VulnSea

CWE-617

CVEs classified under CWE-617, newest first.

84 CVEsRSS

GHSA-c8w6-x74f-vmg3Medium· 6.5
2mo ago

zebrad vulnerable to full node denial of service via crafted Sapling receiver in z_listunifiedreceivers

zebrad vulnerable to full node denial of service via crafted Sapling receiver in z_listunifiedreceivers

▾ Sunlitzebra-rpc · zebra-rpcvia GHSA
CVE-2026-52961Medium· 5.5
3mo ago

In the Linux kernel, the following vulnerability has been resolved: ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size The generic/642 test-case can reproduce the kernel crash: [40243.605254] ------------[ cut here …

In the Linux kernel, the following vulnerability has been resolved: ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size The generic/642 test-case can reproduce the kernel crash: [40243.605254] ------------[ cut here …

▾ Sunlitlinux · linux_kernelEPSS 0.18%via NVD
CVE-2026-10651High· 7.1
3mo ago

A malformed Bluetooth Classic SDP attribute can trigger a reachable assertion in Zephyr's SDP parser

A malformed Bluetooth Classic SDP attribute can trigger a reachable assertion in Zephyr's SDP parser. In subsys/bluetooth/host/classic/sdp.c, bt_sdp_parse_attribute() accepts an input buffer once it contains the 1-byte attribute type and…

▾ Twilightzephyrproject · zephyrEPSS 0.30%via NVD
CVE-2026-41523High· 7.5
3mo ago

vllm: vLLM: Arbitrary code execution via malicious HuggingFace model (CVE-2026-41523)

A flaw was found in vLLM, an inference and serving engine for large language models (LLMs). An unauthenticated attacker can exploit an assert-based security check during activation function loading. By publishing a malicious HuggingFace mo…

▾ TwilightRed Hat · Red Hat AI Inference Server 3.4EPSS 0.91%via CSAF
CVE-2026-52718Medium· 6.5
3mo ago

A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad

A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse_tile_list_obu() function passes a byte count to a bit-reader API that expects a bit count, causing parser desynchron…

▾ SunlitEPSS 0.71%via NVD
CVE-2026-46117High· 7.8
4mo ago

In the Linux kernel, the following vulnerability has been resolved: RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss() Sashiko points out that the user can specify WQs sharing the same CQ as a part of the uAPI and …

In the Linux kernel, the following vulnerability has been resolved: RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss() Sashiko points out that the user can specify WQs sharing the same CQ as a part of the uAPI and …

▾ Twilightlinux · linux_kernelEPSS 0.19%via NVD
CVE-2026-5946High· 7.5
4mo ago

Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes (`ANY` or `NONE`) in the question sec…

Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes (`ANY` or `NONE`) in the question sec…

▾ Twilightisc · bindEPSS 1.7%via NVD
CVE-2026-8843Medium· 6.5
4mo ago

Creating a "2dsphere_bucket" index on a non-timeseries bucket collection will succeed, but any subsequent attempt to insert a document which triggers updating that index will crash the server

Creating a "2dsphere_bucket" index on a non-timeseries bucket collection will succeed, but any subsequent attempt to insert a document which triggers updating that index will crash the server. A similar issue occurs when creating "querya…

▾ Sunlitmongodb · mongodbEPSS 0.42%via NVD
CVE-2026-8257Low· 3.3
4mo ago

A vulnerability was detected in WebAssembly Binaryen up to 117

A vulnerability was detected in WebAssembly Binaryen up to 117. This issue affects the function IRBuilder::makeBrOn of the file src/wasm/wasm-ir-builder.cpp of the component BrOn Parser. Performing a manipulation results in reachable ass…

▾ Sunlitwebassembly · binaryenEPSS 0.19%via NVD
CVE-2026-43344Medium· 5.5
4mo ago

In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel/uncore: Fix die ID init and look up bugs In snbep_pci2phy_map_init(), in the nr_node_ids > 8 path, uncore_device_to_die() may return -1 when all CPUs as…

In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel/uncore: Fix die ID init and look up bugs In snbep_pci2phy_map_init(), in the nr_node_ids > 8 path, uncore_device_to_die() may return -1 when all CPUs as…

▾ Sunlitlinux · linux_kernelEPSS 0.16%via NVD
CVE-2026-39836High· 7.5
4mo ago

net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows (CVE-2026-39836)

A flaw was found in the `net` package of Go (golang). When running on Windows, the `Dial` and `LookupPort` functions can panic if they receive an input containing a NUL (0) byte. This can be triggered by a remote attacker providing a speci…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.62%via CSAF
CVE-2026-31451Medium· 5.5
5mo ago

In the Linux kernel, the following vulnerability has been resolved: ext4: replace BUG_ON with proper error handling in ext4_read_inline_folio Replace BUG_ON() with proper error handling when inline data size exceeds PAGE_SIZE

In the Linux kernel, the following vulnerability has been resolved: ext4: replace BUG_ON with proper error handling in ext4_read_inline_folio Replace BUG_ON() with proper error handling when inline data size exceeds PAGE_SIZE. This pre…

▾ Sunlitlinux · linux_kernelEPSS 0.16%via NVD
CVE-2026-34219Medium· 5.9
6mo ago

libp2p-rust is the official rust language Implementation of the libp2p networking stack

libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to version 0.49.4, the Rust libp2p Gossipsub implementation contains a remotely reachable panic in backoff expiry handling. After a peer sends…

▾ Sunlitprotocol · libp2p-gossipsubEPSS 0.50%via NVD
CVE-2026-27135High· 7.5
6mo ago

nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination (CVE-2026-27135)

A flaw was found in nghttp2. Due to missing internal state validation, the library continues to process incoming data even after a session has been terminated. A remote attacker could exploit this by sending a specially crafted HTTP/2 fram…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.89%via CSAF
CVE-2025-69534High· 7.5
6mo ago

Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing

Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception,…

▾ Twilightpython-markdown · markdownEPSS 0.57%via NVD
CVE-2025-12131Medium· 6.5
7mo ago

A truncated 802.15.4 packet can lead to an assert, resulting in a denial of service.

A truncated 802.15.4 packet can lead to an assert, resulting in a denial of service.

▾ Sunlitsilabs · simplicity_software_development_kitEPSS 0.22%via NVD
CVE-2025-13878High· 7.5
8mo ago

Malformed BRID/HHIT records can cause `named` to terminate unexpectedly. This issue affects BIND 9 versions 9.18.40 through 9.18.43, 9.20.13 through 9.20.17, 9.21.12 through 9.21.16, 9.18.40-S1 through 9.18.43-S1, and 9.20.13-S1 through …

Malformed BRID/HHIT records can cause `named` to terminate unexpectedly. This issue affects BIND 9 versions 9.18.40 through 9.18.43, 9.20.13 through 9.20.17, 9.21.12 through 9.21.16, 9.18.40-S1 through 9.18.43-S1, and 9.20.13-S1 through …

▾ TwilightEPSS 9.2%via NVD
CVE-2025-58188Medium
11mo ago

crypto/x509: golang: Panic when validating certificates with DSA public keys in crypto/x509 (CVE-2025-58188)

A denial of service vector has been discovered in the golang crypto/x509 module. An attacker could craft an intermediate X.509 certificate containing a DSA public key and can crash a remote host with an unauthenticated call to any endpoint…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.36%via CSAF
CVE-2025-59530Medium· 5.3⚖ disputed
11mo ago

github.com/quic-go/quic-go: quic-go Crash Due to Premature HANDSHAKE_DONE Frame (CVE-2025-59530)

A denial of service flaw has been discovered in the quic-go golang library. A misbehaving or malicious server can cause a denial-of-service (DoS) attack on the quic-go client by triggering an assertion failure, leading to a process crash. …

▾ SunlitRed Hat · Red Hat Ansible Automation Platform 2.5 for RHEL 8EPSS 0.46%via CSAF
CVE-2024-57924Medium· 5.5
1y ago

In the Linux kernel, the following vulnerability has been resolved: fs: relax assertions on failure to encode file handles Encoding file handles is usually performed by a filesystem >encode_fh() method that may fail for various reasons…

In the Linux kernel, the following vulnerability has been resolved: fs: relax assertions on failure to encode file handles Encoding file handles is usually performed by a filesystem >encode_fh() method that may fail for various reasons…

▾ Sunlitlinux · linux_kernelEPSS 0.26%via NVD
CVE-2022-48633Medium· 5.5
2y ago

In the Linux kernel, the following vulnerability has been resolved: drm/gma500: Fix WARN_ON(lock->magic != lock) error psb_gem_unpin() calls dma_resv_lock() but the underlying ww_mutex gets destroyed by drm_gem_object_release() move th…

In the Linux kernel, the following vulnerability has been resolved: drm/gma500: Fix WARN_ON(lock->magic != lock) error psb_gem_unpin() calls dma_resv_lock() but the underlying ww_mutex gets destroyed by drm_gem_object_release() move th…

▾ Sunlitlinux · linux_kernelEPSS 0.19%via NVD
CVE-2022-22901Medium· 5.5
4y ago

There is an Assertion in 'context_p->next_scanner_info_p->type == SCANNER_TYPE_FUNCTION' failed at parser_parse_function_arguments in /js/js-parser.c of JerryScript commit a6ab5e9.

There is an Assertion in 'context_p->next_scanner_info_p->type == SCANNER_TYPE_FUNCTION' failed at parser_parse_function_arguments in /js/js-parser.c of JerryScript commit a6ab5e9.

▾ Sunlitjerryscript · jerryscriptEPSS 0.68%via NVD
CVE-2020-20211Medium· 6.5
5y ago

Mikrotik RouterOs 6.44.5 (long-term tree) suffers from an assertion failure vulnerability in the /nova/bin/console process

Mikrotik RouterOs 6.44.5 (long-term tree) suffers from an assertion failure vulnerability in the /nova/bin/console process. An authenticated remote attacker can cause a Denial of Service due to an assertion failure via a crafted packet.

▾ Sunlitmikrotik · routerosEPSS 2.5%via NVD
CVE-2020-15670High· 8.8
5y ago

Mozilla developers reported memory safety bugs present in Firefox for Android 79

Mozilla developers reported memory safety bugs present in Firefox for Android 79. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary cod…

▾ Twilightmozilla · firefoxEPSS 1.1%via NVD
CWE-617 vulnerabilities (CVEs) — page 3 · VulnSea