VulnSea

CWE-665

CVEs classified under CWE-665, newest first.

10 CVEsRSS

CVE-2026-57229Medium· 5.3
4d ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the SMTP MIME parser in rust/src/mime/smtp.rs does not fully reset state when processing Conten…

SunlitOISF · suricataEPSS 0.41%via NVD
CVE-2026-87616High· 8.3
1w ago

Improper initialization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the …

Improper initialization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the …

Twilightgoogle · chromeEPSS 0.39%via NVD
CVE-2026-78940Medium· 4.3
4w ago

Improper initialization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page

Improper initialization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

SunlitGoogle · ChromeEPSS 0.38%via CVEORG
CVE-2026-44434Medium· 5.3
2mo ago

Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server

Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit dccf5d4, Quicly was vulnerable to stateless reset injection through lack of packet entry validation. The QUIC protocol …

SunlitEPSS 0.21%via NVD
CVE-2026-54777Medium· 6.5
3mo ago

CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instance

CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instance

SunlitCoreWCF · CoreWCF.NetNamedPipeEPSS 0.12%via GHSA
GHSA-cmwh-pvxp-8882Medium
3mo ago

DOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch)

DOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch)

Sunlitdompurify · dompurifyvia GHSA
CVE-2026-54279Low
3mo ago

aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence

aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence

Sunlitaiohttp · aiohttpEPSS 0.28%via OSV
CVE-2025-39862Medium· 5.5⚖ disputed
1y ago

kernel: wifi: mt76: mt7915: fix list corruption after hardware restart (CVE-2025-39862)

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: fix list corruption after hardware restart Since stations are recreated from scratch, all lists that wcids are added to must be cleared before callin…

SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.19%via CSAF
CVE-2025-21906High· 7.6
1y ago

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: clean up ROC on failure If the firmware fails to start the session protection, then we do call iwl_mvm_roc_finished() here, but that won't do anyth…

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: clean up ROC on failure If the firmware fails to start the session protection, then we do call iwl_mvm_roc_finished() here, but that won't do anyth…

Twilightlinux · linux_kernelEPSS 0.22%via NVD
CVE-2020-26957Medium· 6.5
5y ago

OneCRL was non-functional in the new Firefox for Android due to a missing service initialization

OneCRL was non-functional in the new Firefox for Android due to a missing service initialization. This could result in a failure to enforce some certificate revocations. *Note: This issue only affected Firefox for Android. Other operatin…

Sunlitmozilla · firefox_mobileEPSS 0.55%via NVD
CWE-665 vulnerabilities (CVEs) · VulnSea