Export limit exceeded: 403286 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (403286 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-106407 | 1 Google | 1 Chrome | 2026-10-08 | 6.5 Medium |
| Incorrect authorization in GetUserMedia in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-11788 | 1 Redhat | 12 389 Directory Server, Directory Server, Directory Server E4s and 9 more | 2026-10-08 | 5.9 Medium |
| A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under memory pressure. | ||||
| CVE-2026-11770 | 2 Port389, Redhat | 13 389-ds-base, 389 Directory Server, Directory Server and 10 more | 2026-10-08 | 7.5 High |
| A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the attacker can extract sensitive server configuration metadata, including replication bind DNs and password storage scheme information. | ||||
| CVE-2026-76560 | 1 Redhat | 10 Directory Server, Directory Server E4s, Enterprise Linux and 7 more | 2026-10-08 | 7.5 High |
| A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access control checks intended to require a matching authenticated identity. This can allow an anonymous LDAP client to perform an operation, such as adding or modifying a directory entry, that a SELFDN-based ACI intended to restrict to a specific authenticated user. | ||||
| CVE-2026-18922 | 1 Redhat | 11 Directory Server, Directory Server E4s, Enterprise Linux and 8 more | 2026-10-08 | 9.8 Critical |
| A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An attacker can send a SASL PLAIN bind as cn=Directory Manager with an incorrect password, then complete a SASL ANONYMOUS bind on the same connection, causing the server to grant Directory Manager authority without any valid credentials. A variant using a valid low-privileged account's own successful bind instead of an anonymous one is also possible. | ||||
| CVE-2026-19843 | 1 Redhat | 6 Directory Server, Directory Server E2s, Directory Server E4s and 3 more | 2026-10-08 | 8.4 High |
| A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP entry's distinguished name (DN) into a shell command string without proper escaping. An LDAP user with delegated privileges to create or rename directory entries could craft a malicious DN containing shell metacharacters. When a Cockpit administrator subsequently views the entry in the 389 Console, the embedded shell command executes with root privileges on the directory server host. | ||||
| CVE-2026-18453 | 1 Redhat | 11 Directory Server, Directory Server E4s, Enterprise Linux and 8 more | 2026-10-08 | 7.5 High |
| A flaw was found in 389 Directory Server. A missing NULL pointer check in the paged results handling of op_shared_search allows an unauthenticated remote attacker to crash the LDAP server by sending a crafted sequence of search requests using the USE_ONE_BACKEND control, resulting in denial of service. | ||||
| CVE-2026-63692 | 1 Dell | 1 Container Storage Modules | 2026-10-08 | 10 Critical |
| Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | ||||
| CVE-2026-18355 | 1 Redhat | 10 Directory Server, Directory Server E4s, Enterprise Linux and 7 more | 2026-10-08 | 7.5 High |
| A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), the wrapped-record length read from the wire is validated only against an upper bound. A small wire length (0, 1, or 2) produces an encrypted_buffer_count below the already-consumed encrypted_buffer_offset, causing an unsigned subtraction underflow in sasl_io_read_packet(). PR_Recv is then requested to read approximately 4 GiB into a 1024-byte heap buffer, resulting in a heap buffer overflow with attacker-controlled content. After a successful SASL bind with integrity protection (SSF > 0), a remote authenticated attacker can cause a denial of service or potentially achieve remote code execution. This flaw is distinct from CVE-2026-11774, whose fix only guards against upper-bound overflow. | ||||
| CVE-2026-15722 | 1 Redhat | 12 389 Directory Server, Directory Server, Directory Server E4s and 9 more | 2026-10-08 | 7.5 High |
| A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated attacker can crash the LDAP server by sending a crafted StartNSDS50ReplicationRequest extended operation containing a replica ID field with more than 16 digit characters. The overflow occurs during payload decoding, before any authorization check. Stack protectors limit impact to denial of service. | ||||
| CVE-2026-67269 | 1 Dell | 1 Container Storage Modules | 2026-10-08 | 9.9 Critical |
| Dell Container Storage Modules (CSM) Operator, versions prior to 1.18.0 contains an Improper Privilege Management vulnerability in the ContainerStorageModule Custom Resource reconciler. A low privileged remote attacker could potentially exploit this vulnerability, leading to escalation of privileges and gaining root-level access on cluster nodes. | ||||
| CVE-2026-107640 | 2026-10-08 | 9.1 Critical | ||
| Integrics Enswitch 3.13 through 4.4 contains an authentication bypass vulnerability in /api/json/user/password/update/ that allows unauthenticated attackers to change account passwords by omitting the reset parameter. Attackers can target accounts with no pending reset, whose empty reset_key matches the defaulted empty value, to take over administrator accounts after enumerating valid usernames. | ||||
| CVE-2026-107635 | 2026-10-08 | 5.5 Medium | ||
| Dislocker through 0.7.3 contains an integer underflow vulnerability in get_vmk() and get_fvek() that allows attackers to trigger out-of-bounds heap reads via crafted datum sizes. Attackers can supply a malicious BitLocker volume image with a datum_size smaller than the 36-byte AES-CCM header, causing hexdump() to over-read and crash dislocker. | ||||
| CVE-2026-107634 | 2026-10-08 | 6.1 Medium | ||
| Dislocker through 0.7.3 contains a heap out-of-bounds read vulnerability in get_dataset() and get_next_datum() that never validate dataset and datum sizes against the metadata allocation. Attackers can craft a BitLocker volume image with inflated dataset or datum sizes that, when opened or mounted, crashes dislocker or discloses adjacent heap memory. | ||||
| CVE-2026-105833 | 1 Espocrm | 1 Espocrm | 2026-10-08 | 7.7 High |
| EspoCRM before 10.0.5 contains an insecure direct object reference vulnerability in PersonalAccount\Service that allows users with Email Account scope access to retrieve other users' IMAP passwords. Attackers who know a victim's Email Account record ID can request that record to steal stored IMAP credentials and access the victim's mailbox. | ||||
| CVE-2026-105831 | 1 Espocrm | 1 Espocrm | 2026-10-08 | 4.3 Medium |
| EspoCRM before 10.0.6 contains a stored HTML injection vulnerability that allows unauthenticated attackers to inject HTML by submitting crafted Lead Capture public form data. The request body is stored in LeadCaptureLogRecord.data and rendered unescaped when administrators view the log record, though Content Security Policy blocks JavaScript execution. | ||||
| CVE-2026-105829 | 1 Thephpleague | 1 Commonmark | 2026-10-08 | 6.1 Medium |
| League CommonMark from 1.3.0 before 2.10.2 contains a cross-site scripting vulnerability that allows users posting Markdown to bypass the DisallowedRawHtml extension by ending raw HTML with a bare disallowed tag name. Attackers can place a lone <script or <iframe line followed by a block supplying attributes like src or onload, executing stored scripts in viewers' browsers under default GFM settings. | ||||
| CVE-2026-105826 | 1 Imagemagick | 1 Imagemagick | 2026-10-08 | 5.3 Medium |
| ImageMagick before 6.9.13-55 and 7.x before 7.1.2-30 contains a security policy bypass in the MAT decoder, which does not enforce configured temporary file size limits when reading highly compressed data. Attackers can supply a crafted MAT image whose decompressed data is written to temporary files larger than the policy allows, consuming disk resources. | ||||
| CVE-2026-105824 | 1 Imagemagick | 1 Imagemagick | 2026-10-08 | 5.9 Medium |
| ImageMagick before 6.9.13-55 and 7.x before 7.1.2-30 contains a use-after-free vulnerability in the RSVG decoder when built without cairo support, triggered when a limit is hit during decoding. Attackers can supply crafted SVG files that cause a limit to be reached, leading to access of freed memory and a crash. | ||||
| CVE-2026-105823 | 1 Imagemagick | 1 Imagemagick | 2026-10-08 | 4 Medium |
| ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 lacks a security policy check in the CUT encoder, allowing configured security policies to be bypassed. Attackers can supply crafted input processed by the CUT encoder to crash the application or leak sensitive data. | ||||