeue race for lockless qdiscs txtify archive
CVE-2026-23307 can: ems_usb: ems_usb_read_bulk_callback(): check the proper length of a message txtify archive
CVE-2026-23383 bpf, arm64: Force 8-byte alignment for JIT buffer to prevent atomic tearing txtify archive
CVE-2026-23390 tracing/dma: Cap dma_map_sg tracepoint arrays to prevent buffer overflow txtify archive
CVE-2026-23368 net: phy: register phy led_triggers during probe to avoid AB-BA deadlock txtify archive
CVE-2026-23325 wifi: mt76: mt7996: Fix possible oob access in mt7996_mac_write_txwi_80211() txtify archive
CVE-2026-23392 netfilter: nf_tables: release flowtable after rcu grace period on error txtify archive
CVE-2026-23315 wifi: mt76: Fix possible oob access in mt76_connac2_mac_write_txwi_80211() txtify archive
CVE-2026-2443 Libsoup: out-of-bounds read in libsoup handle_partial_get() leading to heap information disclosure txtify archive
CVE-2025-58160 Tracing logging user input may result in poisoning logs with ANSI escape sequences txtify archive
CVE-2025-13462 tarfile: Skip DIRTYPE normalization during GNU LONGNAME/LONGLINK handling txtify archive
CVE-2026-2646 Heap buffer overflow in session parsing with wolfSSL_d2i_SSL_SESSION() function txtify archive
CVE-2026-3547 wolfSSL: out-of-bounds read (DoS) in ALPN parsing due to incomplete validation txtify archive
CVE-2026-2645 Acceptance of CertificateVerify Message before ClientKeyExchange in TLS 1.2 txtify archive
CVE-2026-1005 Integer underflow leads to out-of-bounds access in sniffer AES-GCM/CCM/ARIA-GCM decrypt path txtify archive
CVE-2026-0819 Stack buffer overflow in PKCS7 SignedData encoding with custom signed attributes txtify archive
CVE-2026-2369 Libsoup: libsoup: buffer overread due to integer underflow when handling zero-length resources txtify archive
CVE-2026-3099 Libsoup: libsoup: authentication bypass via digest authentication replay attack txtify archive
CVE-2026-4424 Libarchive: libarchive: information disclosure via heap out-of-bounds read in rar archive processing txtify archive
CVE-2026-4426 Libarchive: libarchive: denial of service via malformed iso file processing txtify archive
CVE-2026-33056 tar-rs: unpack_in can chmod arbitrary directories by following symlinks txtify archive
Threat Brief: Recruiting Scheme Impersonating Palo Alto Networks Talent Acquisition Team txtify archive
CVE-2026-3381 Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib txtify archive
How Iran's ruthless enforcers use rape to crush dissent: Brutal sex attacks on victims as young as 12 used to strike fear into protesters, rights groups reveal amid fury over sickening nurse gang rape txtify archive
Stripped, electrocuted and forced to fight each other to the death on camera: New evidence shows how Putin's commanders are torturing their own men txtify archive
CVE-2026-27135 nghttp2 Denial of service: Assertion failure due to the missing state validation txtify archive
CVE-2026-27448 pyOpenSSL allows TLS connection bypass via unhandled callback exception in set_tlsext_servername_callback txtify archive
CVE-2026-3632 Libsoup: libsoup: http smuggling and server-side request forgery via malformed hostnames txtify archive
CVE-2026-3634 Libsoup: libsoup: http header injection and response splitting via crlf injection in content-type header txtify archive
CVE-2026-32766 astral-tokio-tar insufficiently validates PAX extensions during extraction txtify archive
CVE-2026-23272 netfilter: nf_tables: unconditionally bump set->nelems before insertion txtify archive
CVE-2026-23277 net/sched: teql: fix NULL pointer dereference in iptunnel_xmit on TEQL slave xmit txtify archive
CVE-2026-3731 libssh SFTP Extension Name sftp.c sftp_extensions_get_data out-of-bounds txtify archive
CVE-2022-46456 NASM v2.16 was discovered to contain a global buffer overflow in the component dbgdbg_typevalue at /output/outdbg.c. txtify archive
CVE-2006-10003 XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack txtify archive
CVE-2006-10002 XML::Parser versions through 2.47 for Perl could overflow the pre-allocated buffer size cause a heap corruption (double free or corruption) and crashes txtify archive
CVE-2026-23227 drm/exynos: vidi: use ctx->lock to protect struct vidi_context member variables related to memory alloc/free txtify archive
CVE-2026-23220 ksmbd: fix infinite loop caused by next_smb2_rcv_hdr_off reset in error paths txtify archive
CVE-2026-23171 bonding: fix use-after-free due to enslave fail after slave array update txtify archive
CVE-2026-23157 btrfs: do not strictly require dirty metadata threshold for metadata writepages txtify archive
CVE-2026-23126 netdevsim: fix a race issue related to the operation on bpf_bound_progs list txtify archive
CVE-2026-23110 scsi: core: Wake up the error handler when final completions race against each other txtify archive
CVE-2026-27135 nghttp2 Denial of service: Assertion failure due to the missing state validation txtify archive
CVE-2026-23268 apparmor: fix unprivileged local user can do privileged policy management txtify archive
CVE-2026-23267 f2fs: fix IS_CHECKPOINTED flag inconsistency issue caused by concurrent atomic commit and checkpoint writes txtify archive
CVE-2025-71269 btrfs: do not free data reservation in fallback from inline due to -ENOSPC txtify archive
Secretary of War Pete Hegseth and Chairman of the Joint Chiefs Air Force Gen. Dan Caine Hold a Press Briefing txtify archive
CVE-2026-27448 pyOpenSSL allows TLS connection bypass via unhandled callback exception in set_tlsext_servername_callback txtify archive
CVE-2025-71265 fs: ntfs3: fix infinite loop in attr_load_runs_range on inconsistent metadata txtify archive
CVE-2026-4111 Libarchive: infinite loop denial of service in rar5 decompression via archive_read_data() in libarchive txtify archive
CVE-2026-3381 Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib txtify archive
CVE-2026-4105 Systemd: systemd: privilege escalation via improper access control in registermachine d-bus method txtify archive
CVE-2026-4111 Libarchive: infinite loop denial of service in rar5 decompression via archive_read_data() in libarchive txtify archive
Ransomware Under Pressure: Tactics, Techniques, and Procedures in a Shifting Threat Landscape txtify archive
CVE-2026-27138 Panic in name constraint checking for malformed certificates in crypto/x509 txtify archive
CVE-2026-27141 Sending certain HTTP/2 frames can cause a server to panic in golang.org/x/net txtify archive
CVE-2025-58160 Tracing logging user input may result in poisoning logs with ANSI escape sequences txtify archive
CVE-2026-27171 zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition. txtify archive
CVE-2026-3381 Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib txtify archive
Secretary of War Pete Hegseth and Chairman of the Joint Chiefs Air Force Gen. Dan Caine Hold a Press Briefing txtify archive
CVE-2026-25172 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability txtify archive
CVE-2026-25173 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability txtify archive
CVE-2026-26111 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability txtify archive
CVE-2026-26030 GitHub: CVE-2026-26030 Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable txtify archive
CVE-2025-61727 Improper application of excluded DNS name constraints when verifying wildcard names in crypto/x509 txtify archive
CVE-2025-61729 Excessive resource consumption when printing error string for host certificate validation in crypto/x509 txtify archive
CVE-2025-58186 Lack of limit when parsing cookies can cause memory exhaustion in net/http txtify archive
CVE-2026-24293 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-26148 Microsoft Azure AD SSH Login extension for Linux Elevation of Privilege Vulnerability txtify archive
CVE-2026-23865 An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2. txtify archive
CVE-2026-27138 Panic in name constraint checking for malformed certificates in crypto/x509 txtify archive
CVE-2026-27142 URLs in meta content attribute actions are not escaped in html/template txtify archive
CVE-2025-69644 An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually interrupted. This issue affects versions prior to the upstream fix and allows a local attacker to cause excessive resource consumption by supplying a malicious input file. txtify archive
CVE-2025-69651 GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service. txtify archive
CVE-2025-69649 GNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a crafted ELF binary with malformed header fields. During relocation processing, an invalid or null section pointer may be passed into display_relocations(), resulting in a segmentation fault (SIGSEGV) and abrupt termination. No evidence of memory corruption beyond the null pointer dereference, nor any possibility of code execution, was observed. txtify archive
CVE-2025-69645 Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). The issue was observed in binutils 2.44. A local attacker can trigger the crash by supplying a malicious input file. txtify archive
CVE-2025-69652 GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate into DWARF attribute parsing routines. When certain malformed attributes result in an unexpected data length of zero, byte_get_little_endian() triggers a fatal abort. No evidence of memory corruption or code execution was observed; the impact is limited to denial of service. txtify archive
CVE-2025-69650 GNU Binutils thru 2.46 readelf contains a double free vulnerability when processing a crafted ELF binary with malformed relocation data. During GOT relocation handling, dump_relocations may return early without initializing the all_relocations array. As a result, process_got_section_contents() may pass an uninitialized r_symbol pointer to free(), leading to a double free and terminating the program with SIGABRT. No evidence of exploitable memory corruption or code execution was observed; the impact is limited to denial of service. txtify archive
CVE-2025-69646 Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis. txtify archive
CVE-2026-3731 libssh SFTP Extension Name sftp.c sftp_extensions_get_data out-of-bounds txtify archive
Military Commissions Media Invitation Announced for United States v. Abd al-Rahim al-Nashiri Trial txtify archive
Secretary of War Pete Hegseth and Chairman of the Joint Chiefs of Staff Gen. Dan Caine Hold a Press Briefing txtify archive
CVE-2026-23660 Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability txtify archive
CVE-2026-23671 Windows Bluetooth RFCOM Protocol Driver Elevation of Privilege Vulnerability txtify archive
CVE-2026-23672 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability txtify archive
CVE-2026-23673 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability txtify archive
CVE-2026-24283 Multiple UNC Provider Kernel Driver Elevation of Privilege Vulnerability txtify archive
CVE-2026-24291 Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability txtify archive
CVE-2026-24292 Windows Connected Devices Platform Service Elevation of Privilege Vulnerability txtify archive
CVE-2026-24293 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-24295 Windows Device Association Service Elevation of Privilege Vulnerability txtify archive
CVE-2026-24296 Windows Device Association Service Elevation of Privilege Vulnerability txtify archive
CVE-2026-25166 Windows System Image Manager Assessment and Deployment Kit (ADK) Remote Code Execution Vulnerability txtify archive
CVE-2026-25172 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability txtify archive
CVE-2026-25173 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability txtify archive
CVE-2026-25174 Windows Extensible File Allocation Table Elevation of Privilege Vulnerability txtify archive
CVE-2026-25176 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-25178 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-25179 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-25186 Windows Accessibility Infrastructure (ATBroker.exe) Information Disclosure Vulnerability txtify archive
CVE-2026-26111 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability txtify archive
CVE-2026-20967 System Center Operations Manager (SCOM) Elevation of Privilege Vulnerability txtify archive
CVE-2026-26148 Microsoft Azure AD SSH Login extension for Linux Elevation of Privilege Vulnerability txtify archive
CVE-2026-23665 Linux Azure Diagnostic extension (LAD) Elevation of Privilege Vulnerability txtify archive
CVE-2026-26117 Arc Enabled Servers - Azure Connected Machine Agent Elevation of Privilege Vulnerability txtify archive
CVE-2026-26141 Hybrid Worker Extension (Arc‑enabled Windows VMs) Elevation of Privilege Vulnerability txtify archive
CVE-2026-26030 GitHub: CVE-2026-26030 Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable txtify archive
CVE-2026-28364 In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds validation in the readblock() function, which performs unbounded memcpy() operations using attacker-controlled lengths from crafted Marshal data. txtify archive
CVE-2026-22701 filelock Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock txtify archive
CVE-2025-68146 filelock has TOCTOU race condition that allows symlink attacks during lock file creation txtify archive
CVE-2026-26122 Microsoft ACI Confidential Containers Information Disclosure Vulnerability txtify archive
CVE-2026-23651 Microsoft ACI Confidential Containers Elevation of Privilege Vulnerability txtify archive
CVE-2026-26124 Microsoft ACI Confidential Containers Elevation of Privilege Vulnerability txtify archive
CVE-2026-26122 Microsoft ACI Confidential Containers Information Disclosure Vulnerability txtify archive
CVE-2026-23865 An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2. txtify archive
CVE-2026-24821 A heap-based buffer over-read that might affect a system that compiles untrusted Lua code in turanszkij/WickedEngine. txtify archive
Secretary of War Pete Hegseth and Admiral Brad Cooper, Commander of U.S. Central Command, Hold a Press Briefing at Central Command Headquarters on U.S. Military Operations in the Middle East txtify archive
CVE-2026-23651 Microsoft ACI Confidential Containers Elevation of Privilege Vulnerability txtify archive
CVE-2026-26124 Microsoft ACI Confidential Containers Elevation of Privilege Vulnerability txtify archive
CVE-2026-26122 Microsoft ACI Confidential Containers Information Disclosure Vulnerability txtify archive
CVE-2024-24856 NULL pointer deference in acpi_db_convert_to_package of Linux acpi module txtify archive
CVE-2022-4543 A flaw named "EntryBleed" was found in the Linux Kernel Page Table Isolation (KPTI). This issue could allow a local attacker to leak KASLR base via prefetch side-channels based on TLB timing for Intel systems. txtify archive
CVE-2026-0038 In multiple functions of mem_protect.c, there is a possible way to execute arbitrary code due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. txtify archive
CVE-2026-23865 An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2. txtify archive
CVE-2026-24821 A heap-based buffer over-read that might affect a system that compiles untrusted Lua code in turanszkij/WickedEngine. txtify archive
CVE-2026-27141 Sending certain HTTP/2 frames can cause a server to panic in golang.org/x/net txtify archive
Secretary of War Pete Hegseth and Chairman of the Joint Chiefs of Staff Gen. Dan Caine Hold a Press Briefing txtify archive
CVE-2025-58160 Tracing logging user input may result in poisoning logs with ANSI escape sequences txtify archive
CVE-2026-27965 Vitess users with backup storage access can gain unauthorized access to production deployment environments txtify archive
CVE-2025-69873 ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enabled. The pattern keyword accepts runtime data via JSON Pointer syntax ($data reference), which is passed directly to the JavaScript RegExp() constructor without validation. An attacker can inject a malicious regex pattern (e.g., "^(a|a)*$") combined with crafted input to cause catastrophic backtracking. A 31-character payload causes approximately 44 seconds of CPU blocking, with each additional character doubling execution time. This enables complete denial of service with a single HTTP request against any API using ajv with $data: true for dynamic schema validation. txtify archive
CVE-2025-62878 Local Path Provisioner vulnerable to Path Traversal via parameters.pathPattern txtify archive
CVE-2025-61145 libtiff up to v4.7.1 was discovered to contain a double free via the component tools/tiffcrop.c. txtify archive
CVE-2026-23220 ksmbd: fix infinite loop caused by next_smb2_rcv_hdr_off reset in error paths txtify archive
Secretary of War Pete Hegseth and Chairman of the Joint Chiefs of Staff Gen. Dan Caine Hold a Press Briefing txtify archive
CVE-2026-27969 Vitess users with backup storage access can write to arbitrary file paths on restore txtify archive
CVE-2025-69873 ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enabled. The pattern keyword accepts runtime data via JSON Pointer syntax ($data reference), which is passed directly to the JavaScript RegExp() constructor without validation. An attacker can inject a malicious regex pattern (e.g., "^(a|a)*$") combined with crafted input to cause catastrophic backtracking. A 31-character payload causes approximately 44 seconds of CPU blocking, with each additional character doubling execution time. This enables complete denial of service with a single HTTP request against any API using ajv with $data: true for dynamic schema validation. txtify archive
CVE-2026-23220 ksmbd: fix infinite loop caused by next_smb2_rcv_hdr_off reset in error paths txtify archive
CVE-2026-23216 scsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count() txtify archive
CVE-2026-28364 In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds validation in the readblock() function, which performs unbounded memcpy() operations using attacker-controlled lengths from crafted Marshal data. txtify archive
CVE-2026-22997 net: can: j1939: j1939_xtp_rx_rts_session_active(): deactivate session upon receiving the second rts txtify archive
CVE-2026-22976 net/sched: sch_qfq: Fix NULL deref when deactivating inactive aggregate in qfq_reset txtify archive
CVE-2025-71150 ksmbd: Fix refcount leak when invalid session is found on session lookup txtify archive
CVE-2025-68211 ksm: use range-walk function to jump over holes in scan_get_next_rmap_item txtify archive
CVE-2023-54207 HID: uclogic: Correct devm device reference for hidinput input_dev name txtify archive
CVE-2026-21518 GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability txtify archive
CVE-2026-21523 GitHub Copilot and Visual Studio Code Remote Code Execution Vulnerability txtify archive
CVE-2025-69873 ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enabled. The pattern keyword accepts runtime data via JSON Pointer syntax ($data reference), which is passed directly to the JavaScript RegExp() constructor without validation. An attacker can inject a malicious regex pattern (e.g., "^(a|a)*$") combined with crafted input to cause catastrophic backtracking. A 31-character payload causes approximately 44 seconds of CPU blocking, with each additional character doubling execution time. This enables complete denial of service with a single HTTP request against any API using ajv with $data: true for dynamic schema validation. txtify archive
CVE-2026-27969 Vitess users with backup storage access can write to arbitrary file paths on restore txtify archive
CVE-2026-27965 Vitess users with backup storage access can gain unauthorized access to production deployment environments txtify archive
CISA Issues Updated RESURGE Malware Analysis Highlighting a Stealthy but Active Threat txtify archive
CVE-2025-62878 Local Path Provisioner vulnerable to Path Traversal via parameters.pathPattern txtify archive
CVE-2025-61145 libtiff up to v4.7.1 was discovered to contain a double free via the component tools/tiffcrop.c. txtify archive
CVE-2025-61144 libtiff up to v4.7.1 was discovered to contain a stack overflow via the readSeparateStripsIntoBuffer function. txtify archive
CVE-2025-61143 libtiff up to v4.7.1 was discovered to contain a NULL pointer dereference via the component libtiff/tif_open.c. txtify archive
CVE-2021-20233 A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calculation on the assumption that expressing a quoted single quote will require 3 characters while it actually requires 4 characters which allows an attacker to corrupt memory by one byte for each quote in the input. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. txtify archive
CVE-2021-20225 A flaw was found in grub2 in versions prior to 2.06. The option parser allows an attacker to write past the end of a heap-allocated buffer by calling certain commands with a large number of specific short forms of options. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. txtify archive
Military Commissions Media Invitation Announced for United States v. Abd al-Rahim al-Nashiri Pre-Trial Hearing txtify archive
Immediate Action Required: CISA Issues Emergency Directive to Secure Cisco SD-WAN Systems txtify archive
CVE-2026-26960 node-tar has Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in Extraction txtify archive
CVE-2025-68973 In GnuPG through 2.4.8, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted input. (For ExtendedLTS, 2.2.51 and later are fixed versions.) txtify archive
CVE-2026-2739 This affects versions of the package bn.js before 5.2.3. Calling maskn(0) on any BN instance corrupts the internal state, causing toString(), divmod(), and other methods to enter an infinite loop, hanging the process indefinitely. txtify archive
Horrific executions of El Mencho's 'cannibal cartel': From hitmen who cut out and ate victim's heart to mass beheadings and rivals 'blasted with flame throwers', how slain drug lord used extreme violence to spread fear txtify archive
Every detail of Jeffrey Epstein's massive web of influence uncovered in the Mail's interactive Deep Dive into hundreds of surprising connections txtify archive
CVE-2025-71101 platform/x86: hp-bioscfg: Fix out-of-bounds array access in ACPI package parsing txtify archive
CVE-2025-71109 MIPS: ftrace: Fix memory corruption when kernel is located beyond 32 bits txtify archive
CVE-2025-61729 Excessive resource consumption when printing error string for host certificate validation in crypto/x509 txtify archive
CVE-2025-71066 net/sched: ets: Always remove class from active list before deleting in ets_qdisc_change txtify archive
CVE-2025-58436 OpenPrinting CUPS slow client can halt cupsd, leading to a possible DoS attack txtify archive
CVE-2025-68808 media: vidtv: initialize local pointers upon transfer of memory ownership txtify archive
CVE-2025-68781 usb: phy: fsl-usb: Fix use-after-free in delayed work during device removal txtify archive
CVE-2022-22576 An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S) IMAP(S) POP3(S) and LDAP(S) (openldap only). txtify archive
CVE-2025-34468 libcoap Stack-Based Buffer Overflow in Address Resolution DoS or Potential RCE txtify archive
CVE-2025-66382 In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time. txtify archive
CVE-2022-32206 curl < 7.84.0 supports "chained" HTTP compression algorithms meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable "links" in this "decompression chain" was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps.The use of such a decompression chain could result in a "malloc bomb" makingcurl end up spending enormous amounts of allocated heap memory or trying toand returning out of memory errors. txtify archive
CVE-2022-27782 libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse if one of them matches the setup. However several TLS andSSH settings were left out from the configuration match checks making themmatch too easily. txtify archive
CVE-2026-21860 Werkzeug safe_join() allows Windows special device names with compound extensions txtify archive
CVE-2025-65637 A denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line payload larger than 64KB without newline characters. txtify archive
CVE-2025-21839 KVM: x86: Load DR6 with guest value only before entering .vcpu_run() loop txtify archive
CVE-2025-15444 Crypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libsodium txtify archive
CVE-2025-48637 In multiple functions of mem_protect.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. txtify archive
CVE-2025-61727 Improper application of excluded DNS name constraints when verifying wildcard names in crypto/x509 txtify archive
CVE-2020-36426 An issue was discovered in Arm Mbed TLS before 2.24.0. mbedtls_x509_crl_parse_der has a buffer over-read (of one byte). txtify archive
CVE-2024-58089 btrfs: fix double accounting race when btrfs_run_delalloc_range() failed txtify archive
CVE-2021-24119 In Trusted Firmware Mbed TLS 2.24.0, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on software running in isolated environments that can be single stepped, especially Intel SGX. txtify archive
CVE-2023-52969 MariaDB Server 10.4 through 10.5.*, 10.6 through 10.6.*, 10.7 through 10.11.*, and 11.0 through 11.0.* can sometimes crash with an empty backtrace log. This may be related to make_aggr_tables_info and optimize_stage2. txtify archive
CVE-2024-46751 btrfs: don't BUG_ON() when 0 reference count at btrfs_lookup_extent_info() txtify archive
CVE-2024-46786 fscache: delete fscache_cookie_lru_timer when fscache exits to avoid UAF txtify archive
CVE-2024-50008 wifi: mwifiex: Fix memcpy() field-spanning write warning in mwifiex_cmd_802_11_scan_ext() txtify archive
CVE-2024-49954 static_call: Replace pointless WARN_ON() in static_call_module_notify() txtify archive
CVE-2024-8176 Libexpat: expat: improper restriction of xml entity expansion depth in libexpat txtify archive
CVE-2024-55549 xsltGetInheritedNsList in libxslt before 1.1.43 has a use-after-free issue txtify archive
CVE-2025-1767 This CVE only affects Kubernetes clusters that utilize the in-tree gitRepo volume to clone git repositories from other pods within the same node. Since the in-tree gitRepo volume feature has been deprecated and will not receive security updates upstream, any cluster still using this feature remains vulnerable. txtify archive
CVE-2024-9407 Buildah: podman: improper input validation in bind-propagation option of dockerfile run --mount instruction txtify archive
CVE-2025-29768 Vim vulnerable to potential data loss with zip.vim and special crafted zip files txtify archive
CVE-2024-46832 MIPS: cevt-r4k: Don't call get_c0_compare_int if timer irq is installed txtify archive
CVE-2024-46757 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. txtify archive
CVE-2022-32207 When curl < 7.84.0 saves cookies alt-svc and hsts data to local files it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation it might accidentally *widen* the permissions for the target file leaving the updated file accessible to more users than intended. txtify archive
CVE-2022-27774 An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authentication could leak credentials to other services that exist on different protocols or port numbers. txtify archive
CVE-2022-27779 libcurl wrongly allows cookies to be set for Top Level Domains (TLDs) if thehost name is provided with a trailing dot.curl can be told to receive and send cookies. curl's "cookie engine" can bebuilt with or without [Public Suffix List](https://publicsuffix.org/)awareness. If PSL support not provided a more rudimentary check exists to atleast prevent cookies from being set on TLDs. This check was broken if thehost name in the URL uses a trailing dot.This can allow arbitrary sites to set cookies that then would get sent to adifferent and unrelated site or domain. txtify archive
CVE-2024-45720 Apache Subversion: Command line argument injection on Windows platforms txtify archive
CVE-2025-21861 mm/migrate_device: don't add folio to be freed to LRU in migrate_device_finalize() txtify archive
CVE-2022-27781 libcurl provides the `CURLOPT_CERTINFO` option to allow applications torequest details to be returned about a server's certificate chain.Due to an erroneous function a malicious server could make libcurl built withNSS get stuck in a never-ending busy-loop when trying to retrieve thatinformation. txtify archive
CVE-2024-46834 ethtool: fail closed if we can't get max channel used in indirection tables txtify archive
CVE-2025-21866 powerpc/code-patching: Fix KASAN hit by not flagging text patching area as VM_ALLOC txtify archive
CVE-2024-46756 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. txtify archive
CVE-2022-27775 An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead. txtify archive
CVE-2024-46758 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. txtify archive
CVE-2024-0133 NVIDIA Container Toolkit 1.16.1 or earlier contains a vulnerability in the default mode of operation allowing a specially crafted container image to create empty files on the host file system. This does not impact use cases where CDI is used. A successful exploit of this vulnerability may lead to data tampering. txtify archive
CVE-2022-32208 When curl < 7.84.0 does FTP transfers secured by krb5 it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client. txtify archive
CVE-2022-27780 The curl URL parser wrongly accepts percent-encoded URL separators like '/'when decoding the host name part of a URL making it a *different* URL usingthe wrong host name when it is later retrieved.For example a URL like `http://example.com%2F127.0.0.1/` would be allowed bythe parser and get transposed into `http://example.com/127.0.0.1/`. This flawcan be used to circumvent filters checks and more. txtify archive
CVE-2024-49945 net/ncsi: Disable the ncsi work before freeing the associated structure txtify archive
CVE-2024-46841 btrfs: don't BUG_ON on ENOMEM from btrfs_lookup_extent_info() in walk_down_proc() txtify archive
CVE-2024-9632 Xorg-x11-server: tigervnc: heap-based buffer overflow privilege escalation vulnerability txtify archive
CVE-2024-8927 cgi.force_redirect configuration is bypassable due to the environment variable collision txtify archive
CVE-2024-46743 of/irq: Prevent device address out-of-bounds read in interrupt map walk txtify archive
CVE-2024-47191 pam_oath.so in oath-toolkit 2.6.7 through 2.6.11 before 2.6.12 allows root privilege escalation because in the context of PAM code running as root it mishandles usersfile access such as by calling fchown in the presence of a symlink. txtify archive
CVE-2024-46742 smb/server: fix potential null-ptr-deref of lease_ctx_info in smb2_open() txtify archive
CVE-2024-9341 Podman: buildah: cri-o: fips crypto-policy directory mounting issue in containers/common go library txtify archive
CVE-2024-50002 static_call: Handle module init failure correctly in static_call_del_module() txtify archive
CVE-2024-50084 net: microchip: vcap api: Fix memory leaks in vcap_api_encode_rule_test() txtify archive
CVE-2024-46749 Bluetooth: btnxpuart: Fix Null pointer dereference in btnxpuart_flush() txtify archive
CVE-2024-46811 drm/amd/display: Fix index may exceed array range within fpu_update_bw_bounding_box txtify archive
CVE-2024-47554 Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader txtify archive
CVE-2024-46738 VMCI: Fix use-after-free when removing resource in vmci_resource_remove() txtify archive
CVE-2013-4416 The Ocaml xenstored implementation (oxenstored) in Xen 4.1.x, 4.2.x, and 4.3.x allows local guest domains to cause a denial of service (domain shutdown) via a large message reply. txtify archive
CVE-2024-46810 drm/bridge: tc358767: Check if fully initialized before signalling HPD event via IRQ txtify archive
CVE-2024-50005 mac802154: Fix potential RCU dereference issue in mac802154_scan_worker txtify archive
CVE-2024-46687 btrfs: fix a use-after-free when hitting errors inside btrfs_submit_chunk() txtify archive
CVE-2024-39291 drm/amdgpu: Fix buffer size in gfx_v9_4_3_init_ cp_compute_microcode() and rlc_microcode() txtify archive
CVE-2024-45022 mm/vmalloc: fix page mapping if vm_area_alloc_pages() with high order fallback to order 0 txtify archive
CVE-2023-52920 bpf: support non-r10 register spill/fill to/from stack in precision tracking txtify archive
CVE-2024-49959 jbd2: stop waiting for space when jbd2_cleanup_journal_tail() returns error txtify archive
CVE-2024-42311 hfs: fix to initialize fields of hfs_inode_info after hfs_alloc_inode() txtify archive
CVE-2024-49968 ext4: filesystems without casefold feature cannot be mounted with siphash txtify archive
CVE-2024-42308 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. txtify archive
CVE-2023-7256 Double-free in libpcap before 1.10.5 with remote packet capture support. txtify archive
CVE-2024-8006 NULL pointer dereference in libpcap before 1.10.5 with remote packet capture support txtify archive
CVE-2024-33877 HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5T__conv_struct_opt in H5Tconv.c. txtify archive
CVE-2024-33873 HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5D__scatter_mem in H5Dscatgath.c. txtify archive
CVE-2024-32624 HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T__ref_mem_setnull in H5Tref.c (called from H5T__conv_ref in H5Tconv.c) resulting in the corruption of the instruction pointer. txtify archive
CVE-2024-26951 wireguard: netlink: check for dangling peer via is_dead instead of empty list txtify archive
CVE-2023-6864 Memory safety bugs present in Firefox 120, Firefox ESR 115.5, and Thunderbird 115.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121. txtify archive
CVE-2017-15042 An unintended cleartext issue exists in Go before 1.8.4 and 1.9.x before 1.9.1. RFC 4954 requires that, during SMTP, the PLAIN auth scheme must only be used on network connections secured with TLS. The original implementation of smtp.PlainAuth in Go 1.0 enforced this requirement, and it was documented to do so. In 2013, upstream issue #5184, this was changed so that the server may decide whether PLAIN is acceptable. The result is that if you set up a man-in-the-middle SMTP server that doesn't advertise STARTTLS and does advertise that PLAIN auth is OK, the smtp.PlainAuth implementation sends the username and password. txtify archive
CVE-2023-6856 The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overflow when used on systems with the Mesa VM driver. This issue could allow an attacker to perform remote code execution and sandbox escape. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121. txtify archive
CVE-2025-24855 numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is related to xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs, and xsltComputeSortResultInternal. txtify archive
CVE-2025-71136 media: adv7842: Avoid possible out-of-bounds array accesses in adv7842_cp_log_status() txtify archive
CVE-2017-1000097 On Darwin, user's trust preferences for root certificates were not honored. If the user had a root certificate loaded in their Keychain that was explicitly not trusted, a Go program would still verify a connection using that root certificate. txtify archive
CVE-2025-71091 team: fix check for port enabled in team_queue_override_port_prio_changed() txtify archive
CVE-2025-68788 fsnotify: do not generate ACCESS/MODIFY events on child for special files txtify archive
CVE-2025-68815 net/sched: ets: Remove drr class from the active list if it changes to strict txtify archive
CVE-2025-68818 scsi: Revert "scsi: qla2xxx: Perform lockless command completion in abort path" txtify archive
CVE-2025-71097 ipv4: Fix reference count leak when using error routes with nexthop objects txtify archive
Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) txtify archive
Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) txtify archive
Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) txtify archive
CVE-2025-68800 mlxsw: spectrum_mr: Fix use-after-free when updating multicast route stats txtify archive
CVE-2020-0569 Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticated user to potentially enable denial of service via local access. txtify archive
CVE-2020-14378 An integer underflow in dpdk versions before 18.11.10 and before 19.11.5 in the `move_desc` function can lead to large amounts of CPU cycles being eaten up in a long running loop. An attacker could cause `move_desc` to get stuck in a 4,294,967,295-count iteration loop. Depending on how `vhost_crypto` is being used this could prevent other VMs or network tasks from being serviced by the busy DPDK lcore for an extended period. txtify archive
CVE-2025-68778 btrfs: don't log conflicting inode if it's a dir moved in the current transaction txtify archive
CVE-2025-71079 net: nfc: fix deadlock between nfc_unregister_device and rfkill_fop_write txtify archive
CVE-2025-68806 ksmbd: fix buffer validation by including null terminator size in EA length txtify archive
CVE-2021-33503 An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component the authority regular expression exhibits catastrophic backtracking causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect. txtify archive
CVE-2022-42916 In curl before 7.86.0 the HSTS check could be bypassed to trick it into staying with HTTP. Using its HSTS support curl can be instructed to use HTTPS directly (instead of using an insecure cleartext HTTP step) even when HTTP is provided in the URL. This mechanism could be bypassed if the host name in the given URL uses IDN characters that get replaced with ASCII counterparts as part of the IDN conversion e.g. using the character UTF-8 U+3002 (IDEOGRAPHIC FULL STOP) instead of the common ASCII full stop of U+002E (.). The earliest affected version is 7.77.0 2021-05-26. txtify archive
CVE-2026-22801 LIBPNG has an integer truncation causing heap buffer over-read in png_image_write_* txtify archive
CVE-2026-22701 filelock Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock txtify archive
CVE-2025-60876 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). txtify archive
CVE-2025-68291 mptcp: Initialise rcv_mss before calling tcp_send_active_reset() in mptcp_do_fastclose(). txtify archive
CVE-2022-43680 In libexpat through 2.4.9 there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations. txtify archive
CVE-2023-46343 In the Linux kernel before 6.5.9 there is a NULL pointer dereference in send_acknowledge in net/nfc/nci/spi.c. txtify archive
CVE-2023-51043 In the Linux kernel before 6.4.5 drivers/gpu/drm/drm_atomic.c has a use-after-free during a race condition between a nonblocking atomic commit and a driver unload. txtify archive
CVE-2024-23850 In btrfs_get_root_ref in fs/btrfs/disk-io.c in the Linux kernel through 6.7.1 there can be an assertion failure and crash because a subvolume can be read out too soon after its root item is inserted upon subvolume creation. txtify archive
CVE-2024-0775 Kernel: use-after-free while changing the mount option in __ext4_remount leading txtify archive
CVE-2023-51042 In the Linux kernel before 6.4.12 amdgpu_cs_wait_all_fences in drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c has a fence use-after-free. txtify archive
CVE-2024-23848 In the Linux kernel through 6.7.1, there is a use-after-free in cec_queue_msg_fh, related to drivers/media/cec/core/cec-adap.c and drivers/media/cec/core/cec-api.c. txtify archive
CVE-2024-23851 copy_params in drivers/md/dm-ioctl.c in the Linux kernel through 6.7.1 can attempt to allocate more than INT_MAX bytes and crash because of a missing param_kernel->data_size check. This is related to ctl_ioctl. txtify archive
CVE-2023-6531 Kernel: gc's deletion of an skb races with unix_stream_read_generic() leading to uaf txtify archive
CVE-2024-23849 In rds_recv_track_latency in net/rds/af_rds.c in the Linux kernel through 6.7.1 there is an off-by-one error for an RDS_MSG_RX_DGRAM_TRACE_MAX comparison resulting in out-of-bounds access. txtify archive
CVE-2024-22705 An issue was discovered in ksmbd in the Linux kernel before 6.6.10. smb2_get_data_area_len in fs/smb/server/smb2misc.c can cause an smb_strndup_from_utf16 out-of-bounds access because the relationship between Name data and CreateContexts data is mishandled. txtify archive
CVE-2023-51258 A memory leak issue discovered in YASM v.1.3.0 allows a local attacker to cause a denial of service via the new_Token function in the modules/preprocs/nasm/nasm-pp:1512. txtify archive
CVE-2024-0741 An out of bounds write in ANGLE could have allowed an attacker to corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7. txtify archive
CVE-2023-49569 Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients txtify archive
CVE-2024-0646 Kernel: ktls overwrites readonly memory pages when using function splice with a ktls socket as destination txtify archive
CVE-2024-0565 Kernel: cifs filesystem decryption improper input validation remote code execution vulnerability in function receive_encrypted_standard of client txtify archive
CVE-2024-0562 Kernel: use-after-free after removing device in wb_inode_writeback_end in mm/page-writeback.c txtify archive
CVE-2022-29526 Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags parameter the Faccessat function could incorrectly report that a file is accessible. txtify archive
CVE-2022-32149 Denial of service via crafted Accept-Language header in golang.org/x/text/language txtify archive
CVE-2020-22217 Buffer overflow vulnerability in c-ares before 1_16_1 thru 1_17_0 via function ares_parse_soa_reply in ares_parse_soa_reply.c. txtify archive
CVE-2022-4904 A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or a limited impact on confidentiality and integrity. txtify archive
CVE-2021-44716 net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontrolled memory consumption in the header canonicalization cache via HTTP/2 requests. txtify archive
CVE-2023-6040 An out-of-bounds access vulnerability involving netfilter was reported and fixed as: f1082dd31fe4 (netfilter: nf_tables: Reject tables of unsupported family) txtify archive
CVE-2023-46219 When saving HSTS data to an excessively long file name curl could end up removing all contents making subsequent requests using that file unaware of the HSTS status they should otherwise use. txtify archive
CVE-2020-18032 Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by loading a crafted file into the "lib/common/shapes.c" component. txtify archive
CVE-2020-21528 A Segmentation Fault issue discovered in in ieee_segment function in outieee.c in nasm 2.14.03 and 2.15 allows remote attackers to cause a denial of service via crafted assembly file. txtify archive
CVE-2018-1129 A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to bypass signature checks done by cephx protocol. Ceph branches master mimic luminous and jewel are believed to be vulnerable. txtify archive
CVE-2021-38191 An issue was discovered in the tokio crate before 1.8.1 for Rust. Upon a JoinHandle::abort, a Task may be dropped in the wrong thread. txtify archive
CVE-2023-3600 During the worker lifecycle, a use-after-free condition could have occured, which could have led to a potentially exploitable crash. This vulnerability affects Firefox < 115.0.2, Firefox ESR < 115.0.2, and Thunderbird < 115.0.1. txtify archive
CVE-2020-15586 Go before 1.13.13 and 1.14.x before 1.14.5 has a data race in some net/http servers as demonstrated by the httputil.ReverseProxy Handler because it reads a request body and writes a response at the same time. txtify archive
CVE-2023-29405 Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go txtify archive
CVE-2024-20963 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). txtify archive
CVE-2024-20965 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H). txtify archive
CVE-2024-20969 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H). txtify archive
CVE-2019-11358 jQuery before 3.4.0 as used in Drupal Backdrop CMS and other products mishandles jQuery.extend(true {} ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property it could extend the native Object.prototype. txtify archive
CVE-2024-20985 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: UDF). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). txtify archive
CVE-2024-20967 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H). txtify archive
CVE-2024-20981 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H). txtify archive
CVE-2025-21959 netfilter: nf_conncount: Fully initialize struct nf_conncount_tuple in insert_tree() txtify archive
CVE-2024-20973 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). txtify archive
CVE-2023-37203 Insufficient validation in the Drag and Drop API in conjunction with social engineering, may have allowed an attacker to trick end-users into creating a shortcut to local system files. This could have been leveraged to execute arbitrary code. This vulnerability affects Firefox < 115. txtify archive
CVE-2024-20961 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). txtify archive
CVE-2024-30251 Denial of service when trying to parse malformed POST requests in aiohttp txtify archive
CVE-2019-16168 In SQLite through 3.29.0 whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field aka a "severe division by zero in the query planner." txtify archive
CVE-2024-20971 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H). txtify archive
CVE-2024-20977 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). txtify archive
CVE-2018-19416 An issue was discovered in sysstat 12.1.1. The remap_struct function in sa_common.c has an out-of-bounds read during a memmove call, as demonstrated by sadf. txtify archive
CVE-2022-48619 An issue was discovered in drivers/input/input.c in the Linux kernel before 5.17.10. An attacker can cause a denial of service (panic) because input_set_capability mishandles the situation in which an event code falls outside of a bitmap. txtify archive
CVE-2022-42915 curl before 7.86.0 has a double free. If curl is told to use an HTTP proxy for a transfer with a non-HTTP(S) URL it sets up the connection to the remote server by issuing a CONNECT request to the proxy and then tunnels the rest of the protocol through. An HTTP proxy might refuse this request (HTTP proxies often only allow outgoing connections to specific port numbers like 443 for HTTPS) and instead return a non-200 status code to the client. Due to flaws in the error/cleanup handling this could trigger a double free in curl if one of the following schemes were used in the URL for the transfer: dict gopher gophers ldap ldaps rtmp rtmps or telnet. The earliest affected version is 7.77.0. txtify archive
CVE-2022-2585 It was discovered that when exec'ing from a non-leader thread armed POSIX CPU timers would be left on a list but freed leading to a use-after-free. txtify archive
CVE-2010-4756 The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632. txtify archive
CVE-2019-14203 An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: nfs_mount_reply. txtify archive
CVE-2023-48161 Buffer Overflow vulnerability in GifLib Project GifLib v.5.2.1 allows a local attacker to obtain sensitive information via the DumpSCreen2RGB function in gif2rgb.c txtify archive
CVE-2023-45857 An issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information. txtify archive
CVE-2022-46457 NASM v2.16 was discovered to contain a segmentation violation in the component ieee_write_file at /output/outieee.c. txtify archive
CVE-2024-57256 An integer overflow in ext4fs_read_symlink in Das U-Boot before 2025.01-rc1 occurs for zalloc (adding one to an le32 variable) via a crafted ext4 filesystem with an inode size of 0xffffffff, resulting in a malloc of zero and resultant memory overwrite. txtify archive
CVE-2023-39742 giflib v5.2.1 was discovered to contain a segmentation fault via the component getarg.c. txtify archive
CVE-2019-16707 Hunspell 1.7.0 has an invalid read operation in SuggestMgr::leftcommonsubstring in suggestmgr.cxx. txtify archive
CVE-2018-20505 SQLite 3.25.2 when queries are run on a table with a malformed PRIMARY KEY allows remote attackers to cause a denial of service (application crash) by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases). txtify archive
CVE-2022-28506 There is a heap-buffer-overflow in GIFLIB 5.2.1 function DumpScreen2RGB() in gif2rgb.c:298:45. txtify archive
CVE-2019-14193 An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with an unvalidated length at nfs_readlink_reply, in the "if" block after calculating the new path length. txtify archive
CVE-2022-24999 qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express application because an __ proto__ key can be used. In many typical Express use cases, an unauthenticated remote attacker can place the attack payload in the query string of the URL that is used to visit the application, such as a[__proto__]=b&a[__proto__]&a[length]=100000000. The fix was backported to qs 6.9.7, 6.8.3, 6.7.3, 6.6.1, 6.5.3, 6.4.1, 6.3.3, and 6.2.4 (and therefore Express 4.17.3, which has "deps: qs@6.9.7" in its release description, is not vulnerable). txtify archive
CVE-2020-10941 Arm Mbed TLS before 2.16.5 allows attackers to obtain sensitive information (an RSA private key) by measuring cache usage during an import. txtify archive
CVE-2019-18222 The ECDSA signature implementation in ecdsa.c in Arm Mbed Crypto 2.1 and Mbed TLS through 2.19.1 does not reduce the blinded scalar before computing the inverse, which allows a local attacker to recover the private key via side-channel attacks. txtify archive
CVE-2023-42365 A use-after-free vulnerability was discovered in BusyBox v.1.36.1 via a crafted awk pattern in the awk.c copyvar function. txtify archive
CVE-2012-6708 jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differentiate selectors from HTML in a reliable fashion. In vulnerable versions jQuery determined whether the input was HTML by looking for the '<' character anywhere in the string giving attackers more flexibility when attempting to construct a malicious payload. In fixed versions jQuery only deems the input to be HTML if it explicitly starts with the '<' character limiting exploitability only to attackers who can control the beginning of a string which is far less common. txtify archive
CVE-2022-33967 squashfs filesystem implementation of U-Boot versions from v2020.10-rc2 to v2022.07-rc5 contains a heap-based buffer overflow vulnerability due to a defect in the metadata reading process. Loading a specially crafted squashfs image may lead to a denial-of-service (DoS) condition or arbitrary code execution. txtify archive
CVE-2023-42364 A use-after-free vulnerability in BusyBox v.1.36.1 allows attackers to cause a denial of service via a crafted awk pattern in the awk.c evaluate function. txtify archive
CVE-2022-45410 When a ServiceWorker intercepted a request with <code>FetchEvent</code>, the origin of the request was lost after the ServiceWorker took ownership of it. This had the effect of negating SameSite cookie protections. This was addressed in the spec and then in browsers. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107. txtify archive
CVE-2025-38300 crypto: sun8i-ce-cipher - fix error handling in sun8i_ce_cipher_prepare() txtify archive
CVE-2025-27810 Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uninitialized stack memory to compose the TLS Finished message, potentially leading to authentication bypasses such as replays. txtify archive
CVE-2025-60753 An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules. This can cause unbounded memory allocation and lead to denial of service (Out-of-Memory crash). txtify archive
CVE-2022-27536 Certificate.Verify in crypto/x509 in Go 1.18.x before 1.18.1 can be caused to panic on macOS when presented with certain malformed certificates. This allows a remote TLS server to cause a TLS client to panic. txtify archive
CVE-2024-50613 libsndfile through 1.2.2 has a reachable assertion, that may lead to application exit, in mpeg_l3_encode.c mpeg_l3_encoder_close. txtify archive
CVE-2023-42366 A heap-buffer-overflow was discovered in BusyBox v.1.36.1 in the next_token function at awk.c:1159. txtify archive
CVE-2025-53547 Helm Chart Dependency Updating With Malicious Chart.yaml Content And Symlink Can Lead To Code Execution txtify archive
CVE-2019-14197 An issue was discovered in Das U-Boot through 2019.07. There is a read of out-of-bounds data at nfs_read_reply. txtify archive
CVE-2024-50614 TinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/16, that may lead to application exit, in tinyxml2.cpp XMLUtil::GetCharacterRef. txtify archive
CVE-2020-36475 An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). The calculations performed by mbedtls_mpi_exp_mod are not limited; thus, supplying overly large parameters could lead to denial of service when generating Diffie-Hellman key pairs. txtify archive
CVE-2024-50615 TinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/digit, that may lead to application exit, in tinyxml2.cpp XMLUtil::GetCharacterRef. txtify archive
CVE-2020-36477 An issue was discovered in Mbed TLS before 2.24.0. The verification of X.509 certificates when matching the expected common name (the cn argument of mbedtls_x509_crt_verify) with the actual certificate name is mishandled: when the subjecAltName extension is present, the expected name is compared to any name in that extension regardless of its type. This means that an attacker could impersonate a 4-byte or 16-byte domain by getting a certificate for the corresponding IPv4 or IPv6 address (this would require the attacker to control that IP address, though). txtify archive
CVE-2023-6816 Xorg-x11-server: heap buffer overflow in devicefocusevent and procxiquerypointer txtify archive
CVE-2023-28154 Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object. txtify archive
CVE-2010-0291 The Linux kernel before 2.6.32.4 allows local users to gain privileges or cause a denial of service (panic) by calling the (1) mmap or (2) mremap function, aka the "do_mremap() mess" or "mremap/mmap mess." txtify archive
CVE-2011-4969 Cross-site scripting (XSS) vulnerability in jQuery before 1.6.3, when using location.hash to select elements, allows remote attackers to inject arbitrary web script or HTML via a crafted tag. txtify archive
CVE-2022-33103 Das U-Boot from v2020.10 to v2022.07-rc3 was discovered to contain an out-of-bounds write via the function sqfs_readdir(). txtify archive
CVE-2025-38249 ALSA: usb-audio: Fix out-of-bounds read in snd_usb_get_audioformat_uac3() txtify archive
CVE-2020-36424 An issue was discovered in Arm Mbed TLS before 2.24.0. An attacker can recover a private key (for RSA or static Diffie-Hellman) via a side-channel attack against generation of base blinding/unblinding values. txtify archive
CVE-2023-45853 MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename comment or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version and exposes the applicable MiniZip code through its compress API. txtify archive
CVE-2024-31755 cJSON v1.7.17 was discovered to contain a segmentation violation which can trigger through the second parameter of function cJSON_SetValuestring at cJSON.c. txtify archive
CVE-2025-38245 atm: Release atm_dev_mutex after removing procfs in atm_dev_deregister(). txtify archive
CVE-2024-42040 Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today on any platform allows an attacker on the local network to leak memory from four up to 32 bytes of memory stored behind the packet to the network depending on the later use of DHCP-provided parameters via crafted DHCP responses. txtify archive
CVE-2025-37936 perf/x86/intel: KVM: Mask PEBS_ENABLE loaded for guest with vCPU's value. txtify archive
CVE-2025-64436 KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes txtify archive
CVE-2024-42068 bpf: Take return from set_memory_ro() into account with bpf_prog_lock_ro() txtify archive
CVE-2025-23144 backlight: led_bl: Hold led_access lock when calling led_sysfs_disable() txtify archive
CVE-2024-57911 iio: dummy: iio_simply_dummy_buffer: fix information leak in triggered buffer txtify archive
CVE-2019-14200 An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: rpc_lookup_reply. txtify archive
CVE-2025-37973 wifi: cfg80211: fix out-of-bounds access during multi-link element defragmentation txtify archive
CVE-2025-38258 mm/damon/sysfs-schemes: free old damon_sysfs_scheme_filter->memcg_path on write txtify archive
CVE-2019-14198 An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with a failed length check at nfs_read_reply when calling store_block in the NFSv3 case. txtify archive
CVE-2025-37758 ata: pata_pxa: Fix potential NULL pointer dereference in pxa_ata_probe() txtify archive
CVE-2024-32650 Rustls vulnerable to an infinite loop in rustls::conn::ConnectionCommon::complete_io() with proper client input txtify archive
CVE-2022-30790 Das U-Boot 2022.01 has a Buffer Overflow, a different issue than CVE-2022-30552. txtify archive
CVE-2023-28155 The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS or HTTPS to HTTP). NOTE: This vulnerability only affects products that are no longer supported by the maintainer. txtify archive
CVE-2024-57798 drm/dp_mst: Ensure mst_primary pointer is valid in drm_dp_mst_handle_up_req() txtify archive
CVE-2019-14192 An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy when parsing a UDP packet due to a net_process_received_packet integer underflow during an nc_input_packet call. txtify archive
CVE-2023-26136 Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using CookieJar in rejectPublicSuffixes=false mode. This issue arises from the manner in which the objects are initialized. txtify archive
CVE-2024-49962 ACPICA: check null return of ACPI_ALLOCATE_ZEROED() in acpi_db_convert_to_package() txtify archive
CVE-2021-38578 Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize. txtify archive
CVE-2023-44270 An issue was discovered in PostCSS before 8.4.31. The vulnerability affects linters using PostCSS to parse external untrusted CSS. An attacker can prepare CSS in such a way that it will contains parts parsed by PostCSS as a CSS comment. After processing by PostCSS, it will be included in the PostCSS output in CSS nodes (rules, properties) despite being included in a comment. txtify archive
CVE-2025-37742 jfs: Fix uninit-value access of imap allocated in the diMount() function txtify archive
CVE-2020-36478 An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). A NULL algorithm parameters entry looks identical to an array of REAL (size zero) and thus the certificate is considered valid. However, if the parameters do not match in any way, then the certificate should be considered invalid. txtify archive
CVE-2024-49985 i2c: stm32f7: Do not prepare/unprepare clock during runtime suspend/resume txtify archive
CVE-2025-32023 Redis allows out of bounds writes in hyperloglog commands leading to RCE txtify archive
CVE-2024-57257 A stack consumption issue in sqfs_size in Das U-Boot before 2025.01-rc1 occurs via a crafted squashfs filesystem with deep symlink nesting. txtify archive
CVE-2025-38237 media: platform: exynos4-is: Add hardware sync wait to fimc_is_hw_change_mode() txtify archive
CVE-2024-50015 ext4: dax: fix overflowing extents beyond inode size when partially writing txtify archive
CVE-2025-27809 Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unless the TLS client application calls mbedtls_ssl_set_hostname. txtify archive
CVE-2025-37810 usb: dwc3: gadget: check that event count does not exceed event buffer length txtify archive
CVE-2023-45142 OpenTelemetry-Go Contrib has DoS vulnerability in otelhttp due to unbound cardinality metrics txtify archive
CVE-2019-14194 An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with a failed length check at nfs_read_reply when calling store_block in the NFSv2 case. txtify archive
CVE-2024-42070 netfilter: nf_tables: fully validate NFT_DATA_VALUE on store to data registers txtify archive
CVE-2019-14201 An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: nfs_lookup_reply. txtify archive
CVE-2025-38104 drm/amdgpu: Replace Mutex with Spinlock for RLCG register access to avoid Priority Inversion in SRIOV txtify archive
CVE-2023-39319 Improper handling of special tags within script contexts in html/template txtify archive
CVE-2024-42228 drm/amdgpu: Using uninitialized value *size when calling amdgpu_vce_cs_reloc txtify archive
CVE-2019-14199 An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy when parsing a UDP packet due to a net_process_received_packet integer underflow during an *udp_packet_handler call. txtify archive
CVE-2025-68756 block: Use RCU in blk_mq_[un]quiesce_tagset() instead of set->tag_list_lock txtify archive
CVE-2024-57258 Integer overflows in memory allocation in Das U-Boot before 2025.01-rc1 occur for a crafted squashfs filesystem via sbrk, via request2size, or because ptrdiff_t is mishandled on x86_64. txtify archive
CVE-2025-38227 media: vidtv: Terminating the subsequent process of initialization failure txtify archive
CVE-2023-51781 An issue was discovered in the Linux kernel before 6.6.8. atalk_ioctl in net/appletalk/ddp.c has a use-after-free because of an atalk_recvmsg race condition. txtify archive
CVE-2024-57926 drm/mediatek: Set private->all_drm_private[i]->drm to NULL if mtk_drm_bind returns err txtify archive
CVE-2024-57259 sqfs_search_dir in Das U-Boot before 2025.01-rc1 exhibits an off-by-one error and resultant heap memory corruption for squashfs directory listing because the path separator is not considered in a size calculation. txtify archive
CVE-2025-23140 misc: pci_endpoint_test: Avoid issue of interrupts remaining after request_irq error txtify archive
CVE-2025-61099 FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the opaque_info_detail function at ospf_opaque.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted LS Update packet. txtify archive
CVE-2023-51782 An issue was discovered in the Linux kernel before 6.6.8. rose_ioctl in net/rose/af_rose.c has a use-after-free because of a rose_accept race condition. txtify archive
CVE-2024-12705 DNS-over-HTTPS implementation suffers from multiple issues under heavy query load txtify archive
CVE-2024-3096 PHP function password_verify can erroneously return true when argument contains NUL txtify archive
CVE-2025-61104 FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_unknown_tlv function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet. txtify archive
CVE-2021-28216 BootPerformanceTable pointer is read from an NVRAM variable in PEI. Recommend setting PcdFirmwarePerformanceDataTableS3Support to FALSE. txtify archive
CVE-2023-45287 Before Go 1.20, the RSA based key exchange methods in crypto/tls may exhibit a timing side channel txtify archive
CVE-2022-46392 An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. An adversary with access to precise enough information about memory accesses (typically an untrusted operating system attacking a secure enclave) can recover an RSA private key after observing the victim performing a single private-key operation if the window size (MBEDTLS_MPI_WINDOW_SIZE) used for the exponentiation is 3 or smaller. txtify archive
CVE-2025-38219 f2fs: prevent kernel warning due to negative i_nlink from corrupted image txtify archive
CVE-2025-61100 FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the ospf_opaque_lsa_dump function at ospf_opaque.c. This vulnerability allows attackers to cause a Denial of Service (DoS) under specific malformed LSA conditions. txtify archive
CVE-2024-57255 An integer overflow in sqfs_resolve_symlink in Das U-Boot before 2025.01-rc1 occurs via a crafted squashfs filesystem with an inode size of 0xffffffff, resulting in a malloc of zero and resultant memory overwrite. txtify archive
CVE-2025-61101 FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_rmt_itf_addr function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet. txtify archive
CVE-2024-50602 An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser. txtify archive
CVE-2025-69277 libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group. txtify archive
CVE-2025-23141 KVM: x86: Acquire SRCU in KVM_GET_MP_STATE to protect guest memory accesses txtify archive
CVE-2023-3341 A stack exhaustion flaw in control channel code may cause named to terminate unexpectedly txtify archive
CVE-2020-36422 An issue was discovered in Arm Mbed TLS before 2.23.0. A side channel allows recovery of an ECC private key, related to mbedtls_ecp_check_pub_priv, mbedtls_pk_parse_key, mbedtls_pk_parse_keyfile, mbedtls_ecp_mul, and mbedtls_ecp_mul_restartable. txtify archive
CVE-2024-31584 Pytorch before v2.2.0 has an Out-of-bounds Read vulnerability via the component torch/csrc/jit/mobile/flatbuffer_loader.cpp. txtify archive
CVE-2020-13630 ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow related to the snippet feature. txtify archive
CVE-2023-45284 Incorrect detection of reserved device names on Windows in path/filepath txtify archive
CVE-2023-6337 Vault May be Vulnerable to a Denial of Service Through Memory Exhaustion When Handling Large HTTP Requests txtify archive
CVE-2025-58160 Tracing logging user input may result in poisoning logs with ANSI escape sequences txtify archive
CVE-2025-23084 A vulnerability has been identified in Node.js, specifically affecting the handling of drive names in the Windows environment. Certain Node.js functions do not treat drive names as special on Windows. As a result, although Node.js assumes a relative path, it actually refers to the root directory. On Windows, a path that does not start with the file separator is treated as relative to the current directory. This vulnerability affects Windows users of `path.join` API. txtify archive
CVE-2021-44732 Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure. txtify archive
CVE-2023-42363 A use-after-free vulnerability was discovered in xasprintf function in xfuncs_printf.c:344 in BusyBox v.1.36.1. txtify archive
CVE-2024-3177 Bypassing mountable secrets policy imposed by the ServiceAccount admission plugin txtify archive
CVE-2023-4580 Push notifications stored on disk in private browsing mode were not being encrypted potentially allowing the leak of sensitive information. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2. txtify archive
CVE-2020-36425 An issue was discovered in Arm Mbed TLS before 2.24.0. It incorrectly uses a revocationDate check when deciding whether to honor certificate revocation via a CRL. In some situations, an attacker can exploit this by changing the local clock. txtify archive
CVE-2022-3650 A privilege escalation flaw was found in Ceph. Ceph-crash.service allows a local attacker to escalate privileges to root in the form of a crash dump and dump privileged information. txtify archive
CVE-2022-30767 nfs_lookup_reply in net/nfs.c in Das U-Boot through 2022.04 (and through 2022.07-rc2) has an unbounded memcpy with a failed length check, leading to a buffer overflow. NOTE: this issue exists because of an incorrect fix for CVE-2019-14196. txtify archive
CVE-2025-37739 f2fs: fix to avoid out-of-bounds access in f2fs_truncate_inode_blocks() txtify archive
CVE-2025-38183 net: lan743x: fix potential out-of-bounds write in lan743x_ptp_io_event_clock_get() txtify archive
CVE-2023-0664 A flaw was found in the QEMU Guest Agent service for Windows. A local unprivileged user may be able to manipulate the QEMU Guest Agent's Windows installer via repair custom actions to elevate their privileges on the system. txtify archive
CVE-2025-38231 nfsd: Initialize ssc before laundromat_work to prevent NULL dereference txtify archive
CVE-2024-57254 An integer overflow in sqfs_inode_size in Das U-Boot before 2025.01-rc1 occurs in the symlink size calculation via a crafted squashfs filesystem. txtify archive
CVE-2024-0752 A use-after-free crash could have occurred on macOS if a Firefox update were being applied on a very busy system. This could have resulted in an exploitable crash. This vulnerability affects Firefox < 122. txtify archive
CVE-2025-61105 FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_link_info function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet. txtify archive
CVE-2024-27316 Apache HTTP Server: HTTP/2 DoS by memory exhaustion on endless continuation frames txtify archive
CVE-2022-25881 This affects versions of the package http-cache-semantics before 4.1.1. The issue can be exploited via malicious request header values sent to a server when that server reads the cache policy from the request using this library. txtify archive
CVE-2024-39495 greybus: Fix use-after-free bug in gb_interface_release due to race condition. txtify archive
CVE-2025-61102 FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_adj_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet. txtify archive
CVE-2022-34835 In Das U-Boot through 2022.07-rc5, an integer signedness error and resultant stack-based buffer overflow in the "i2c md" command enables the corruption of the return address pointer of the do_i2c_md function. txtify archive
CVE-2024-31744 In Jasper 4.2.2 the jpc_streamlist_remove function in src/libjasper/jpc/jpc_dec.c:2407 has an assertion failure vulnerability allowing attackers to cause a denial of service attack through a specific image file. txtify archive
CVE-2023-29404 Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go txtify archive
CVE-2024-45336 Sensitive headers incorrectly sent after cross-domain redirect in net/http txtify archive
CVE-2025-37787 net: dsa: mv88e6xxx: avoid unregistering devlink regions which were never registered txtify archive
CVE-2022-25883 Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range when untrusted user data is provided as a range. txtify archive
CVE-2025-61107 FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted LSA Update packet. txtify archive
CVE-2024-1737 BIND's database will be slow if a very large number of RRs exist at the same name txtify archive
CVE-2019-14204 An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: nfs_umountall_reply. txtify archive
CVE-2025-61106 FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet. txtify archive
CVE-2023-28321 An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patterns when listed as "Subject Alternative Name" in TLS server certificates. curl can be built to use its own name matching function for TLS rather than one provided by a TLS library. This private wildcard matching function would match IDN (International Domain Name) hosts incorrectly and could as a result accept patterns that otherwise should mismatch. IDN hostnames are converted to puny code before used for certificate checks. Puny coded names always start with `xn--` and should not be allowed to pattern match but the wildcard check in curl could still check for `x*` which would match even though the IDN name most likely contained nothing even resembling an `x`. txtify archive
CVE-2017-7718 hw/display/cirrus_vga_rop.h in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) via vectors related to copying VGA data via the cirrus_bitblt_rop_fwd_transp_ and cirrus_bitblt_rop_fwd_ functions. txtify archive
CVE-2024-49894 drm/amd/display: Fix index out of bounds in degamma hardware format translation txtify archive
CVE-2025-61103 FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_lan_adj_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet. txtify archive
CVE-2023-29932 llvm-project commit fdbc55a5 was discovered to contain a segmentation fault via the component mlir::IROperand<mlir::OpOperand. txtify archive
CVE-2024-45026 s390/dasd: fix error recovery leading to data corruption on ESE devices txtify archive
CVE-2019-14196 An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with a failed length check at nfs_lookup_reply. txtify archive
CVE-2020-36476 An issue was discovered in Mbed TLS before 2.24.0 (and before 2.16.8 LTS and before 2.7.17 LTS). There is missing zeroization of plaintext buffers in mbedtls_ssl_read to erase unused application data from memory. txtify archive
CVE-2024-49867 btrfs: wait for fixup workers before stopping cleaner kthread during umount txtify archive
CVE-2022-49043 xmlXIncludeAddNode in xinclude.c in libxml2 before 2.11.0 has a use-after-free. txtify archive
CVE-2025-68724 crypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id txtify archive
CVE-2024-45015 drm/msm/dpu: move dpu_encoder's connector assignment to atomic_enable() txtify archive
CVE-2024-10846 Excessive Platform Resource Consumption within a Loop when unmarshalling Compose file having recursive loop txtify archive
CVE-2019-14202 An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: nfs_readlink_reply. txtify archive
CVE-2024-46674 usb: dwc3: st: fix probed platform device ref count on probe error path txtify archive
CVE-2025-0395 When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size. txtify archive
CVE-2024-4076 Assertion failure when serving both stale cache data and authoritative zone content txtify archive
CVE-2019-14195 An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with unvalidated length at nfs_readlink_reply in the "else" block after calculating the new path length. txtify archive
CVE-2023-24536 Excessive resource consumption in net/http, net/textproto and mime/multipart txtify archive
CVE-2022-2880 Incorrect sanitization of forwarded query parameters in net/http/httputil txtify archive
CVE-2024-31583 Pytorch before version v2.2.0 was discovered to contain a use-after-free vulnerability in torch/csrc/jit/mobile/interpreter.cpp. txtify archive
CVE-2025-3416 Rust-openssl: rust-openssl use-after-free in `md::fetch` and `cipher::fetch` txtify archive
CVE-2021-41772 Go before 1.16.10 and 1.17.x before 1.17.3 allows an archive/zip Reader.Open panic via a crafted ZIP archive containing an invalid name or an empty filename field. txtify archive
CVE-2024-49981 media: venus: fix use after free bug in venus_remove due to race condition txtify archive
CVE-2024-22653 yasm commit 9defefae was discovered to contain a NULL pointer dereference via the yasm_section_bcs_append function at section.c. txtify archive
CVE-2024-3817 HashiCorp go-getter Vulnerable to Argument Injection When Fetching Remote Default Git Branches txtify archive
CVE-2021-42836 GJSON before 1.9.3 allows a ReDoS (regular expression denial of service) attack. txtify archive
CVE-2024-11218 Podman: buildah: container breakout by using --jobs=2 and a race condition when building a malicious containerfile txtify archive
CVE-2025-49179 Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: integer overflow in x record extension txtify archive
CVE-2024-31580 PyTorch before v2.2.0 was discovered to contain a heap buffer overflow vulnerability in the component /runtime/vararg_functions.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input. txtify archive
CVE-2024-35790 usb: typec: altmodes/displayport: create sysfs nodes as driver's default device attribute group txtify archive
CVE-2025-49175 Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: out-of-bounds read in x rendering extension animated cursors txtify archive
CVE-2025-23090 Rejected reason: This CVE record has been withdrawn due to a duplicate entry CVE-2025-23083. txtify archive
CVE-2025-49176 Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: integer overflow in big requests extension txtify archive
CVE-2025-49178 Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: unprocessed client request due to bytes to ignore txtify archive
CVE-2024-32487 less through 653 allows OS command execution via a newline character in the name of a file because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment variable but this is set by default in many common cases. txtify archive
CVE-2024-21171 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.37 and prior and 8.4.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). txtify archive
CVE-2025-49180 Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: integer overflow in x resize, rotate and reflect (randr) extension txtify archive
CVE-2023-39318 Improper handling of HTML-like comments in script contexts in html/template txtify archive
CVE-2024-6608 It was possible to move the cursor using pointerlock from an iframe. This allowed moving the cursor outside of the viewport and the Firefox window. This vulnerability affects Firefox < 128 and Thunderbird < 128. txtify archive
CVE-2024-45590 body-parser vulnerable to denial of service when url encoding is enabled txtify archive
CVE-2024-9042 This CVE affects only Windows worker nodes. Your worker node is vulnerable to this issue if it is running one of the affected versions listed below. txtify archive
CVE-2019-14249 dwarf_elf_load_headers.c in libdwarf before 2019-07-05 allows attackers to cause a denial of service txtify archive
CVE-2020-28163 libdwarf before 20201201 allows a dwarf_print_lines.c NULL pointer dereference and application crash via a DWARF5 line-table header that has an invalid FORM for a pathname. txtify archive
CVE-2025-54566 hw/pci/pcie_sriov.c in QEMU through 10.0.3 has a migration state inconsistency, a related issue to CVE-2024-26327. txtify archive
CVE-2020-27545 libdwarf before 20201017 has a one-byte out-of-bounds read because of an invalid pointer dereference via an invalid line table in a crafted object. txtify archive
CVE-2022-27664 In net/http in Go before 1.18.6 and 1.19.x before 1.19.1 attackers can cause a denial of service because an HTTP/2 connection can hang during closing if shutdown were preempted by a fatal error. txtify archive
CVE-2024-6610 Form validation popups could capture escape key presses. Therefore, spamming form validation messages could be used to prevent users from exiting full-screen mode. This vulnerability affects Firefox < 128 and Thunderbird < 128. txtify archive
CVE-2025-54567 hw/pci/pcie_sriov.c in QEMU through 10.0.3 mishandles the VF Enable bit write mask, a related issue to CVE-2024-26327. txtify archive
CVE-2016-8681 The _dwarf_get_abbrev_for_code function in dwarf_util.c in libdwarf 20161001 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) by calling the dwarfdump command on a crafted file. txtify archive
CVE-2024-26596 net: dsa: fix netdev_priv() dereference before check on non-DSA netdevice events txtify archive
CVE-2023-51257 An invalid memory write issue in Jasper-Software Jasper v.4.1.1 and before allows a local attacker to execute arbitrary code. txtify archive
CVE-2023-52576 x86/mm, kexec, ima: Use memblock_free_late() from ima_free_kexec_buffer() txtify archive
CVE-2024-35195 Requests `Session` object does not verify requests after making first request with verify=False txtify archive
CVE-2022-2995 Incorrect handling of the supplementary groups in the CRI-O container engine might lead to sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container. txtify archive
CVE-2025-54090 Apache HTTP Server: 'RewriteCond expr' always evaluates to true in 2.4.64 txtify archive
CVE-2025-50181 urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation txtify archive
CVE-2025-23266 NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, information disclosure, and denial of service. txtify archive
CVE-2024-47702 bpf: Fail verification for sign-extension of packet data/data_end/data_meta txtify archive
CVE-2022-27651 A flaw was found in buildah where containers were incorrectly started with non-empty default permissions. A bug was found in Moby (Docker Engine) where containers were incorrectly started with non-empty inheritable Linux process capabilities enabling an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs. This has the potential to impact confidentiality and integrity. txtify archive
CVE-2022-48303 GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump txtify archive
CVE-2024-26648 drm/amd/display: Fix variable deferencing before NULL check in edp_setup_replay() txtify archive
CVE-2025-38215 fbdev: Fix do_register_framebuffer to prevent null-ptr-deref in fb_videomode_to_var txtify archive
CVE-2025-21951 bus: mhi: host: pci_generic: Use pci_try_reset_function() to avoid deadlock txtify archive
CVE-2022-46175 JSON5 is an extension to the popular JSON file format that aims to be easier to write and maintain by hand (e.g. for config files). The `parse` method of the JSON5 library before and including versions 1.0.1 and 2.2.1 does not restrict parsing of keys named `__proto__` allowing specially crafted strings to pollute the prototype of the resulting object. This vulnerability pollutes the prototype of the object returned by `JSON5.parse` and not the global Object prototype which is the commonly understood definition of Prototype Pollution. However polluting the prototype of a single object can have significant security impact for an application if the object is later used in trusted operations. This vulnerability could allow an attacker to set arbitrary and unexpected keys on the object returned from `JSON5.parse`. The actual impact will depend on how applications utilize the returned object and how they filter unwanted keys but could include denial of service cross-site scripting elevation txtify archive
CVE-2021-3636 It was found in OpenShift before version 4.8 that the generated certificate for the in-cluster Service CA incorrectly included additional certificates. The Service CA is automatically mounted into all pods allowing them to safely connect to trusted in-cluster services that present certificates signed by the trusted Service CA. The incorrect inclusion of additional CAs in this certificate would allow an attacker that compromises any of the additional CAs to masquerade as a trusted in-cluster service. txtify archive
CVE-2025-3360 Glibc: glib prior to 2.82.5 is vulnerable to integer overflow and buffer under-read when parsing a very long invalid iso 8601 timestamp with g_date_time_new_from_iso8601(). txtify archive
CVE-2025-40914 Perl CryptX before version 0.087 contains a dependency that may be susceptible to an integer overflow txtify archive
CVE-2022-27649 A flaw was found in Podman where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs. txtify archive
CVE-2024-6603 In an out-of-memory scenario an allocation could fail but free would have been called on the pointer afterwards leading to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128. txtify archive
CVE-2025-39711 media: ivsc: Fix crash at shutdown due to missing mei_cldev_disable() calls txtify archive
CVE-2024-4778 Memory safety bugs present in Firefox 125. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 126. txtify archive
CVE-2024-57896 btrfs: flush delalloc workers queue before stopping cleaner kthread during unmount txtify archive
CVE-2024-28085 wall in util-linux through 2.40 often installed with setgid tty permissions allows escape sequences to be sent to other users' terminals through argv. (Specifically escape sequences received from stdin are blocked but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover. txtify archive
CVE-2021-3602 An information disclosure flaw was found in Buildah when building containers using chroot isolation. Running processes in container builds (e.g. Dockerfile RUN commands) can access environment variables from parent and grandparent processes. When run in a container in a CI/CD environment environment variables may include sensitive information that was shared with the container in order to be used only by Buildah itself (e.g. container registry credentials). txtify archive
CVE-2025-68345 ALSA: hda: cs35l41: Fix NULL pointer dereference in cs35l41_hda_read_acpi() txtify archive
CVE-2024-6612 CSP violations generated links in the console tab of the developer tools, pointing to the violating resource. This caused a DNS prefetch which leaked that a CSP violation happened. This vulnerability affects Firefox < 128 and Thunderbird < 128. txtify archive
CVE-2023-42821 github.com/gomarkdown/markdown Out-of-bounds Read while parsing citations txtify archive
CVE-2025-68362 wifi: rtl818x: rtl8187: Fix potential buffer underflow in rtl8187_rx_cb() txtify archive
CVE-2025-6021 Libxml2: integer overflow in xmlbuildqname() leads to stack buffer overflow in libxml2 txtify archive
CVE-2025-7394 In the OpenSSL compatibility layer implementation, the function RAND_poll() was not behaving as expected and leading to the potential for predictable values returned from RAND_bytes() after fork() is called. This can lead to weak or predictable random numbers generated in applications that are both using RAND_bytes() and doing fork() operations. This only affects applications explicitly calling RAND_bytes() after fork() and does not affect any internal TLS operations. Although RAND_bytes() documentation in OpenSSL calls out not being safe for use with fork() without first calling RAND_poll(), an additional code change was also made in wolfSSL to make RAND_bytes() behave similar to OpenSSL after a fork() call without calling RAND_poll(). Now the Hash-DRBG used gets reseeded after detecting running in a new process. If making use of RAND_bytes() and calling fork() we recommend updating to the latest version of wolfSSL. Thanks to Per Allansson from Appgate for the report. txtify archive
CVE-2023-47100 In Perl before 5.38.2, S_parse_uniprop_string in regcomp.c can write to unallocated space because a property name associated with a \p{...} regular expression construct is mishandled. The earliest affected version is 5.30.0. txtify archive
CVE-2025-68354 regulator: core: Protect regulator_supply_alias_list with regulator_list_mutex txtify archive
CVE-2023-31486 HTTP::Tiny before 0.083 a Perl core module since 5.13.9 and available standalone on CPAN has an insecure default TLS configuration where users must opt in to verify certificates. txtify archive
CVE-2025-38352 posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() txtify archive
CVE-2023-51780 An issue was discovered in the Linux kernel before 6.6.8. do_vcc_ioctl in net/atm/ioctl.c has a use-after-free because of a vcc_recvmsg race condition. txtify archive
CVE-2025-68349 NFSv4/pNFS: Clear NFS_INO_LAYOUTCOMMIT in pnfs_mark_layout_stateid_invalid txtify archive
CVE-2025-58186 Lack of limit when parsing cookies can cause memory exhaustion in net/http txtify archive
CVE-2025-21490 Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H). txtify archive
CVE-2019-16276 Go before 1.12.10 and 1.13.x before 1.13.1 allow HTTP Request Smuggling. txtify archive
CVE-2022-35409 An issue was discovered in Mbed TLS before 2.28.1 and 3.x before 3.2.0. In some configurations, an unauthenticated attacker can send an invalid ClientHello message to a DTLS server that causes a heap-based buffer over-read of up to 255 bytes. This can cause a server crash or possibly information disclosure based on error responses. Affected configurations have MBEDTLS_SSL_DTLS_CLIENT_PORT_REUSE enabled and MBEDTLS_SSL_IN_CONTENT_LEN less than a threshold that depends on the configuration: 258 bytes if using mbedtls_ssl_cookie_check, and possibly up to 571 bytes with a custom cookie check function. txtify archive
CVE-2023-31484 CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS. txtify archive
CVE-2021-33198 In Go before 1.15.13 and 1.16.x before 1.16.5 there can be a panic for a large exponent to the math/big.Rat SetString or UnmarshalText method. txtify archive
CVE-2024-28863 node-tar vulnerable to denial of service while parsing a tar file due to lack of folders count validation txtify archive
CVE-2025-40913 Net::Dropbear versions through 0.16 for Perl contains a dependency that may be susceptible to an integer overflow txtify archive
CVE-2019-16910 Arm Mbed TLS before 2.19.0 and Arm Mbed Crypto before 2.0.0, when deterministic ECDSA is enabled, use an RNG with insufficient entropy for blinding, which might allow an attacker to recover a private key via side-channel attacks if a victim signs the same message many times. (For Mbed TLS, the fix is also available in versions 2.7.12 and 2.16.3.) txtify archive
CVE-2018-10906 In fuse before versions 2.9.8 and 3.x before 3.2.5 fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root users to mount a FUSE file system with the 'allow_other' mount option regardless of whether 'user_allow_other' is set in the fuse configuration. An attacker may use this flaw to mount a FUSE file system accessible by other users and trick them into accessing files on that file system possibly causing Denial of Service or other unspecified effects. txtify archive
CVE-2020-25576 An issue was discovered in the rand_core crate before 0.4.2 for Rust. Casting of byte slices to integer slices mishandles alignment constraints. txtify archive
CVE-2025-38213 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. txtify archive
CVE-2024-30261 Undici's fetch with integrity option is too lax when algorithm is specified but hash value is in incorrect txtify archive
CVE-2025-32386 Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination txtify archive
CVE-2025-53605 The protobuf crate before 3.7.2 for Rust allows uncontrolled recursion in the protobuf::coded_input_stream::CodedInputStream::skip_group parsing of unknown fields in untrusted input. txtify archive
CVE-2023-41361 An issue was discovered in FRRouting FRR 9.0. bgpd/bgp_open.c does not check for an overly large length of the rcv software version. txtify archive
CVE-2025-2784 Libsoup: heap buffer over-read in `skip_insignificant_space` when sniffing content txtify archive
CVE-2024-40647 Unintentional exposure of environment variables to subprocesses in sentry-sdk txtify archive
CVE-2023-46752 An issue was discovered in FRRouting FRR through 9.0.1. It mishandles malformed MP_REACH_NLRI data leading to a crash. txtify archive
CVE-2015-2158 Off-by-one error in the pngcrush_measure_idat function in pngcrush.c in pngcrush before 1.7.84 allows remote attackers to cause a denial of service txtify archive
CVE-2025-32053 Libsoup: heap buffer overflows in sniff_feed_or_html() and skip_insignificant_space() txtify archive
CVE-2023-47235 An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when a malformed BGP UPDATE message with an EOR is processed because the presence of EOR does not lead to a treat-as-withdraw outcome. txtify archive
CVE-2022-2588 It was discovered that the cls_route filter implementation in the Linux kernel would not remove an old filter from the hashtable before freeing it if its handle had the value 0. txtify archive
CVE-2021-43666 A Denial of Service vulnerability exists in mbed TLS 3.0.0 and earlier in the mbedtls_pkcs12_derivation function when an input password's length is 0. txtify archive
CVE-2023-47234 An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when processing a crafted BGP UPDATE message with a MP_UNREACH_NLRI attribute and additional NLRI data (that lacks mandatory path attributes). txtify archive
CVE-2022-2586 It was discovered that a nft object or expression could reference a nft set on a different nft table leading to a use-after-free once that table was deleted. txtify archive
CVE-2024-47734 bonding: Fix unnecessary warnings and logs from bond_xdp_get_xmit_slave() txtify archive
CVE-2024-53213 net: usb: lan78xx: Fix double free issue with interrupt buffer allocation txtify archive
CVE-2023-46753 An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without mandatory attributes e.g. one with only an unknown transit attribute. txtify archive
CVE-2024-6611 A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This vulnerability affects Firefox < 128 and Thunderbird < 128. txtify archive
CVE-2024-49868 btrfs: fix a NULL pointer dereference when failed to start a new trasacntion txtify archive
CVE-2024-54680 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. txtify archive
CVE-2024-25177 LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an unsinking of IR_FSTORE for NULL metatable, which leads to Denial of Service (DoS). txtify archive
CVE-2018-14040 In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attributeIn Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute txtify archive
CVE-2024-32020 Cloning local Git repository by untrusted user allows the untrusted user to modify objects in the cloned repository at will txtify archive
CVE-2025-21991 x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less NUMA nodes txtify archive
CVE-2021-20286 A flaw was found in libnbd 1.7.3. An assertion failure in nbd_unlocked_opt_go in ilb/opt.c may lead to denial of service. txtify archive
CVE-2021-45707 An issue was discovered in the nix crate 0.16.0 and later before 0.20.2 0.21.x before 0.21.2 and 0.22.x before 0.22.2 for Rust. unistd::getgrouplist has an out-of-bounds write if a user is in more than 16 /etc/groups groups. txtify archive
CVE-2025-23016 FastCGI fcgi2 (aka fcgi) 2.x through 2.4.4 has an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c. txtify archive
CVE-2024-23722 In Fluent Bit 2.1.8 through 2.2.1 a NULL pointer dereference can be caused via an invalid HTTP payload with the content type of x-www-form-urlencoded. It crashes and does not restart. This could result in logs not being delivered properly. txtify archive
CVE-2019-11834 cJSON before 1.7.11 allows out-of-bounds access related to \x00 in a string literal. txtify archive
CVE-2022-34038 Etcd v3.5.4 allows remote attackers to cause a denial of service via function PageWriter.write in pagewriter.go. NOTE: the vendor's position is that this is not a vulnerability. txtify archive
CVE-2025-29087 In SQLite 3.44.0 through 3.49.0 before 3.49.1, the concat_ws() SQL function can cause memory to be written beyond the end of a malloc-allocated buffer. If the separator argument is attacker-controlled and has a large string (e.g., 2MB or more), an integer overflow occurs in calculating the size of the result buffer, and thus malloc may not allocate enough memory. txtify archive
CVE-2022-4415 A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpable kernel setting. txtify archive
CVE-2022-23772 Rat.SetString in math/big in Go before 1.16.14 and 1.17.x before 1.17.7 has an overflow that can lead to Uncontrolled Memory Consumption. txtify archive
CVE-2023-26159 Versions of the package follow-redirects before 1.15.4 are vulnerable to Improper Input Validation due to the improper handling of URLs by the url.parse() function. When new URL() throws an error it can be manipulated to misinterpret the hostname. An attacker could exploit this weakness to redirect traffic to a malicious site potentially leading to information disclosure phishing attacks or other security breaches. txtify archive
CVE-2021-32923 HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (specifically those within 1 second of their maximum TTL) which caused them to be incorrectly treated as non-expiring during subsequent use. Fixed in 1.5.9 1.6.5 and 1.7.2. txtify archive
CVE-2025-6199 Gdk-pixbuf: uninitialized memory disclosure in gdkpixbuf gif lzw decoder txtify archive
CVE-2019-11835 cJSON before 1.7.11 allows out-of-bounds access related to multiline comments. txtify archive
CVE-2025-7519 Polkit: xml policy file with a large number of nested elements may lead to out-of-bounds write txtify archive
CVE-2023-41913 strongSwan before 5.9.12 has a buffer overflow and possible unauthenticated remote code execution via a DH public value that exceeds the internal buffer in charon-tkm's DH proxy. The earliest affected version is 5.3.0. An attack can occur via a crafted IKE_SA_INIT message. txtify archive
CVE-2024-26987 mm/memory-failure: fix deadlock when hugetlb_optimize_vmemmap is enabled txtify archive
CVE-2024-47701 ext4: avoid OOB when system.data xattr changes underneath the filesystem txtify archive
CVE-2024-34459 An issue was discovered in xmllint (from libxml2) before 2.11.8 and 2.12.x before 2.12.7. Formatting error messages with xmllint --htmlout can result in a buffer over-read in xmlHTMLPrintFileContext in xmllint.c. txtify archive
CVE-2023-50711 `serde` deserialization for `FamStructWrapper` lacks bound checks that could potentially lead to out-of-bounds memory access txtify archive
CVE-2023-49992 Espeak-ng 1.52-dev was discovered to contain a Stack Buffer Overflow via the function RemoveEnding at dictionary.c. txtify archive
CVE-2025-68337 jbd2: avoid bug_on in jbd2_journal_get_create_access() when file system corrupted txtify archive
CVE-2024-56786 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. txtify archive
CVE-2024-30204 In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments. txtify archive
CVE-2025-32728 In sshd in OpenSSH before 10.0, the DisableForwarding directive does not adhere to the documentation stating that it disables X11 and agent forwarding. txtify archive
CVE-2024-36478 null_blk: fix null-ptr-dereference while configuring 'power' and 'submit_queues' txtify archive
CVE-2024-4773 When a network error occurred during page load, the prior content could have remained in view with a blank URL bar. This could have been used to obfuscate a spoofed web site. This vulnerability affects Firefox < 126. txtify archive
CVE-2023-49994 Espeak-ng 1.52-dev was discovered to contain a Floating Point Exception via the function PeaksToHarmspect at wavegen.c. txtify archive
CVE-2022-45639 OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m parameter. NOTE: third parties have disputed this because there is no analysis showing that the backtick command executes outside the context of the user account that entered the command line. txtify archive
CVE-2018-1000215 Dave Gamble cJSON version 1.7.6 and earlier contains a CWE-772 vulnerability in cJSON library that can result in Denial of Service txtify archive
CVE-2024-29039 Missing check in tpm2_checkquote allows attackers to misrepresent the TPM state txtify archive
CVE-2023-49991 Espeak-ng 1.52-dev was discovered to contain a Stack Buffer Underflow via the function CountVowelPosition at synthdata.c. txtify archive
CVE-2024-32021 Local Git clone may hardlink arbitrary user-readable files into the new repository's "objects/" directory txtify archive
CVE-2025-68114 Capstone doesn't check vsnprintf return in SStream_concat, allows stack buffer underflow and overflow txtify archive
CVE-2024-25178 LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an out-of-bounds read in the stack-overflow handler in lj_state.c. txtify archive
CVE-2025-21993 iscsi_ibft: Fix UBSAN shift-out-of-bounds warning in ibft_attr_show_nic() txtify archive
CVE-2007-6109 Stack-based buffer overflow in emacs allows user-assisted attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a large precision value in an integer format string specifier to the format function as demonstrated via a certain "emacs -batch -eval" command line. txtify archive
CVE-2024-4775 An iterator stop condition was missing when handling WASM code in the built-in profiler, potentially leading to invalid memory access and undefined behavior. *Note:* This issue only affects the application when the profiler is running. This vulnerability affects Firefox < 126. txtify archive
CVE-2025-38062 genirq/msi: Store the IOMMU IOVA directly in msi_desc instead of iommu_cookie txtify archive
CVE-2024-30260 Undici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch request stream pipeline txtify archive
CVE-2023-7104 SQLite SQLite3 make alltest sqlite3session.c sessionReadRecord heap-based overflow txtify archive
CVE-2024-4770 When saving a page to PDF, certain font styles could have led to a potential use-after-free crash. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11. txtify archive
CVE-2024-5642 Buffer overread when using an empty list with SSLContext.set_npn_protocols() txtify archive
CVE-2022-28737 There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables txtify archive
CVE-2025-59529 simple protocol server ignores accepts unlimited connections and logs failures without limit txtify archive
CVE-2023-51764 Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_keywords=chunking (or certain other options that exist in recent versions). Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address allowing bypass of an SPF protection mechanism. This occurs because Postfix supports <LF>.<CR><LF> but some other popular e-mail servers do not. To prevent attack variants (by always disallowing <LF> without <CR>) a different solution is required such as the smtpd_forbid_bare_newline=yes option with a Postfix minimum version of 3.5.23 3.6.13 3.7.9 3.8.4 or 3.9. txtify archive
CVE-2024-25176 LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240626 have a stack-buffer-overflow in lj_strfmt_wfnum in lj_strfmt_num.c. txtify archive
CVE-2023-50966 erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header. txtify archive
CVE-2024-37371 In MIT Kerberos 5 (aka krb5) before 1.21.3 an attacker can cause invalid memory reads during GSS message token handling by sending message tokens with invalid length fields. txtify archive
CVE-2025-27363 An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary code execution. This vulnerability may have been exploited in the wild. txtify archive
CVE-2023-51714 An issue was discovered in the HTTP2 implementation in Qt before 5.15.17 6.x before 6.2.11 6.3.x through 6.5.x before 6.5.4 and 6.6.x before 6.6.2. network/access/http2/hpacktable.cpp has an incorrect HPack integer overflow check. txtify archive
CVE-2025-21941 drm/amd/display: Fix null check for pipe_ctx->plane_state in resource_build_scaling_params txtify archive
CVE-2024-31852 LLVM before 18.1.3 generates code in which the LR register can be overwritten without data being saved to the stack and thus there can sometimes be an exploitable error in the flow of control. This affects the ARM backend and can be demonstrated with Clang. NOTE: the vendor perspective is "we don't have strong objections for a CVE to be created ... It does seem that the likelihood of this miscompile enabling an exploit remains very low because the miscompile resulting in this JOP gadget is such that the function is most likely to crash on most valid inputs to the function. So if this function is covered by any testing the miscompile is most likely to be discovered before the binary is shipped to production." txtify archive
CVE-2024-37370 In MIT Kerberos 5 (aka krb5) before 1.21.3 an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token causing the unwrapped token to appear truncated to the application. txtify archive
CVE-2025-38039 net/mlx5e: Avoid WARN_ON when configuring MQPRIO with HTB offload enabled txtify archive
CVE-2023-30589 The llhttp parser in the http module in Node v20.2.0 does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS). The CR character (without LF) is sufficient to delimit HTTP header fields in the llhttp parser. According to RFC7230 section 3 only the CRLF sequence should delimit each header-field. This impacts all Node.js active versions: v16 v18 and v20 txtify archive
CVE-2024-50061 i3c: master: cdns: Fix use after free vulnerability in cdns_i3c_master Driver Due to Race Condition txtify archive
CVE-2022-34169 Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets txtify archive
CVE-2025-27152 Possible SSRF and Credential Leakage via Absolute URL in axios Requests txtify archive
CVE-2024-6257 HashiCorp go-getter Vulnerable to Code Execution On Git Update Via Git Config Manipulation txtify archive
CVE-2021-46023 An Untrusted Pointer Dereference was discovered in function mrb_vm_exec in mruby before 3.1.0-rc. The vulnerability causes a segmentation fault and application crash. txtify archive
CVE-2025-38136 usb: renesas_usbhs: Reorder clock handling and power management in probe txtify archive
CVE-2023-5115 Ansible: malicious role archive can cause ansible-galaxy to overwrite arbitrary files txtify archive
CVE-2023-52971 MariaDB Server 10.10 through 10.11.* and 11.0 through 11.4.* crashes in JOIN::fix_all_splittings_in_plan. txtify archive
CVE-2021-38190 An issue was discovered in the nalgebra crate before 0.27.1 for Rust. It allows out-of-bounds memory access because it does not ensure that the number of elements is equal to the product of the row count and column count. txtify archive
CVE-2022-35256 The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling. txtify archive
CVE-2023-52284 Bytecode Alliance wasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) before 1.3.0 can have an "double free or corruption" error for a valid WebAssembly module because push_pop_frame_ref_offset is mishandled. txtify archive
CVE-2021-33195 Go before 1.15.13 and 1.16.x before 1.16.5 has functions for DNS lookups that do not validate replies from DNS servers and thus a return value may contain an unsafe injection (e.g. XSS) that does not conform to the RFC1035 format. txtify archive
CVE-2023-52733 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. txtify archive
CVE-2025-37804 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. txtify archive
CVE-2023-7008 Systemd-resolved: unsigned name response in signed zone is not refused when dnssec=yes txtify archive
CVE-2025-12058 Vulnerability in Keras Model.load_model Leading to Arbitrary Local File Loading and SSRF txtify archive
CVE-2025-21887 ovl: fix UAF in ovl_dentry_update_reval by moving dput() in ovl_link_up txtify archive
CVE-2025-38042 dmaengine: ti: k3-udma-glue: Drop skip_fdq argument from k3_udma_glue_reset_rx_chn txtify archive
CVE-2024-41184 In the vrrp_ipsets_handler handler (fglobal_parser.c) of keepalived through 2.3.1 an integer overflow can occur. NOTE: this CVE Record might not be worthwhile because an empty ipset name must be configured by the user. txtify archive
CVE-2023-34411 The xml-rs crate before 0.8.14 for Rust and Crab allows a denial of service (panic) via an invalid <! token (such as <!DOCTYPEs/%<!A nesting) in an XML document. The earliest affected version is 0.8.9. txtify archive
CVE-2025-53906 Vim has path traversal issue with zip.vim and special crafted zip archives txtify archive
CVE-2022-26691 A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina macOS Monterey 12.3 macOS Big Sur 11.6.5. An application may be able to gain elevated privileges. txtify archive
CVE-2023-0778 A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal file in a volume with a symlink while exporting the volume, allowing for access to arbitrary files on the host file system. txtify archive
CVE-2024-40725 Apache HTTP Server: source code disclosure with handlers configured via AddType txtify archive
CVE-2016-3959 The Verify function in crypto/dsa/dsa.go in Go before 1.5.4 and 1.6.x before 1.6.1 does not properly check parameters passed to the big integer library, which might allow remote attackers to cause a denial of service (infinite loop) via a crafted public key to a program that uses HTTPS client certificates or SSH server libraries. txtify archive
CVE-2022-31394 Hyperium Hyper before 0.14.19 does not allow for customization of the max_header_list_size method in the H2 third-party software allowing attackers to perform HTTP2 attacks. txtify archive
CVE-2024-12905 An Improper Link Resolution Before File Access ("Link Following") and Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal"). This vulnerability occurs when extracting a maliciously crafted tar file, which can result in unauthorized file writes or overwrites outside the intended extraction directory. The issue is associated with index.js in the tar-fs package. This issue affects tar-fs: from 0.0.0 before 1.16.4, from 2.0.0 before 2.1.2, from 3.0.0 before 3.0.8. txtify archive
CVE-2025-53905 Vim has path traversial issue with tar.vim and special crafted tar files txtify archive
CVE-2022-1708 A vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyone with access to the Kube API. The ExecSync request runs commands in a container and logs the output of the command. This output is then read by CRI-O after command execution and it is read in a manner where the entire file corresponding to the output of the command is read in. Thus if the output of the command is large it is possible to exhaust the memory or the disk space of the node when CRI-O reads the output of the command. The highest threat from this vulnerability is system availability. txtify archive
CVE-2019-19317 lookupName in resolve.c in SQLite 3.30.1 omits bits from the colUsed bitmask in the case of a generated column, which allows attackers to cause a denial of service or possibly have unspecified other impact. txtify archive
CVE-2022-0811 A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Kubernetes cluster that uses the CRI-O runtime to achieve a container escape and arbitrary code execution as root on the cluster node, where the malicious pod was deployed. txtify archive
CVE-2024-49895 drm/amd/display: Fix index out of bounds in DCN30 degamma hardware format translation txtify archive
CVE-2023-42467 QEMU through 8.0.0 could trigger a division by zero in scsi_disk_reset in hw/scsi/scsi-disk.c because scsi_disk_emulate_mode_select does not prevent s->qdev.blocksize from being 256. This stops QEMU and the guest immediately. txtify archive
CVE-2024-57978 media: imx-jpeg: Fix potential error pointer dereference in detach_pm() txtify archive
CVE-2023-3354 Improper i/o watch removal in tls handshake can lead to remote unauthenticated denial of service txtify archive
CVE-2025-37976 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. txtify archive
CVE-2019-19076 A memory leak in the nfp_abm_u32_knode_replace() function in drivers/net/ethernet/netronome/nfp/abm/cls.c in the Linux kernel before 5.3.6 allows attackers to cause a denial of service (memory consumption) aka CID-78beef629fd9. NOTE: This has been argued as not a valid vulnerability. The upstream commit 78beef629fd9 was reverted txtify archive
CVE-2019-19926 multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsing, as demonstrated by errors from sqlite3WindowRewrite() calls. NOTE: this vulnerability exists because of an incomplete fix for CVE-2019-19880. txtify archive
CVE-2024-48615 Null Pointer Dereference vulnerability in libarchive 3.7.6 and earlier when running program bsdtar in function header_pax_extension at rchive_read_support_format_tar.c:1844:8. txtify archive
CVE-2014-10402 An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute in the data source name (DSN). NOTE: this issue exists because of an incomplete fix for CVE-2014-10401. txtify archive
CVE-2024-44952 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. txtify archive
CVE-2025-50078 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and 9.0.0-9.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). txtify archive
CVE-2014-8991 pip 1.3 through 1.5.6 allows local users to cause a denial of service (prevention of package installation) by creating a /tmp/pip-build-* file for another user. txtify archive
CVE-2025-1734 Streams HTTP wrapper does not fail for headers with invalid name and no colon txtify archive
CVE-2025-50091 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and 9.0.0-9.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H). txtify archive
CVE-2024-25580 An issue was discovered in gui/util/qktxhandler.cpp in Qt before 5.15.17 6.x before 6.2.12 6.3.x through 6.5.x before 6.5.5 and 6.6.x before 6.6.2. A buffer overflow and application crash can occur via a crafted KTX image file. txtify archive
CVE-2021-43565 The x/crypto/ssh package before 0.0.0-20211202192323-5770296d904e of golang.org/x/crypto allows an attacker to panic an SSH server. txtify archive
CVE-2024-29018 External DNS requests from 'internal' networks could lead to data exfiltration txtify archive
CVE-2024-56606 af_packet: avoid erroring out after sock_init_data() in packet_create() txtify archive
CVE-2025-50097 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and 9.0.0-9.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H). txtify archive
CVE-2024-1013 Unixodbc: out of bounds stack write due to pointer-to-integer types conversion txtify archive
CVE-2025-1219 libxml streams use wrong content-type header when requesting a redirected resource txtify archive
CVE-2024-44997 net: ethernet: mtk_wed: fix use-after-free panic in mtk_wed_setup_tc_block_cb() txtify archive
CVE-2024-39473 ASoC: SOF: ipc4-topology: Fix input format query of process modules without base extension txtify archive
CVE-2021-3611 A stack overflow vulnerability was found in the Intel HD Audio device (intel-hda) of QEMU. A malicious guest could use this flaw to crash the QEMU process on the host resulting in a denial of service condition. The highest threat from this vulnerability is to system availability. This flaw affects QEMU versions prior to 7.0.0. txtify archive
CVE-2021-20255 A stack overflow via an infinite recursion vulnerability was found in the eepro100 i8255x device emulator of QEMU. This issue occurs while processing controller commands due to a DMA reentry issue. This flaw allows a guest user or process to consume CPU cycles or crash the QEMU process on the host resulting in a denial of service. The highest threat from this vulnerability is to system availability. txtify archive
CVE-2025-2312 cifs.upcall makes an upcall to the wrong namespace in containerized environments txtify archive
CVE-2022-4899 A vulnerability was found in zstd v1.4.10 where an attacker can supply empty string as an argument to the command line tool to cause buffer overrun. txtify archive
CVE-2022-30594 The Linux kernel before 5.17.2 mishandles seccomp permissions. The PTRACE_SEIZE code path allows attackers to bypass intended restrictions on setting the PT_SUSPEND_SECCOMP flag. txtify archive
CVE-2024-47712 wifi: wilc1000: fix potential RCU dereference issue in wilc_parse_join_bss_param txtify archive
CVE-2023-27043 The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is identified as the value of the addr-spec. In some applications, an attacker can bypass a protection mechanism in which application access is granted only after verifying receipt of e-mail to a specific domain (e.g., only @company.example.com addresses may be used for signup). This occurs in email/_parseaddr.py in recent versions of Python. txtify archive
CVE-2023-6597 An issue was found in the CPython `tempfile.TemporaryDirectory` class affecting versions 3.12.1 3.11.7 3.10.13 3.9.18 and 3.8.18 and prior. The tempfile.TemporaryDirectory class would dereference symlinks during cleanup of permissions-related errors. This means users which can run privileged programs are potentially able to modify permissions of files referenced by symlinks in some circumstances. txtify archive
CVE-2023-39130 GNU gdb (GDB) 13.0.50.20220805-git was discovered to contain a heap buffer overflow via the function pe_as16() at /gdb/coff-pe-read.c. txtify archive
CVE-2025-21789 LoongArch: csum: Fix OoB access in IP checksum code for negative lengths txtify archive
CVE-2023-6507 Groups not dropped before running subprocess when using empty 'extra_groups' parameter txtify archive
CVE-2023-39129 GNU gdb (GDB) 13.0.50.20220805-git was discovered to contain a heap use after free via the function add_pe_exported_sym() at /gdb/coff-pe-read.c. txtify archive
CVE-2024-39476 md/raid5: fix deadlock that raid5d() wait for itself to clear MD_SB_CHANGE_PENDING txtify archive
CVE-2022-40898 An issue discovered in Python Packaging Authority (PyPA) Wheel 0.37.1 and earlier allows remote attackers to cause a denial of service via attacker controlled input to wheel cli. txtify archive
CVE-2023-52340 The IPv6 implementation in the Linux kernel before 6.3 has a net/ipv6/route.c max_size threshold that can be consumed easily e.g. leading to a denial of service (network is unreachable errors) when IPv6 packets are sent in a loop via a raw socket. txtify archive
CVE-2023-46136 Werkzeug vulnerable to high resource usage when parsing multipart/form-data containing a large part with CR/LF character at the beginning txtify archive
CVE-2023-25588 Field `the_bfd` of `asymbol` is uninitialized in function `bfd_mach_o_get_synthetic_symtab` txtify archive
CVE-2021-27291 In pygments 1.1+ fixed in 2.7.4 the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity and are vulnerable to ReDoS. By crafting malicious input an attacker can cause a denial of service. txtify archive
CVE-2024-21890 The Node.js Permission Model does not clarify in the documentation that wildcards should be only used as the last character of a file path. For example: ``` --allow-fs-read=/home/node/.ssh/*.pub ``` will ignore `pub` and give access to everything after `.ssh/`. This misleading documentation affects all users using the experimental permission model in Node.js 20 and Node.js 21. Please note that at the time this CVE was issued the permission model is an experimental feature of Node.js. txtify archive
CVE-2022-47673 An issue was discovered in Binutils addr2line before 2.39.3, function parse_module contains multiple out of bound reads which may cause a denial of service or other unspecified impacts. txtify archive
CVE-2021-20270 An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file as demonstrated by input that only contains the "exception" keyword. txtify archive
CVE-2021-45480 An issue was discovered in the Linux kernel before 5.15.11. There is a memory leak in the __rds_conn_create() function in net/rds/connection.c in a certain combination of circumstances. txtify archive
CVE-2025-38099 Bluetooth: Disable SCO support if READ_VOICE_SETTING is unsupported/broken txtify archive
CVE-2024-22025 A vulnerability in Node.js has been identified allowing for a Denial of Service (DoS) attack through resource exhaustion when using the fetch() function to retrieve content from an untrusted URL. The vulnerability stems from the fact that the fetch() function in Node.js always decodes Brotli making it possible for an attacker to cause resource exhaustion when fetching content from an untrusted URL. An attacker controlling the URL passed into fetch() can exploit this vulnerability to exhaust memory potentially leading to process termination depending on the system configuration. txtify archive
CVE-2022-47696 An issue was discovered Binutils objdump before 2.39.3 allows attackers to cause a denial of service or other unspecified impacts via function compare_symbols. txtify archive
CVE-2023-49083 cryptography vulnerable to NULL-dereference when loading PKCS7 certificates txtify archive
CVE-2025-38102 VMCI: fix race between vmci_host_setup_notify and vmci_ctx_unset_notify txtify archive
CVE-2022-28391 BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's value to a VT compatible terminal. Alternatively the attacker could choose to change the terminal's colors. txtify archive
CVE-2025-38098 drm/amd/display: Don't treat wb connector as physical in create_validate_stream_for_sink txtify archive
CVE-2025-50084 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and 9.0.0-9.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H). txtify archive
CVE-2023-39128 GNU gdb (GDB) 13.0.50.20220805-git was discovered to contain a stack overflow via the function ada_decode at /gdb/ada-lang.c. txtify archive
CVE-2023-25193 hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks. txtify archive
CVE-2023-5870 Postgresql: role pg_signal_backend can signal certain superuser processes. txtify archive
CVE-2024-45006 xhci: Fix Panther point NULL pointer deref at full-speed re-enumeration txtify archive
CVE-2024-39474 mm/vmalloc: fix vmalloc which may return null if called with __GFP_NOFAIL txtify archive
CVE-2010-4226 cpio, as used in build 2007.05.10, 2010.07.28, and possibly other versions, allows remote attackers to overwrite arbitrary files via a symlink within an RPM package archive. txtify archive
CVE-2025-38126 net: stmmac: make sure that ptp_rate is not 0 before configuring timestamping txtify archive
CVE-2025-53023 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). txtify archive
CVE-2025-27219 In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability. The method does not impose any limit on the length of the raw cookie value it processes. This oversight can lead to excessive resource consumption when parsing extremely large cookies. txtify archive
CVE-2023-44488 VP9 in libvpx before 1.13.1 mishandles widths leading to a crash related to encoding. txtify archive
CVE-2012-2677 Integer overflow in the ordered_malloc function in boost/pool/pool.hpp in Boost Pool txtify archive
CVE-2016-2781 chroot in GNU coreutils when used with --userspec allows local users to escape to the parent session via a crafted TIOCSTI ioctl call which pushes characters to the terminal's input buffer. txtify archive
CVE-2024-55553 In FRRouting (FRR) all routes are re-validated if the total size of an update received via RTR exceeds the internal socket's buffer size txtify archive
CVE-2024-22017 setuid() does not affect libuv's internal io_uring operations if initialized before the call to setuid(). This allows the process to perform privileged operations despite presumably having dropped such privileges through a call to setuid(). This vulnerability affects all users using version greater or equal than Node.js 18.18.0 Node.js 20.4.0 and Node.js 21. txtify archive
CVE-2024-45506 HAProxy 2.9.x before 2.9.10 3.0.x before 3.0.4 and 3.1.x through 3.1-dev6 allows a remote denial of service for HTTP/2 zero-copy forwarding (h2_send loop) under a certain set of conditions as exploited in the wild in 2024. txtify archive
CVE-2025-50102 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and 9.0.0-9.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H). txtify archive
CVE-2023-46218 This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains. It could do this by exploiting a mixed case flaw in curl's function that verifies a given cookie domain against the Public Suffix List (PSL). For example a cookie could be set with `domain=co.UK` when the URL used a lower case hostname `curl.co.uk` even though `co.uk` is listed as a PSL domain. txtify archive
CVE-2025-21614 go-git clients vulnerable to DoS via maliciously crafted Git server replies txtify archive
CVE-2024-49913 drm/amd/display: Add null check for top_pipe_to_program in commit_planes_for_stream txtify archive
CVE-2025-6170 Libxml2: stack buffer overflow in xmllint interactive shell command handling txtify archive
CVE-2024-52560 fs/ntfs3: Mark inode as bad as soon as error detected in mi_enum_attr() txtify archive
CVE-2022-47085 An issue was discovered in ostree before 2022.7 allows attackers to cause a denial of service or other unspecified impacts via the print_panic function in repo_checkout_filter.rs. txtify archive
CVE-2024-28757 libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate). txtify archive
CVE-2025-21779 KVM: x86: Reject Hyper-V's SEND_IPI hypercalls if local APIC isn't in-kernel txtify archive
CVE-2024-44971 net: dsa: bcm_sf2: Fix a possible memory leak in bcm_sf2_mdio_register() txtify archive
CVE-2025-32462 Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL txtify archive
CVE-2025-49809 mtr through 0.95, in certain privileged contexts, mishandles execution of a program specified by the MTR_PACKET environment variable. NOTE: mtr on macOS may often have Sudo rules, as an indirect consequence of Homebrew not installing setuid binaries. txtify archive
CVE-2023-51385 In ssh in OpenSSH before 9.6 OS command injection might occur if a user name or host name has shell metacharacters and this name is referenced by an expansion token in certain situations. For example an untrusted Git repository can have a submodule with shell metacharacters in a user name or host name. txtify archive
CVE-2025-21776 USB: hub: Ignore non-compliant devices with too many configs or interfaces txtify archive
CVE-2021-20197 There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar objcopy strip ranlib. When these utilities are run as a privileged user (presumably as part of a script updating binaries across different users) an unprivileged user can trick these utilities into getting ownership of arbitrary files through a symlink. txtify archive
CVE-2022-43551 A vulnerability exists in curl <7.87.0 HSTS check that could be bypassed to trick it to keep using HTTP. Using its HSTS support curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is provided in the URL. However the HSTS mechanism could be bypassed if the host name in the given URL first uses IDN characters that get replaced to ASCII counterparts as part of the IDN conversion. Like using the character UTF-8 U+3002 (IDEOGRAPHIC FULL STOP) instead of the common ASCII full stop (U+002E) `.`. Then in a subsequent request it does not detect the HSTS state and makes a clear text transfer. Because it would store the info IDN encoded but look for it IDN decoded. txtify archive
CVE-2023-51384 In ssh-agent in OpenSSH before 9.6 certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys these constraints are only applied to the first key even if a PKCS#11 token returns multiple keys. txtify archive
CVE-2007-2768 OpenSSH when using OPIE (One-Time Passwords in Everything) for PAM allows remote attackers to determine the existence of certain user accounts which displays a different response if the user account exists and is configured to use one-time passwords (OTP) a similar issue to CVE-2007-2243. txtify archive
CVE-2024-28180 Go JOSE vulnerable to Improper Handling of Highly Compressed Data (Data Amplification) txtify archive
CVE-2025-52496 Mbed TLS before 3.6.4 has a race condition in AESNI detection if certain compiler optimizations occur. An attacker may be able to extract an AES key from a multithreaded program, or perform a GCM forgery. txtify archive
CVE-2023-4535 Opensc: out-of-bounds read in myeid driver handling encryption using symmetric keys txtify archive
CVE-2024-39936 An issue was discovered in HTTP2 in Qt before 5.15.18 6.x before 6.2.13 6.3.x through 6.5.x before 6.5.7 and 6.6.x through 6.7.x before 6.7.3. Code to make security-relevant decisions about an established connection may execute too early because the encrypted() signal has not yet been emitted and processed.. txtify archive
CVE-2023-23914 A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using its HSTS support curl can be instructed to use HTTPS instead of usingan insecure clear-text HTTP step even when HTTP is provided in the URL. ThisHSTS mechanism would however surprisingly be ignored by subsequent transferswhen done on the same command line because the state would not be properlycarried on. txtify archive
CVE-2023-2977 A vulnerbility was found in OpenSC. This security flaw cause a buffer overrun vulnerability in pkcs15 cardos_have_verifyrc_package. The attacker can supply a smart card package with malformed ASN1 context. The cardos_have_verifyrc_package function scans the ASN1 buffer for 2 tags where remaining length is wrongly caculated due to moved starting pointer. This leads to possible heap-based buffer oob read. In cases where ASAN is enabled while compiling this causes a crash. Further info leak or more damage is possible. txtify archive
CVE-2023-27538 An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the configurations match. However two SSH settings were omitted from the configuration check allowing them to match easily potentially leading to the reuse of an inappropriate connection. txtify archive
CVE-2020-26160 jwt-go before 4.0.0-preview1 allows attackers to bypass intended access restrictions in situations with []string{} for m["aud"] (which is allowed by the specification). Because the type assertion fails "" is the value of aud. This is a security problem if the JWT token is presented to a service that lacks its own audience check. txtify archive
CVE-2023-41915 OpenPMIx PMIx before 4.2.6 and 5.0.x before 5.0.1 allows attackers to obtain ownership of arbitrary files via a race condition during execution of library code with UID 0. txtify archive
CVE-2021-32292 An issue was discovered in json-c from 20200420 (post 0.14 unreleased code) through 0.15-20200726. A stack-buffer-overflow exists in the auxiliary sample program json_parse which is located in the function parseit. txtify archive
CVE-2024-21896 The permission model protects itself against path traversal attacks by calling path.resolve() on any paths given by the user. If the path is to be treated as a Buffer the implementation uses Buffer.from() to obtain a Buffer from the result of path.resolve(). By monkey-patching Buffer internals namely Buffer.prototype.utf8Write the application can modify the result of path.resolve() which leads to a path traversal vulnerability. This vulnerability affects all users using the experimental permission model in Node.js 20 and Node.js 21. Please note that at the time this CVE was issued the permission model is an experimental feature of Node.js. txtify archive
CVE-2023-27535 An authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during subsequent transfers. Previously created connections are kept in a connection pool for reuse if they match the current setup. However certain FTP settings such as CURLOPT_FTP_ACCOUNT CURLOPT_FTP_ALTERNATIVE_TO_USER CURLOPT_FTP_SSL_CCC and CURLOPT_USE_SSL were not included in the configuration match checks causing them to match too easily. This could lead to libcurl using the wrong credentials when performing a transfer potentially allowing unauthorized access to sensitive information. txtify archive
CVE-2025-23048 Apache HTTP Server: mod_ssl access control bypass with session resumption txtify archive
CVE-2025-27220 In the CGI gem before 0.4.2 for Ruby, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the Util#escapeElement method. txtify archive
CVE-2024-21891 Node.js depends on multiple built-in utility functions to normalize paths provided to node:fs functions which can be overwitten with user-defined implementations leading to filesystem permission model bypass through path traversal attack. This vulnerability affects all users using the experimental permission model in Node.js 20 and Node.js 21. Please note that at the time this CVE was issued the permission model is an experimental feature of Node.js. txtify archive
CVE-2024-39884 Apache HTTP Server: source code disclosure with handlers configured via AddType txtify archive
CVE-2024-58052 drm/amdgpu: Fix potential NULL pointer dereference in atomctrl_get_smc_sclk_range_table txtify archive
CVE-2024-24758 Proxy-Authorization header not cleared on cross-origin redirect in fetch in Undici txtify archive
CVE-2024-56741 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. txtify archive
CVE-2024-39894 OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g. for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly other timing attacks against keystroke entry could occur. txtify archive
CVE-2020-24347 njs through 0.4.3, used in NGINX, has an out-of-bounds read in njs_lvlhsh_level_find in njs_lvlhsh.c. txtify archive
CVE-2023-38546 This flaw allows an attacker to insert cookies at will into a running program using libcurl if the specific series of conditions are met. libcurl performs transfers. In its API an application creates "easy handles" that are the individual handles for single transfers. libcurl provides a function call that duplicates en easy handle called [curl_easy_duphandle](https://curl.se/libcurl/c/curl_easy_duphandle.html). If a transfer has cookies enabled when the handle is duplicated the cookie-enable state is also cloned - but without cloning the actual cookies. If the source handle did not read any cookies from a specific file on disk the cloned version of the handle would instead store the file name as `none` (using the four ASCII letters no quotes). Subsequent use of the cloned handle that does not explicitly set a source to load cookies from would then inadvertently load cookies from a file named `none` - if such a file exists and is readable in the current directory of the program usin txtify archive
CVE-2023-50495 NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry(). txtify archive
CVE-2025-39732 wifi: ath11k: fix sleeping-in-atomic in ath11k_mac_op_set_bitrate_mask() txtify archive
CVE-2025-21700 net: sched: Disallow replacing of child qdisc from one parent to another txtify archive
CVE-2022-46456 NASM v2.16 was discovered to contain a global buffer overflow in the component dbgdbg_typevalue at /output/outdbg.c. txtify archive
CVE-2025-27221 In the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.join, URI#merge, URI#+) have an inadvertent leakage of authentication credentials because userinfo is retained even after changing the host. txtify archive
CVE-2022-24921 regexp.Compile in Go before 1.16.15 and 1.17.x before 1.17.8 allows stack exhaustion via a deeply nested expression. txtify archive
CVE-2025-48924 Apache Commons Lang, Apache Commons Lang: ClassUtils.getClass(...) can throw a StackOverflowError on very long inputs txtify archive
CVE-2023-27533 A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and "telnet options" during server negotiation. The lack of proper input scrubbing allows an attacker to send content or perform option negotiation without the application's intent. This vulnerability could be exploited if an application allows user input thereby enabling attackers to execute arbitrary code on the system. txtify archive
CVE-2016-9841 inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic txtify archive
CVE-2025-57052 cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c, allowing remote attackers to bypass array bounds checking and access restricted data via malformed JSON pointer strings containing alphanumeric characters. txtify archive
CVE-2024-2313 If kernel headers need to be extracted bpftrace will attempt to load them from a temporary directory. An unprivileged attacker could use this to force bcc to load compromised linux headers. Linux distributions which provide kernel headers by default are not affected by default. txtify archive
CVE-2023-27534 A path traversal vulnerability exists in curl <8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element in addition to its intended use as the first element to indicate a path relative to the user's home directory. Attackers can exploit this flaw to bypass filtering or execute arbitrary code by crafting a path like /~2/foo while accessing a server with a specific user. txtify archive
CVE-2025-5455 Possible denial of service when passing malformed data in a URL to qDecodeDataUrl txtify archive
CVE-2025-6491 NULL Pointer Dereference in PHP SOAP Extension via Large XML Namespace Prefix txtify archive
CVE-2025-21794 HID: hid-thrustmaster: fix stack-out-of-bounds read in usb_check_int_endpoints() txtify archive
CVE-2024-50059 ntb: ntb_hw_switchtec: Fix use after free vulnerability in switchtec_ntb_remove due to race condition txtify archive
CVE-2019-10638 In the Linux kernel before 5.1.7 a device can be tracked by an attacker using the IP ID values the kernel produces for connection-less protocols (e.g. UDP and ICMP). When such traffic is sent to multiple destination IP addresses it is possible to obtain hash collisions (of indices to the counter array) and thereby obtain the hashing key (via enumeration). An attack may be conducted by hosting a crafted web page that uses WebRTC or gQUIC to force UDP traffic to attacker-controlled IP addresses. txtify archive
CVE-2016-9840 inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic txtify archive
CVE-2023-27536 An authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect user permissions due to a failure to check for changes in the CURLOPT_GSSAPI_DELEGATION option. This vulnerability affects krb5/kerberos/negotiate/GSSAPI transfers and could potentially result in unauthorized access to sensitive information. The safest option is to not reuse connections if the CURLOPT_GSSAPI_DELEGATION option has been changed. txtify archive
CVE-2023-46853 In Memcached before 1.6.22 an off-by-one error exists when processing proxy requests in proxy mode if \n is used instead of \r\n. txtify archive
CVE-2024-11584 cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grants 0666 permissions, making it world-writable. This is used for the "/run/cloud-init/hook-hotplug-cmd" FIFO. An unprivileged user could trigger hotplug-hook commands. txtify archive
CVE-2023-46852 In Memcached before 1.6.22 a buffer overflow exists when processing multiget requests in proxy mode if there are many spaces after the "get" substring. txtify archive
CVE-2024-6174 When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration. txtify archive
CVE-2021-22918 Node.js before 16.4.1 14.17.2 12.22.2 is vulnerable to an out-of-bounds read when uv__idna_toascii() is used to convert strings to ASCII. The pointer p is read and increased without checking whether it is beyond pe with the latter holding a pointer to the end of the buffer. This can lead to information disclosures or crashes. This function can be triggered via uv_getaddrinfo(). txtify archive
CVE-2023-28938 Uncontrolled resource consumption in some Intel(R) SSD Tools software before version mdadm-4.2-rc2 may allow a priviledged user to potentially enable denial of service via local access. txtify archive
CVE-2023-28320 A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for resolving host names selected at build time. If it is built to use the synchronous resolver it allows name resolves to time-out slow operations using `alarm()` and `siglongjmp()`. When doing this libcurl used a global buffer that was not mutex protected and a multi-threaded application might therefore crash or otherwise misbehave. txtify archive
CVE-2023-28736 Buffer overflow in some Intel(R) SSD Tools software before version mdadm-4.2-rc2 may allow a privileged user to potentially enable escalation of privilege via local access. txtify archive
CVE-2022-23806 Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int value that is not a valid field element. txtify archive
CVE-2020-25657 A flaw was found in all released versions of m2crypto where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API via the timed processing of valid PKCS#1 v1.5 Ciphertext. The highest threat from this vulnerability is to confidentiality. txtify archive
CVE-2024-28110 Go SDK for CloudEvents's use of WithRoundTripper to create a Client leaks credentials txtify archive
CVE-2022-43552 A use after free vulnerability exists in curl <7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operations. When getting denied to tunnel the specific protocols SMB or TELNET curl would use a heap-allocated struct after it had been freed in its transfer shutdown code path. txtify archive
CVE-2016-9179 It was found that Lynx doesn't parse the authority component of the URL correctly txtify archive
CVE-1999-0817 Lynx WWW client allows a remote attacker to specify command-line parameters which Lynx uses when calling external programs to handle certain protocols, e.g. telnet. txtify archive
CVE-2025-4598 Systemd-coredump: race condition that allows a local attacker to crash a suid program and gain read access to the resulting core dump txtify archive
CVE-2025-25724 list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafted TAR archive that is read with a verbose value of 2. For example, the 100-byte buffer may not be sufficient for a custom locale. txtify archive
CVE-2022-33099 An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs. txtify archive
CVE-2025-21753 btrfs: fix use-after-free when attempting to join an aborted transaction txtify archive
CVE-2023-27537 A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks two threads sharing the same HSTS data could end up doing a double-free or use-after-free. txtify archive
CVE-2024-53156 wifi: ath9k: add range check for conn_rsp_epid in htc_connect_service() txtify archive
CVE-2021-40633 A memory leak (out-of-memory) in gif2rgb in util/gif2rgb.c in giflib 5.1.4 allows remote attackers trigger an out of memory exception or denial of service via a gif format file. txtify archive
CVE-2017-14867 Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to support subcommands such as cvsserver, which allows attackers to execute arbitrary OS commands via shell metacharacters in a module name. The vulnerable code is reachable via git-shell even without CVS support. txtify archive
CVE-2022-28805 singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code. txtify archive
CVE-2015-8472 Buffer overflow in libpng allows remote attackers to cause a denial of service txtify archive
CVE-2023-23916 An allocation of resources without limits or throttling vulnerability exists in curl <v7.88.0 based on the "chained" HTTP compression algorithms meaning that a server response can be compressed multiple times and potentially with differentalgorithms. The number of acceptable "links" in this "decompression chain" wascapped but the cap was implemented on a per-header basis allowing a maliciousserver to insert a virtually unlimited number of compression steps simply byusing many headers. The use of such a decompression chain could result in a "malloc bomb" making curl end up spending enormous amounts of allocated heap memory or trying to and returning out of memory errors. txtify archive
CVE-2023-45322 libxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory allocation fails. This occurs in xmlUnlinkNode in tree.c. NOTE: the vendor's position is "I don't think these issues are critical enough to warrant a CVE ID ... because an attacker typically can't control when memory allocations fail." txtify archive
CVE-2023-3750 Libvirt: improper locking in virstoragepoolobjlistsearch may lead to denial of service txtify archive
From BRICKSTORM to GRIMBOLT: UNC6201 Exploiting a Dell RecoverPoint for Virtual Machines Zero-Day txtify archive
Horror of Putin's nuclear bomb in space: Global leaders are so worried they've started manoeuvres against it. Now TOM LEONARD reveals how it would cripple the West... and that's just the start txtify archive
Is the party over for Thailand's playboy king? He made his poodle an air force chief, spent Covid in a hotel with 20 'sex soldiers' and threw a 'disloyal' mistress in jail… but has the death of his mother changed him? txtify archive
Inside Putin's horrific torture gulags where inmates are gassed in 'elephant masks', used as 'human furniture' and forced to endure 'Putin's phone' txtify archive
The End is Just the Beginning of Better Security: Enhanced Vulnerability Management with OpenEoX txtify archive
CISA Announces New Town Halls to Engage with Stakeholders on Cyber Incident Reporting for Critical Infrastructure txtify archive
GTIG AI Threat Tracker: Distillation, Experimentation, and (Continued) Integration of AI for Adversarial Use txtify archive
CISA’s 2025 Year in Review: Driving Security and Resilience Across Critical Infrastructure txtify archive
CISA Releases Guide to Help Critical Infrastructure Users Adopt More Secure Communication txtify archive
CVE-2026-21518 GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability txtify archive
CVE-2026-21234 Windows Connected Devices Platform Service Elevation of Privilege Vulnerability txtify archive
CVE-2026-21236 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-23655 Microsoft ACI Confidential Containers Information Disclosure Vulnerability txtify archive
CVE-2026-21523 GitHub Copilot and Visual Studio Code Remote Code Execution Vulnerability txtify archive
CVE-2026-21522 Microsoft ACI Confidential Containers Elevation of Privilege Vulnerability txtify archive
CVE-2026-21537 Microsoft Defender for Endpoint Linux Extension Remote Code Execution Vulnerability txtify archive
CVE-2026-21525 Windows Remote Access Connection Manager Denial of Service Vulnerability txtify archive
CVE-2026-21243 Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability txtify archive
CVE-2026-21241 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2026-21238 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability txtify archive
CVE-2025-2884 Cert CC: CVE-2025-2884 Out-of-Bounds read vulnerability in TCG TPM2.0 reference implementation txtify archive
UNC1069 Targets Cryptocurrency Sector with New Tooling and AI-Enabled Social Engineering txtify archive
CISA Orders Federal Agencies to Strengthen Edge Device Security Amid Rising Cyber Threats txtify archive
Guidance from the Frontlines: Proactive Defense Against ShinyHunters-Branded Data Theft Targeting SaaS txtify archive
CISA Urges Critical Infrastructure Organizations to Take Action Against Insider Threats txtify archive
CISA Releases Product Categories List to Propel Post-Quantum Cryptography Adoption Pursuant to President Trump’s Executive Order 14306 txtify archive
CVE-2026-20830 Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability txtify archive
CVE-2026-21221 Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability txtify archive
Closing the Door on Net-NTLMv1: Releasing Rainbow Tables to Accelerate Protocol Deprecation txtify archive