VulnSea

Tagged “csaf”

CVEs tagged csaf, newest first.

3138 CVEsRSS

CVE-2026-67304High· 7.5
1mo ago

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when reader-state decoding fails

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when reader-state decoding fails. Attackers can send malformed smartcard IRP requests with non-zero cReaders and truncate…

▾ Twilightfreerdp · freerdpEPSS 0.65%via NVD
CVE-2026-67302Medium· 4.3
1mo ago

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a divide-by-zero vulnerability in the rdpecam camera redirection client

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a divide-by-zero vulnerability in the rdpecam camera redirection client. ecam_dev_process_start_streams_request() parses a server-controlled CAM_MEDIA_TYPE_DESCRIPTION from a S…

▾ Sunlitfreerdp · freerdpEPSS 0.50%via NVD
CVE-2026-67301High· 7.5
1mo ago

FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC and PolygonCB primary drawing orders

FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC and PolygonCB primary drawing orders. When AsyncUpdate is enabled (e.g., xfreerdp /async-update), update_message_Polygo…

▾ Twilightfreerdp · freerdpEPSS 0.65%via NVD
CVE-2026-67298High· 7.5
1mo ago

FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server-side RAIL channel handler (rail_server_handle_messages() in channels/rail/server/rail_main.c)

FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server-side RAIL channel handler (rail_server_handle_messages() in channels/rail/server/rail_main.c). When processing a RAIL PDU header, the code subtracts RAIL_PD…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.67%via NVD
CVE-2026-67297High· 7.5
1mo ago

FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body()

FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers controlling a malicious RD Gateway endpoint can send oversized chunked respo…

▾ Twilightfreerdp · freerdpEPSS 0.52%via NVD
CVE-2026-67296High· 7.5
1mo ago

FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation

FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation. A malicious RDP client can send a header-only RDPEI message wit…

▾ Twilightfreerdp · freerdpEPSS 0.52%via NVD
CVE-2026-67291High· 7.5
1mo ago

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c. When handling a GLYPH_FRAGMENT_ADD update, the code reads …

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.65%via NVD
CVE-2026-67290High· 7.5
1mo ago

FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDEOINFO media types with insufficient ExtraData

FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDEOINFO media types with insufficient ExtraData. Attackers can send malformed media format data from a server to t…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.61%via NVD
CVE-2026-67288High· 7.5⚖ disputed
1mo ago

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations. When smartcard emu…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.64%via NVD
CVE-2026-18218Medium· 4.2
1mo ago

A flaw was found in the TokenManager component of the Keycloak identity management service

A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a specific application (client) using a "not-before" policy, the revocation may be silently i…

▾ Sunlitredhat · build_of_keycloakEPSS 0.29%via NVD
CVE-2026-18215Medium· 6.8
1mo ago

Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant)

Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant). A flaw was discovered where this restriction is ignored when using the token exchange feature. This means …

▾ Sunlitredhat · build_of_keycloakEPSS 0.40%via NVD
CVE-2026-18209Low· 3.4
1mo ago

A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flows

A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flows. The issue occurs because the security check designed to prevent HTTP parameter pollution only inspects the query p…

▾ Sunlitredhat · build_of_keycloakEPSS 0.41%via NVD
CVE-2026-16105Medium· 4.9
1mo ago

A flaw was found in the RoleContainerResource component of Keycloak

A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoints in the admin REST API do not properly enforce authorization checks when managing composite roles. This allows a de…

▾ Sunlitredhat · build_of_keycloakEPSS 0.42%via NVD
CVE-2026-18446High· 7.5
1mo ago

fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authority (CVE-2026-18446)

A flaw was found in fast-uri. This vulnerability arises because fast-uri incorrectly parses Uniform Resource Identifiers (URIs) when a backslash is used in place of a forward slash to introduce the authority component. This discrepancy wit…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.22%via CSAF
CVE-2026-18214Medium· 6.8
1mo ago

Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Workspace domains

Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Workspace domains. A flaw was found where the token exchange feature, which allows swapping a Google token for a Keycloa…

▾ Sunlitredhat · build_of_keycloakEPSS 0.40%via NVD
CVE-2026-17701Critical· 9.6
2mo ago

Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page

Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chrom…

▾ Midnightgoogle · chromeEPSS 0.33%via NVD
CVE-2026-59881Medium· 5.3
2mo ago

aiohttp: AIOHTTP: Denial of Service via unnegotiated WebSocket compression (CVE-2026-59881)

A flaw was found in AIOHTTP. The WebSocket client in AIOHTTP processes compressed data frames even when the compression mechanism, known as permessage-deflate, has not been properly negotiated. A malicious server can exploit this by sendin…

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.52%via CSAF
CVE-2026-17678High· 8.8
2mo ago

Out of bounds read in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page

Out of bounds read in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

▾ Twilightgoogle · chromeEPSS 0.34%via NVD
CVE-2026-17677High· 8.8
2mo ago

Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page

Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

▾ Twilightgoogle · chromeEPSS 0.34%via NVD
CVE-2026-17676Critical· 9.6
2mo ago

Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page

Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium securi…

▾ Midnightgoogle · chromeEPSS 0.34%via NVD
CVE-2026-17675Critical· 9.6
2mo ago

Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page

Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

▾ Midnightgoogle · chromeEPSS 0.34%via NVD
CVE-2026-17671Critical· 9.6
2mo ago

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium sec…

▾ Midnightgoogle · chromeEPSS 0.34%via NVD
CVE-2026-17668Medium· 6.5
2mo ago

Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page

Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

▾ Sunlitgoogle · chromeEPSS 0.35%via NVD
CVE-2026-17667Medium· 6.5
2mo ago

Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page

Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

▾ Sunlitgoogle · chromeEPSS 0.35%via NVD
CVE-2026-18255High· 7.2
2mo ago

A flaw was found in Quay

A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repositories they are not a member of, allowing an attacker with read-only superuser privileges to impersonate any robot …

▾ TwilightRed Hat · quay/quay-rhel8EPSS 0.65%via NVD
CVE-2026-64560High· 7.8PoC
2mo ago

In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: Prevent UAF caused by non-leader exec() race Wongi and Jungwoo decoded and reported a non-leader exec() related race which can result in an UAF: sy…

In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: Prevent UAF caused by non-leader exec() race Wongi and Jungwoo decoded and reported a non-leader exec() related race which can result in an UAF: sy…

▾ MidnightLinux · LinuxEPSS 0.18%via NVD
CVE-2026-18201Medium· 5.5
2mo ago

Keycloak provides a way to manage identity providers and organizations through its administrative API

Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator with permission to manage identity providers could link a new provider to an organization…

▾ Sunlitredhat · build_of_keycloakEPSS 0.38%via NVD
CVE-2026-20316Medium· 5.3CISA KEV0dayPoC
2mo ago

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within…

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within…

▾ Midnightcisco · secure_firewall_management_centerEPSS 35%via NVD
CVE-2026-16313High· 7.6
2mo ago

A flaw was found in sg3_utils

A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-suppl…

▾ TwilightRed Hat · sg3_utilsEPSS 0.35%via NVD
CVE-2026-54603High· 8.6
2mo ago

OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC)

OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). From 0.4.0 to 2.0.21, a protocol-relative redirect Location returned to OAuth2::Client#request overrides the request authority,…

▾ Twilightoauth2 · oauth2EPSS 0.59%via NVD
CVEs tagged “csaf” — page 75 · VulnSea