Tagged “score-dispute”
CVEs tagged score-dispute, newest first.
589 CVEsRSS
CVE-2026-43697High· 7.1⚖ disputedAn out-of-bounds read was addressed with improved bounds checking
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Processing a maliciously crafted 3D file may lead to an out-of-bounds read.
CVE-2026-18119Critical· 9.0⚖ disputedConcrete CMS below 9.5.3 did not sanitize custom style values in the Block Design dialog before writing them into page CSS via a DOM sink, permitting stored cross-site scripting
Concrete CMS below 9.5.3 did not sanitize custom style values in the Block Design dialog before writing them into page CSS via a DOM sink, permitting stored cross-site scripting. An editor-level user could execute script in an administra…
CVE-2025-64031Low· 2.5PoC⚖ disputedlibarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer overflow in the gzip writer via the original-filename field to archive_compressor_gzip_open in archive_write_add_filter_gzip.c, aka GHSA-92wx-p669-8gr9
libarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer overflow in the gzip writer via the original-filename field to archive_compressor_gzip_open in archive_write_add_filter_gzip.c, aka GHSA-92wx-p669-8gr9. This relates to bsdtar.…
CVE-2026-82434Medium· 6.5⚖ disputedDescription When ZooKeeper authentication is configured, Storm deliberately retains `storm.zookeeper.topology.auth.payload` in the topology configuration, because workers need it
Description When ZooKeeper authentication is configured, Storm deliberately retains `storm.zookeeper.topology.auth.payload` in the topology configuration, because workers need it. Nimbus then served that configuration verbatim to any ca…
CVE-2026-90771Low· 3.7PoC⚖ disputedjoi before versions 17.13.8 and 18.2.9 contains a prototype pollution vulnerability in the messages compilation function that accepts __proto__ as an error code
joi before versions 17.13.8 and 18.2.9 contains a prototype pollution vulnerability in the messages compilation function that accepts __proto__ as an error code. Attackers can supply __proto__ keys in custom messages to replace the retur…
CVE-2026-52297Low· 2.9⚖ disputedFFmpeg before 9.0 has an out-of-bounds read because there is insufficiently padded extradata in the MOV parsing path in mov_read_iacb in libavformat/mov.c.
FFmpeg before 9.0 has an out-of-bounds read because there is insufficiently padded extradata in the MOV parsing path in mov_read_iacb in libavformat/mov.c.
CVE-2026-52296Low· 2.9⚖ disputedFFmpeg before 9.0 has an out-of-bounds read because of missing required padding in WMA extradata allocation paths in libavcodec/wmaenc.c.
FFmpeg before 9.0 has an out-of-bounds read because of missing required padding in WMA extradata allocation paths in libavcodec/wmaenc.c.
CVE-2026-89637High· 7.0⚖ disputedkernel: smb: client: fix UAF and buffer leak in cifs_check_trans2() for malformed secondary T2 (CVE-2026-89637)
A flaw was found in the Linux kernel's Server Message Block (SMB) client. When processing a malformed secondary TRANSACT2 response, a use-after-free (UAF) vulnerability and a buffer leak can occur in the `cifs_check_trans2()` function. Thi…
CVE-2026-81004Medium· 5.5⚖ disputedkernel: ipmi:msghandler: Cancel work cleanly on an error (CVE-2026-81004)
A flaw was found in the Linux kernel's Intelligent Platform Management Interface (IPMI) message handler. When an error occurs during the startup of an IPMI interface, scheduled work may not be properly canceled. This can prevent the interf…
CVE-2026-80997Medium· 5.5⚖ disputedkernel: net: ipa: fix stalled modem TX queue after runtime resume (CVE-2026-80997)
A flaw was found in the Linux kernel's IP Accelerator (IPA) network driver. Specifically, the `ipa_start_xmit()` function incorrectly manages the transmit (TX) queue during a device's runtime resume process. This can lead to the TX queue s…
CVE-2026-80995Medium· 5.5⚖ disputedkernel: net: mctp: hold a reference to the route device in mctp_route_lookup() (CVE-2026-80995)
A flaw was found in the Linux kernel's MCTP (Message Control Transport Protocol) networking implementation. This vulnerability arises because the `mctp_route_lookup()` function accesses a route device without holding a persistent reference…
CVE-2026-80991Medium· 5.5⚖ disputedkernel: net: ravb: serialize PTP clock teardown (CVE-2026-80991)
A flaw was found in the Linux kernel's `net: ravb` module. A race condition exists during the Precision Time Protocol (PTP) clock teardown. This allows the `ravb_ptp_interrupt()` function to attempt to use a PTP clock after it has been fre…
CVE-2026-80986High· 7.0⚖ disputedkernel: net/smc: bound the peer rkey counts in SMC-Rv2 LLC messages (CVE-2026-80986)
A flaw was found in the Linux kernel's SMC-Rv2 network component. A remote attacker could exploit this vulnerability by sending a specially crafted message during an SMC-Rv2 link addition. This can lead to a slab-out-of-bounds write, poten…
CVE-2026-80985High· 7.0⚖ disputedkernel: net/smc: carry oversized SMC-Rv2 LLC messages in the queue entry (CVE-2026-80985)
A flaw was found in the Linux kernel's Server Message Block over Remote Direct Memory Access (SMC-Rv2) protocol implementation. The `smc_llc_rmt_delete_rkey()` and `smc_llc_save_add_link_rkeys()` functions incorrectly handle oversized LLC …
CVE-2026-80981High· 7.0⚖ disputedkernel: net/smc: fix use-after-free of the LLC qentry in smc_llc_srv_add_link() (CVE-2026-80981)
A flaw was found in the Linux kernel's net/smc component. A local attacker could exploit a use-after-free vulnerability in the `smc_llc_srv_add_link()` function, where a freed memory region is improperly accessed. This can lead to memory c…
CVE-2026-80980Medium· 5.5⚖ disputedkernel: net/smc: stop killed, freed and out_of_sync sharing a byte (CVE-2026-80980)
A flaw was found in the Linux kernel's SMC (Server Message Block over Remote Direct Memory Access) protocol implementation. A concurrency issue exists where three connection state flags (killed, freed, and out_of_sync) share a single byte …
CVE-2026-80975Medium· 5.5⚖ disputedkernel: mfd: qnap-mcu: keep the reply buffer alive past a command timeout (CVE-2026-80975)
A flaw was found in the Linux kernel's `qnap-mcu` driver. This vulnerability occurs when the driver processes commands and a reply from the Microcontroller Unit (MCU) arrives after a command has timed out or failed. The driver may write th…
CVE-2026-80961Medium· 5.5⚖ disputedkernel: dm-pcache: validate kset key_num and intra-segment bounds (CVE-2026-80961)
A flaw was found in the `dm-pcache` component of the Linux kernel. A local attacker with `CAP_SYS_ADMIN` capabilities could exploit unbounded fields decoded from the cache device. This could lead to an out-of-bounds read, potentially discl…
CVE-2026-80959Medium· 5.5⚖ disputedkernel: dm-pcache: bound the persisted tail-position offset (CVE-2026-80959)
A flaw was found in the Linux kernel's device-mapper persistent cache (dm-pcache) component. A local attacker with administrative privileges (CAP_SYS_ADMIN) could provide a specially crafted cache device, leading to an out-of-bounds read. …
CVE-2026-80958Medium· 5.5⚖ disputedkernel: dm-pcache: clamp the tail kset read to the segment data region (CVE-2026-80958)
A flaw was found in the dm-pcache component of the Linux kernel. The tail-kset read operations, used by cache_replay(), the writeback worker, and the garbage collection (GC) worker, incorrectly calculate the length of the data region. This…
CVE-2026-80955Medium· 5.5⚖ disputedkernel: dm-pcache: fix use-after-free and invalid seg operations in kset_replay() (CVE-2026-80955)
A flaw was found in the Linux kernel's dm-pcache component. This vulnerability, a use-after-free, occurs within the `kset_replay` function when a stale key's segment generation is accessed after it has been freed. This could allow a local …
CVE-2026-80954Medium· 5.5⚖ disputedkernel: i3c: Fix unlocked dereference of dev->desc in i3c_device_get_supported_xfer_mode() (CVE-2026-80954)
A flaw was found in the Linux kernel's i3c driver. The `i3c_device_get_supported_xfer_mode()` function attempts to access a device descriptor without holding the necessary lock. This unlocked dereference can lead to memory corruption, pote…
CVE-2026-80953Medium· 5.5⚖ disputedkernel: i3c: master: adi: initialize the lock before enabling interrupts (CVE-2026-80953)
A flaw was found in the Linux kernel's i3c master driver. A race condition exists where the `adi_i3c_master_probe()` function requests an interrupt and unmasks a register before a critical lock (`xferqueue.lock`) is properly initialized. T…
CVE-2026-80950Medium· 5.5⚖ disputedkernel: i3c: renesas: Check that the transfer is valid before accessing it (CVE-2026-80950)
A flaw was found in the Linux kernel's Renesas I3C driver. This driver uses an asynchronous model for data transfers. When a transfer times out, the associated memory is freed. However, if an interrupt occurs after the memory is freed but …
CVE-2026-80947High· 7.0⚖ disputedkernel: wifi: rtl8xxxu: fix use-after-free from rx_urb_wq on stop (CVE-2026-80947)
A flaw was found in the Linux kernel's `rtl8xxxu` Wi-Fi driver. A race condition exists during the driver's stop process, specifically when handling receive (RX) Universal Serial Bus (USB) Request Blocks (URBs). This allows a worker to acc…
CVE-2026-80945Critical· 9.1⚖ disputedIn the Linux kernel, the following vulnerability has been resolved: crypto: iaa - unmap dst before software fallback on decompress On a hardware analytics error, decompress retries through the software fallback, which writes req->dst w…
In the Linux kernel, the following vulnerability has been resolved: crypto: iaa - unmap dst before software fallback on decompress On a hardware analytics error, decompress retries through the software fallback, which writes req->dst w…
CVE-2026-80943Medium· 5.5⚖ disputedkernel: wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids (CVE-2026-80943)
A flaw was found in the Linux kernel's rtlwifi driver. This vulnerability occurs when the `rtl92du_tx_fill_desc()` function uses a Quality of Service (QoS) Traffic Identifier (TID) value greater than 8 as an index into an array that only h…
CVE-2026-80937Medium· 5.5⚖ disputedkernel: wifi: mt76: mt7915: bound the device EEPROM address before the EFUSE copy (CVE-2026-80937)
A flaw was found in the Linux kernel's Wi-Fi driver for mt7915 chipsets. This vulnerability allows a malicious or malfunctioning Wi-Fi device to provide an invalid memory address. This can cause the driver to write data beyond its allocate…
CVE-2026-80936Medium· 5.5⚖ disputedkernel: wifi: mt76: mt7925: cancel mlo_pm_work on stop (CVE-2026-80936)
A flaw was found in the Linux kernel's mt7925 Wi-Fi driver. During multi-link power-save setup, the `mlo_pm_work` is queued with a delay but not properly cancelled when the device is stopped. This can lead to the work item attempting to ac…
CVE-2026-89523High· 7.0⚖ disputedkernel: wifi: mt76: mt7925: cancel pending mlo_pm_work (CVE-2026-89523)
A flaw was found in the Linux kernel's MediaTek mt7925 Wi-Fi driver. When the device is reset, suspended, or unregistered, a pending work item (`mlo_pm_work`) can continue to execute. This can lead to the work item accessing memory that ha…