VulnSea

Tagged “csaf”

CVEs tagged csaf, newest first.

3093 CVEsRSS

CVE-2026-90781Medium· 4.4PoC
2w ago

alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters

alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a long cont…

▾ TwilightALSA Project · alsa-libEPSS 0.17%via NVD
CVE-2026-90780High· 7.5
2w ago

SIPp through 3.7.7 contains a buffer overflow vulnerability in the get_header() function in src/sip_parser.cpp when processing SIP messages with header content exceeding 20,490 bytes

SIPp through 3.7.7 contains a buffer overflow vulnerability in the get_header() function in src/sip_parser.cpp when processing SIP messages with header content exceeding 20,490 bytes. Unauthenticated remote attackers can send crafted SIP…

▾ TwilightSIPp · sippEPSS 0.86%via NVD
CVE-2026-90779High· 7.5
2w ago

SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() when processing SIP authentication challenges with oversized algorithm parameters

SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() when processing SIP authentication challenges with oversized algorithm parameters. A malicious SIP server can send a crafted 401 or 407 challenge to …

▾ TwilightRed Hat · sippEPSS 0.80%via NVD
CVE-2026-90778High· 7.5
2w ago

SIPp through 3.7.7 contains a buffer overflow vulnerability in get_peer_tag() function when processing SIP To headers with tag parameters of 2049 bytes or more

SIPp through 3.7.7 contains a buffer overflow vulnerability in get_peer_tag() function when processing SIP To headers with tag parameters of 2049 bytes or more. Unauthenticated remote attackers can send crafted SIP messages with oversize…

▾ TwilightSIPp · sippEPSS 0.86%via NVD
CVE-2026-90776High· 7.5PoC
2w ago

Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing email addresses with RFC 5322 comments

Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing email addresses with RFC 5322 comments. Attackers can craft malicious email headers with comment-separ…

▾ Midnightnodemailer · nodemailerEPSS 0.68%via NVD
CVE-2026-90584Medium· 5.3PoC
2w ago

A weakness has been identified in TooTallNate Java-WebSocket up to 1.6.1

A weakness has been identified in TooTallNate Java-WebSocket up to 1.6.1. The impacted element is the function processFrameContinuousAndNonFin of the file Draft_6455.java of the component Fragmentation Handler. Executing a manipulation c…

▾ TwilightTooTallNate · Java-WebSocketEPSS 0.72%via NVD
CVE-2026-52297Low· 2.9⚖ disputed
2w ago

FFmpeg before 9.0 has an out-of-bounds read because there is insufficiently padded extradata in the MOV parsing path in mov_read_iacb in libavformat/mov.c.

FFmpeg before 9.0 has an out-of-bounds read because there is insufficiently padded extradata in the MOV parsing path in mov_read_iacb in libavformat/mov.c.

▾ SunlitFFmpeg · FFmpegEPSS 0.15%via NVD
CVE-2026-52296Low· 2.9⚖ disputed
2w ago

FFmpeg before 9.0 has an out-of-bounds read because of missing required padding in WMA extradata allocation paths in libavcodec/wmaenc.c.

FFmpeg before 9.0 has an out-of-bounds read because of missing required padding in WMA extradata allocation paths in libavcodec/wmaenc.c.

▾ SunlitFFmpeg · FFmpegEPSS 0.15%via NVD
CVE-2026-89266High· 8.2PoC
2w ago

stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int

stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int. Attackers can craft a malicious Ogg Vorbis file with large entries and dimension…

▾ Midnightnothings · stb_vorbisEPSS 0.64%via NVD
CVE-2026-90555Medium· 6.5
2w ago

vLLM versions before 0.28.0 fail to validate audio sample rate headers in the transcription endpoint, allowing authenticated clients to bypass duration checks

vLLM versions before 0.28.0 fail to validate audio sample rate headers in the transcription endpoint, allowing authenticated clients to bypass duration checks. Attackers can submit forged FLAC headers with inflated sample rates to trigge…

▾ Sunlitvllm · vllmEPSS 0.52%via NVD
CVE-2026-90554Medium· 6.2
2w ago

vLLM versions >=0.10.2 and <0.28.0 do not apply any audio decode-size or duration limit when extracting audio from video input for NanoNemotronVL models

vLLM versions >=0.10.2 and <0.28.0 do not apply any audio decode-size or duration limit when extracting audio from video input for NanoNemotronVL models. In nano_nemotron_vl.py, _extract_audio_from_videos calls load_audio_pyav(BytesIO(vi…

▾ Sunlitvllm · vllmEPSS 0.20%via NVD
CVE-2026-90553High· 7.8
2w ago

vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes

vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbi…

▾ Twilightvllm · vllmEPSS 0.31%via NVD
CVE-2026-90616High· 7.4
2w ago

In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read and write access to files on the host, which can be escalated to arbitrary code execution on the host, a different vulnerability than CVE-2026-76925

In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read and write access to files on the host, which can be escalated to arbitrary code execution on the host, a different vulnerability than CVE-2026-76925. Flatpak c…

▾ TwilightFlatpak · FlatpakEPSS 0.18%via NVD
CVE-2026-90560High· 8.2PoC
2w ago

zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds

zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds. Attackers can supply …

▾ MidnightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.62%via NVD
CVE-2026-90558Critical· 9.8
2w ago

sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit

sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit. Attackers can craft malicious SIP packets with oversized Call-ID, X-Call-ID, or…

▾ Midnightirontec · sngrepEPSS 0.88%via NVD
CVE-2026-90557Medium· 6.1
2w ago

Freeciv versions 3.1.0 through 3.2.5 contain an out-of-bounds read vulnerability in sg_load_player_unit() when processing savegame files with invalid unit activity indices

Freeciv versions 3.1.0 through 3.2.5 contain an out-of-bounds read vulnerability in sg_load_player_unit() when processing savegame files with invalid unit activity indices. An attacker can craft a malicious savegame file with an out-of-r…

▾ Sunlitfreeciv · freecivEPSS 0.18%via NVD
CVE-2026-90556High· 7.8
2w ago

Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceeding the fixed array bound of 64 elements

Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceeding the fixed array bound of 64 elements. Attackers can craft malicious savegame files th…

▾ Twilightfreeciv · freecivEPSS 0.20%via NVD
CVE-2026-87910Medium· 5.7
2w ago

When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive

When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the loca…

▾ SunlitPython Software Foundation · CPythonEPSS 0.54%via NVD
CVE-2026-80948Medium· 5.5
2w ago

kernel: wifi: iwlwifi: dvm: fix memory leak in iwl_op_mode_dvm_start() (CVE-2026-80948)

A flaw was found in the Linux kernel's iwlwifi driver. An error handling issue within the `iwl_op_mode_dvm_start()` function can cause a memory leak. This occurs when certain error paths bypass a memory deallocation step, leading to unrele…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.22%via CSAF
CVE-2026-89773Medium· 5.5
2w ago

kernel: drm/amd/display: Skip Update HDCP Config In Transition State (CVE-2026-89773)

A flaw was found in the `drm/amd/display` component of the Linux kernel. This vulnerability occurs because the High-bandwidth Digital Content Protection (HDCP) configuration routine is skipped during a transition state when an invalid `dm_…

▾ SunlitRed Hat · Red Hat Enterprise Linux 6EPSS 0.20%via CSAF
CVE-2026-89722Medium· 5.5
2w ago

kernel: PCI/sysfs: Fix out-of-bounds read in pci_write_legacy_io() (CVE-2026-89722)

A flaw was found in the Linux kernel's PCI/sysfs component. A local user with root privileges could trigger an out-of-bounds read in the `pci_write_legacy_io()` function by writing to the `legacy_io` sysfs file with a size less than four b…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVE-2026-89642High· 7.0
2w ago

kernel: cifs: call pagecache_isize_extended() in cifs_setsize() when extending (CVE-2026-89642)

A flaw was found in the Linux kernel's Common Internet File System (CIFS) implementation. When a client extends a file, the `cifs_setsize()` function fails to properly zero out the newly extended portion of the page cache. This oversight c…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.20%via CSAF
CVE-2026-89637High· 7.0⚖ disputed
2w ago

kernel: smb: client: fix UAF and buffer leak in cifs_check_trans2() for malformed secondary T2 (CVE-2026-89637)

A flaw was found in the Linux kernel's Server Message Block (SMB) client. When processing a malformed secondary TRANSACT2 response, a use-after-free (UAF) vulnerability and a buffer leak can occur in the `cifs_check_trans2()` function. Thi…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.63%via CSAF
CVE-2026-89556Medium· 5.5
2w ago

kernel: module: validate string table section types (CVE-2026-89556)

A flaw was found in the Linux kernel. This vulnerability arises from insufficient validation of string table section types within ELF (Executable and Linkable Format) files. A local attacker could exploit this by providing a specially craf…

▾ SunlitRed Hat · LinuxEPSS 0.21%via CSAF
CVE-2026-81004Medium· 5.5⚖ disputed
2w ago

kernel: ipmi:msghandler: Cancel work cleanly on an error (CVE-2026-81004)

A flaw was found in the Linux kernel's Intelligent Platform Management Interface (IPMI) message handler. When an error occurs during the startup of an IPMI interface, scheduled work may not be properly canceled. This can prevent the interf…

▾ SunlitRed Hat · LinuxEPSS 0.19%via CSAF
CVE-2026-80998Medium· 5.5
2w ago

kernel: net: bnxt: ring the doorbell when SW USO exits early (CVE-2026-80998)

A flaw was found in the Linux kernel's `bnxt` network driver. When processing a burst of packets, the driver may fail to notify the network device (ring the doorbell) if the Software UDP Segmentation Offload (SW USO) path exits prematurely…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.49%via CSAF
CVE-2026-80997Medium· 5.5⚖ disputed
2w ago

kernel: net: ipa: fix stalled modem TX queue after runtime resume (CVE-2026-80997)

A flaw was found in the Linux kernel's IP Accelerator (IPA) network driver. Specifically, the `ipa_start_xmit()` function incorrectly manages the transmit (TX) queue during a device's runtime resume process. This can lead to the TX queue s…

▾ SunlitRed Hat · Red Hat Enterprise Linux 10EPSS 0.63%via CSAF
CVE-2026-80995Medium· 5.5⚖ disputed
2w ago

kernel: net: mctp: hold a reference to the route device in mctp_route_lookup() (CVE-2026-80995)

A flaw was found in the Linux kernel's MCTP (Message Control Transport Protocol) networking implementation. This vulnerability arises because the `mctp_route_lookup()` function accesses a route device without holding a persistent reference…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.17%via CSAF
CVE-2026-80991Medium· 5.5⚖ disputed
2w ago

kernel: net: ravb: serialize PTP clock teardown (CVE-2026-80991)

A flaw was found in the Linux kernel's `net: ravb` module. A race condition exists during the Precision Time Protocol (PTP) clock teardown. This allows the `ravb_ptp_interrupt()` function to attempt to use a PTP clock after it has been fre…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.17%via CSAF
CVE-2026-80986High· 7.0⚖ disputed
2w ago

kernel: net/smc: bound the peer rkey counts in SMC-Rv2 LLC messages (CVE-2026-80986)

A flaw was found in the Linux kernel's SMC-Rv2 network component. A remote attacker could exploit this vulnerability by sending a specially crafted message during an SMC-Rv2 link addition. This can lead to a slab-out-of-bounds write, poten…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.65%via CSAF
CVEs tagged “csaf” — page 28 · VulnSea