VulnSea

CWE-617

CVEs classified under CWE-617, newest first.

77 CVEsRSS

CVE-2026-75894High· 7.5
3d ago

In osmo-iuh from 0.1.0 through 1.8.0 a reachable assertion was found in the ranap_handle_co_dt() function via a arbitrarily sized NAS-PDU that leads to process crash and remote denial of service.

In osmo-iuh from 0.1.0 through 1.8.0 a reachable assertion was found in the ranap_handle_co_dt() function via a arbitrarily sized NAS-PDU that leads to process crash and remote denial of service.

TwilightOsmocom · osmo-iuhEPSS 0.17%via NVD
CVE-2026-91147Medium· 5.9
3d ago

A flaw was found in `cockpit-ws`

A flaw was found in `cockpit-ws`. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a specially crafted request. When the `WebService.UrlRoot` is configured and a request is made t…

SunlitRed Hat · cockpitEPSS 0.33%via NVD
CVE-2026-84450Medium· 4.3
3d ago

libheif is a HEIF and AVIF file format decoder and encoder

libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.3, a crafted image item containing a clap property and an ispe width or height greater than INT32_MAX + 1 can reach crop calculations through heif_image_h…

Sunlitstrukturag · libheifEPSS 0.39%via NVD
CVE-2026-8674Medium· 5.3
4d ago

Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assert…

Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assert…

SunlitThe GNU C Library · glibcEPSS 0.31%via NVD
CVE-2026-92971High· 7.5PoC
4d ago

InternLM LMDeploy through 0.17.0 contains a reachable assertion vulnerability in the DistServe decode migration loop that allows unauthenticated attackers to terminate the inference engine

InternLM LMDeploy through 0.17.0 contains a reachable assertion vulnerability in the DistServe decode migration loop that allows unauthenticated attackers to terminate the inference engine. Attackers can submit a migration_request with a…

MidnightInternLM · lmdeployEPSS 0.49%via NVD
CVE-2026-92416Medium· 4.3PoC
5d ago

A vulnerability has been found in Open5GS up to 2.8.0

A vulnerability has been found in Open5GS up to 2.8.0. Affected by this issue is the function smf_n4_handle_session_report_request of the file src/smf/n4-handler.c of the component PFCP Session Report Request Handler. The manipulation le…

TwilightEPSS 0.40%via NVD
CVE-2026-80274High· 7.5
5d ago

If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valid wildcard answer and signed NSEC3 proof, followed by an unsigned NSEC at the same owner name, it will trigger an un…

If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valid wildcard answer and signed NSEC3 proof, followed by an unsigned NSEC at the same owner name, it will trigger an un…

TwilightISC · BIND 9EPSS 0.49%via NVD
CVE-2026-76163High· 7.5
5d ago

If BIND is loaded with a "`named.conf`" file that contains no global "`options`" block, an attacker can send a query of QTYPE TKEY which may cause an assertion failure and subsequent unexpected program exit. This issue affects BIND 9 ver…

If BIND is loaded with a "`named.conf`" file that contains no global "`options`" block, an attacker can send a query of QTYPE TKEY which may cause an assertion failure and subsequent unexpected program exit. This issue affects BIND 9 ver…

TwilightISC · BIND 9EPSS 0.48%via NVD
CVE-2026-19666High· 7.5
5d ago

On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process will exit unexpectedly. This issue affects BIND 9 versions 9.11.0 through 9.18.…

On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process will exit unexpectedly. This issue affects BIND 9 versions 9.11.0 through 9.18.…

TwilightISC · BIND 9EPSS 0.48%via NVD
CVE-2026-77692High· 7.5
5d ago

An attacker can cause `named` to abort by sending a crafted DNS-over-HTTPS request with a cryptographically invalid SIG(0) record, and then closing the transport connection prematurely. This issue affects BIND 9 versions 9.20.0 through 9…

An attacker can cause `named` to abort by sending a crafted DNS-over-HTTPS request with a cryptographically invalid SIG(0) record, and then closing the transport connection prematurely. This issue affects BIND 9 versions 9.20.0 through 9…

TwilightISC · BIND 9EPSS 0.48%via NVD
CVE-2026-73438Medium· 5.3
5d ago

On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, an unauthenticated attacker on the same OSPFv3 broadcast domain can send a specially crafted set of packets that can cause the Ospf3 ag…

On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, an unauthenticated attacker on the same OSPFv3 broadcast domain can send a specially crafted set of packets that can cause the Ospf3 ag…

SunlitArista Networks · EOSEPSS 0.21%via NVD
CVE-2026-91951Medium· 6.5PoC
6d ago

FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in the urbdrc client channel's urb_send_current_frame_number_result() function

FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in the urbdrc client channel's urb_send_current_frame_number_result() function. A malicious RDP server can send a crafted 28-byte USB redirection message to trig…

TwilightFreeRDP · FreeRDPEPSS 0.35%via NVD
CVE-2026-91961Medium· 6.5
6d ago

FreeRDP before 3.31.0 contains a denial-of-service vulnerability in the URBDRC control-transfer request path that fails to validate OutputBufferSize before forwarding to the libusb backend

FreeRDP before 3.31.0 contains a denial-of-service vulnerability in the URBDRC control-transfer request path that fails to validate OutputBufferSize before forwarding to the libusb backend. A malicious RDP server can send a control-trans…

SunlitFreeRDP · FreeRDPEPSS 0.35%via NVD
CVE-2026-55776Medium· 6.5PoC
6d ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an authenticated OpenBao caller with write access to transit/keys/* could terminate the server process by setting derived to true while the type paramete…

Twilightopenbao · openbaoEPSS 0.46%via NVD
CVE-2026-15893Medium· 6.5
1w ago

net_if_ipv6_calc_reachable_time() in subsys/net/ip/net_if.c derives a randomized ND reachable time from ipv6->base_reachable_time as min_reachable + sys_rand32_get() % (max_reachable - min_reachable), where min_reachable = base/2 and max…

net_if_ipv6_calc_reachable_time() in subsys/net/ip/net_if.c derives a randomized ND reachable time from ipv6->base_reachable_time as min_reachable + sys_rand32_get() % (max_reachable - min_reachable), where min_reachable = base/2 and max…

Sunlitzephyrproject · zephyrEPSS 0.20%via NVD
CVE-2026-90613Low· 3.3PoC
1w ago

A security flaw has been discovered in GPAC up to f1219cde

A security flaw has been discovered in GPAC up to f1219cde. Affected by this vulnerability is the function stbl_GetSampleInfos of the file isomedia/stbl_read.c of the component MP4Box. The manipulation results in reachable assertion. The…

TwilightEPSS 0.12%via NVD
CVE-2026-90612Low· 3.3PoC
1w ago

A vulnerability was identified in GPAC up to f1219cde

A vulnerability was identified in GPAC up to f1219cde. Affected is the function gf_sm_dump_command_list of the file scene_manager/scene_dump.c of the component MP4Box. The manipulation leads to reachable assertion. The attack must be car…

TwilightEPSS 0.12%via NVD
CVE-2026-90611Low· 3.3PoC
1w ago

A vulnerability was determined in GPAC up to f1219cde

A vulnerability was determined in GPAC up to f1219cde. This impacts the function xmt_parse_element of the file scene_manager/loader_xmt.c of the component MP4Box. Executing a manipulation can lead to reachable assertion. The attack is re…

TwilightEPSS 0.12%via NVD
CVE-2026-90685Low· 2.8PoC
1w ago

A vulnerability has been found in GPAC up to f1219cde

A vulnerability has been found in GPAC up to f1219cde. Affected by this issue is the function lsr_exec_command_list of the file laser/lsr_dec.c of the component MP4Box. The manipulation leads to reachable assertion. Local access is requi…

TwilightEPSS 0.11%via NVD
CVE-2026-90684Low· 2.8PoC
1w ago

A flaw has been found in GPAC up to f1219cde

A flaw has been found in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field_count of the file scenegraph/base_scenegraph.c of the component MP4Box. Executing a manipulation can lead to reachable asserti…

TwilightEPSS 0.11%via NVD
CVE-2026-90683Low· 3.3PoC
1w ago

A vulnerability was detected in GPAC up to f1219cde

A vulnerability was detected in GPAC up to f1219cde. Affected is the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. Performing a manipulation results in reachable assertion. Attacking locall…

TwilightEPSS 0.12%via NVD
CVE-2026-90786Medium· 5.3PoC
1w ago

A vulnerability was determined in Dvidelabs flatcc up to 0.6.3

A vulnerability was determined in Dvidelabs flatcc up to 0.6.3. This impacts the function align_order_members of the file src/compiler/semantics.c of the component Duplicate Symbol Handler. This manipulation causes reachable assertion. T…

TwilightDvidelabs · flatccEPSS 0.43%via NVD
CVE-2026-90785Medium· 5.3PoC
1w ago

A vulnerability was found in Dvidelabs flatcc up to 0.6.3

A vulnerability was found in Dvidelabs flatcc up to 0.6.3. This affects the function analyze_struct of the file src/compiler/semantics.c of the component Struct Analysis. The manipulation results in reachable assertion. It is possible to…

TwilightDvidelabs · flatccEPSS 0.42%via NVD
CVE-2026-89146High· 7.5PoC
1w ago

libp2p-rendezvous through 0.17.1 fails to validate registration TTL values in discovery responses, allowing attackers to trigger timer arithmetic overflow

libp2p-rendezvous through 0.17.1 fails to validate registration TTL values in discovery responses, allowing attackers to trigger timer arithmetic overflow. A malicious rendezvous server can send a discovery response with an unbounded TTL…

Midnightlibp2p · libp2p-rendezvousEPSS 0.43%via NVD
CVE-2026-89727High· 7.0
1w ago

kernel: KVM: arm64: GICv2: Don't WARN on out-of-range GICV_DIR INTID (CVE-2026-89727)

A flaw was found in the Kernel-based Virtual Machine (KVM) for ARM64 (arm64) architecture. A malicious guest operating system can provide an interrupt ID (INTID) that is outside the expected range to the GICv2 (Generic Interrupt Controller…

TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.15%via CSAF
CVE-2026-89716Medium· 4.4
1w ago

kernel: Linux kernel zram: Denial of Service due to improper deflate parameter validation (CVE-2026-89716)

A flaw was found in the zram component of the Linux kernel. This vulnerability occurs because the system does not properly validate user-supplied deflate parameters, specifically `winbits` values. An attacker could exploit this by providin…

SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.20%via CSAF
CVE-2026-75584High· 7.5
1w ago

ION-DTN before 4.2.1-a.1 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash the ION process by sending a BPv7 bundle with a zero-length payload

ION-DTN before 4.2.1-a.1 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash the ION process by sending a BPv7 bundle with a zero-length payload. The canonicalizePayloadBlock() function in bps…

Twilightnasa-jpl · ION-DTNEPSS 0.43%via NVD
CVE-2026-82068Medium· 6.5
1w ago

A security issue in MongoDB Server allows an authenticated user with write privileges to trigger a persistent fatal assertion crash by sending specially crafted retryable write commands

A security issue in MongoDB Server allows an authenticated user with write privileges to trigger a persistent fatal assertion crash by sending specially crafted retryable write commands. The crash state is durably persisted, causing the …

Sunlitmongodb · mongodbEPSS 0.28%via NVD
CVE-2026-82065Medium· 6.5
1w ago

A security issue in the MongoDB Server's storage engine integration layer allows an authenticated user with collection creation privileges to cause a persistent denial of service

A security issue in the MongoDB Server's storage engine integration layer allows an authenticated user with collection creation privileges to cause a persistent denial of service. Insufficient validation of user-supplied storage configur…

Sunlitmongodb · mongodbEPSS 0.28%via NVD
CVE-2026-82064High· 7.5
1w ago

A security issue in MongoDB Server allows an unauthenticated network user to cause a denial of service on a specific type of replica set member

A security issue in MongoDB Server allows an unauthenticated network user to cause a denial of service on a specific type of replica set member. The server contains an assertion in its read concern processing logic that can be reached wi…

Twilightmongodb · mongodbEPSS 0.29%via NVD
CWE-617 vulnerabilities (CVEs) · VulnSea