<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Memory Corruption (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/mem-corruption.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/mem-corruption-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Memory Corruption (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:35 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-25277 – Memory corruption while using Strongbox due to buffer overflow.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25277</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25277</guid>
    <pubDate>Mon, 01 Jun 2026 23:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25277</strong></p>
  <p>Memory corruption while using Strongbox due to buffer overflow.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25277">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25276 – Memory corruption while using Strongbox due to missing bounds check.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25276</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25276</guid>
    <pubDate>Mon, 01 Jun 2026 23:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25276</strong></p>
  <p>Memory corruption while using Strongbox due to missing bounds check.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-129</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25276">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25260 – Memory Corruption when accessing shared buffers without validation of concurrent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25260</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25260</guid>
    <pubDate>Mon, 01 Jun 2026 23:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25260</strong></p>
  <p>Memory Corruption when accessing shared buffers without validation of concurrent user-mode input modifications.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25260">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25259 – Memory corruption while processing multiple IOCTL command for escape operations.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25259</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25259</guid>
    <pubDate>Mon, 01 Jun 2026 23:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25259</strong></p>
  <p>Memory corruption while processing multiple IOCTL command for escape operations.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25259">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25258 – Memory corruption while processing IOCTL calls for escape operations.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25258</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25258</guid>
    <pubDate>Mon, 01 Jun 2026 23:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25258</strong></p>
  <p>Memory corruption while processing IOCTL calls for escape operations.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25258">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24092 – Memory Corruption when processing fastboot commands to set display mode.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24092</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24092</guid>
    <pubDate>Mon, 01 Jun 2026 23:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24092</strong></p>
  <p>Memory Corruption when processing fastboot commands to set display mode.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-1286</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24092">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24091 – Memory corruption while processing fastboot commands with improperly formatted i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24091</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24091</guid>
    <pubDate>Mon, 01 Jun 2026 23:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24091</strong></p>
  <p>Memory corruption while processing fastboot commands with improperly formatted input.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-1286</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24091">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24089 – Memory corruption while processing fastboot commands with invalid input.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24089</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24089</guid>
    <pubDate>Mon, 01 Jun 2026 23:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24089</strong></p>
  <p>Memory corruption while processing fastboot commands with invalid input.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-1286</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24089">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24087 – Memory corruption while processing fastboot OEM commands.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24087</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24087</guid>
    <pubDate>Mon, 01 Jun 2026 23:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24087</strong></p>
  <p>Memory corruption while processing fastboot OEM commands.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-1286</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24087">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24085 – Memory Corruption when processing display command line information due to improp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24085</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24085</guid>
    <pubDate>Mon, 01 Jun 2026 23:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24085</strong></p>
  <p>Memory Corruption when processing display command line information due to improper initialization of a variable.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24085">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-59606 – Memory Corruption when writing to invalid memory locations occurs due to heap me...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59606</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59606</guid>
    <pubDate>Mon, 01 Jun 2026 23:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-59606</strong></p>
  <p>Memory Corruption when writing to invalid memory locations occurs due to heap memory exhaustion during secure data initialization.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59606">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-59605 – Memory Corruption when processing device identifier strings that exceed the expe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59605</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59605</guid>
    <pubDate>Mon, 01 Jun 2026 23:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-59605</strong></p>
  <p>Memory Corruption when processing device identifier strings that exceed the expected maximum length.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59605">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-59604 – Memory Corruption when running a memory copy operation due to invalid writes cau...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59604</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59604</guid>
    <pubDate>Mon, 01 Jun 2026 23:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-59604</strong></p>
  <p>Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59604">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20452 – In wlan AP driver, there is a possible memory corruption due to a heap buffer ov...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20452</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20452</guid>
    <pubDate>Mon, 01 Jun 2026 04:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20452</strong></p>
  <p>In wlan AP driver, there is a possible memory corruption due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00480138; Issue ID: MSV-6295.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20452">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9038 – A stack-based buffer overflow vulnerability in the charging controller’s signal-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9038</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9038</guid>
    <pubDate>Thu, 28 May 2026 20:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9038</strong></p>
  <p>A stack-based buffer overflow vulnerability in the charging controller’s signal-processing logic allows an attacker with physical access to the charging interface to supply message fields that exceed expected bounds. Because the input is not sufficiently validated, memory corruption may occur, which can lead to execution of unauthorized code with elevated privileges.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9038">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46173 – In the Linux kernel, the following vulnerability has been resolved:

exit: preve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46173</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46173</guid>
    <pubDate>Thu, 28 May 2026 10:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46173</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  exit: prevent preemption of oopsing TASK_DEAD task  When an already-exiting task oopses, make_task_dead() currently calls do_task_dead() with preemption enabled.  That is forbidden: do_task_dead() calls __schedule(), which has a comment saying "WARNING: must be called with preemption disabled!".  If an oopsing task is preempted…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46173">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46081 – In the Linux kernel, the following vulnerability has been resolved:

crypto: aco...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46081</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46081</guid>
    <pubDate>Wed, 27 May 2026 14:17:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46081</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  crypto: acomp - fix wrong pointer stored by acomp_save_req()  acomp_save_req() stores &req->chain in req->base.data. When acomp_reqchain_done() is invoked on asynchronous completion, it receives &req->chain as the data argument but casts it directly to struct acomp_req. Since data points to the chain member, all subsequent field…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46081">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5260 – A flaw was found in libgnutls. A remote attacker, by sending an extremely short ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5260</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5260</guid>
    <pubDate>Tue, 26 May 2026 22:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5260</strong></p>
  <p>A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-1284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5260">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44983 – smallbitvec is a growable bit-vector for Rust, optimized for size. From 1.0.1 to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44983</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44983</guid>
    <pubDate>Tue, 26 May 2026 22:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44983</strong></p>
  <p>smallbitvec is a growable bit-vector for Rust, optimized for size. From 1.0.1 to 2.6.0, an integer overflow in the internal capacity calculation of smallbitvec can lead to an undersized heap allocation, resulting in a heap buffer overflow through safe APIs only. This allows memory corruption without requiring unsafe code from the caller. This vulnerability is fixed in 2.6.1.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44983">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7454 – A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7454</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7454</guid>
    <pubDate>Tue, 26 May 2026 18:16:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7454</strong></p>
  <p>A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7454">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7452 – A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7452</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7452</guid>
    <pubDate>Tue, 26 May 2026 18:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7452</strong></p>
  <p>A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7452">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8975 – Memory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8975</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8975</guid>
    <pubDate>Tue, 19 May 2026 14:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8975</strong></p>
  <p>Memory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8975">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8974 – Memory safety bugs present in Firefox ESR 140.10 and Firefox 150. Some of these ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8974</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8974</guid>
    <pubDate>Tue, 19 May 2026 14:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8974</strong></p>
  <p>Memory safety bugs present in Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8974">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8973 – Memory safety bugs present in Firefox 150. Some of these bugs showed evidence of...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8973</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8973</guid>
    <pubDate>Tue, 19 May 2026 14:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8973</strong></p>
  <p>Memory safety bugs present in Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 151 and Thunderbird 151.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8973">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-37239 – libbabl 0.1.62 contains a broken double free detection vulnerability that allows...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37239</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37239</guid>
    <pubDate>Sat, 16 May 2026 16:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-37239</strong></p>
  <p>libbabl 0.1.62 contains a broken double free detection vulnerability that allows attackers to bypass memory safety checks by exploiting signature overwriting in freed chunks. Attackers can call babl_free() twice on the same pointer without triggering detection, as libc's malloc metadata overwrites babl's signature field upon freeing, enabling potential memory corruption and code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-415</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37239">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8696 – radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_pids_list() fu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8696</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8696</guid>
    <pubDate>Fri, 15 May 2026 21:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8696</strong></p>
  <p>radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_pids_list() function within the GDB client core that allows remote attackers to cause a denial of service or potentially execute arbitrary code by sending malformed thread information responses. Attackers can trigger the vulnerability by causing qsThreadInfo to fail after qfThreadInfo successfully allocates RDebugPid structures, re…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8696">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8695 – radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_threads_list()...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8695</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8695</guid>
    <pubDate>Fri, 15 May 2026 17:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8695</strong></p>
  <p>radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_threads_list() function that allows remote attackers to trigger memory corruption by sending a valid qfThreadInfo response followed by a malformed qsThreadInfo response. Attackers can exploit this vulnerability through GDB remote debugging to cause a denial of service or potentially achieve code execution by manipulating thread lis…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8695">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43906 – OpenImageIO is a toolset for reading, writing, and manipulating image files of a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43906</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43906</guid>
    <pubDate>Thu, 14 May 2026 20:17:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43906</strong></p>
  <p>OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, a heap-based buffer overflow in the HEIF decoder of OpenImageIO allows out-of-bounds writes via crafted images due to a subimage metadata mismatch, leading to memory corruption and potential code execution. This vulnerability is fixed in…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43906">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8449 – Linux ksmbd contains a remote memory corruption vulnerability in the ACL inherit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8449</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8449</guid>
    <pubDate>Tue, 12 May 2026 22:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8449</strong></p>
  <p>Linux ksmbd contains a remote memory corruption vulnerability in the ACL inheritance path that allows remote clients with directory creation permissions to trigger a heap out-of-bounds read and subsequent heap corruption by setting a crafted DACL with a malformed SID containing an inflated num_subauth field. Attackers can exploit this vulnerability by creating a directory, setting the malicious D…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8449">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-12659 – The affected applications contains a memory corruption vulnerability while parsi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12659</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12659</guid>
    <pubDate>Tue, 12 May 2026 14:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-12659</strong></p>
  <p>The affected applications contains a memory corruption vulnerability while parsing specially crafted IPT files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-27349, ZDI-CAN-27389)</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12659">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42046 – libcaca is a colour ASCII art library. In 0.99.beta20 and earlier, an integer ov...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42046</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42046</guid>
    <pubDate>Mon, 11 May 2026 22:22:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42046</strong></p>
  <p>libcaca is a colour ASCII art library. In 0.99.beta20 and earlier, an integer overflow vulnerability in libcaca's canvas import functionality allows an attacker to cause a controlled heap out-of-bounds write (heap overflow) by supplying a crafted file in the "caca" format. Depending on the build configuration and memory allocator, this may lead to memory corruption or remote code execution. This…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42046">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-7261 – In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7261</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7261</guid>
    <pubDate>Sun, 10 May 2026 05:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-7261</strong></p>
  <p>In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the case SOAP requests results in an error, the persistance is handled incorrectly, resulting in freeing the object while keeping a pointer to it, which m…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7261">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42311 – Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42311</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42311</guid>
    <pubDate>Sat, 09 May 2026 06:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42311</strong></p>
  <p>Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution. This issue has been patched in version 12.2.0.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42311">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-26522 – The socket connection handler in aswArPot.sys in the Avast and AVG Windows Anti ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-26522</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-26522</guid>
    <pubDate>Fri, 08 May 2026 05:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-26522</strong></p>
  <p>The socket connection handler in aswArPot.sys in the Avast and AVG Windows Anti Rootkit driver before 22.1 allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) due to a double fetch vulnerability at aswArPot+0xc4a3.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-26522">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8093 – Memory safety bugs present in Firefox 150.0.1. Some of these bugs showed evidenc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8093</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8093</guid>
    <pubDate>Thu, 07 May 2026 13:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8093</strong></p>
  <p>Memory safety bugs present in Firefox 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2 and Thunderbird 150.0.2.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8093">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8092 – Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Fir...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8092</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8092</guid>
    <pubDate>Thu, 07 May 2026 13:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8092</strong></p>
  <p>Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8092">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43250 – In the Linux kernel, the following vulnerability has been resolved:

usb: chipid...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43250</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43250</guid>
    <pubDate>Wed, 06 May 2026 12:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43250</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  usb: chipidea: udc: fix DMA and SG cleanup in _ep_nuke()  The ChipIdea UDC driver can encounter "not page aligned sg buffer" errors when a USB device is reconnected after being disconnected during an active transfer. This occurs because _ep_nuke() returns requests to the gadget layer without properly unmapping DMA buffers or cle…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43250">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43150 – In the Linux kernel, the following vulnerability has been resolved:

perf/arm-cm...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43150</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43150</guid>
    <pubDate>Wed, 06 May 2026 12:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43150</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  perf/arm-cmn: Reject unsupported hardware configurations  So far we've been fairly lax about accepting both unknown CMN models (at least with a warning), and unknown revisions of those which we do know, as although things do frequently change between releases, typically enough remains the same to be somewhat useful for at least…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43150">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-29004 – BusyBox before commit 42202bf contains a heap buffer overflow vulnerability in t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29004</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29004</guid>
    <pubDate>Mon, 04 May 2026 18:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-29004</strong></p>
  <p>BusyBox before commit 42202bf contains a heap buffer overflow vulnerability in the DHCPv6 client (udhcpc6) DNS_SERVERS option handler in networking/udhcp/d6_dhcpc.c that allows network-adjacent attackers to trigger memory corruption by sending a crafted DHCPv6 response with a malformed D6_OPT_DNS_SERVERS option. Attackers can exploit incorrect heap buffer allocation calculations in the option_to_…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29004">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24082 – Memory Corruption when copying data from a freed source while executing performa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24082</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24082</guid>
    <pubDate>Mon, 04 May 2026 17:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24082</strong></p>
  <p>Memory Corruption when copying data from a freed source while executing performance counter deselect operation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24082">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-47408 – Memory corruption when another driver calls an IOCTL with invalid input/output b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47408</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47408</guid>
    <pubDate>Mon, 04 May 2026 17:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-47408</strong></p>
  <p>Memory corruption when another driver calls an IOCTL with invalid input/output buffer.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-822</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47408">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-47407 – Memory corruption while creating a process on the digital signal processor due t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47407</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47407</guid>
    <pubDate>Mon, 04 May 2026 17:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-47407</strong></p>
  <p>Memory corruption while creating a process on the digital signal processor due to allocation failure at the kernel level.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47407">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-47405 – Memory corruption when processing camera sensor input/output control codes with ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47405</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47405</guid>
    <pubDate>Mon, 04 May 2026 17:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-47405</strong></p>
  <p>Memory corruption when processing camera sensor input/output control codes with invalid output buffers.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-822</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47405">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33846 – A heap buffer overflow vulnerability exists in the DTLS handshake fragment reass...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33846</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33846</guid>
    <pubDate>Mon, 04 May 2026 10:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33846</strong></p>
  <p>A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending cra…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-130</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33846">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31743 – In the Linux kernel, the following vulnerability has been resolved:

nvmem: zynq...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31743</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31743</guid>
    <pubDate>Fri, 01 May 2026 15:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31743</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  nvmem: zynqmp_nvmem: Fix buffer size in DMA and memcpy  Buffer size used in dma allocation and memcpy is wrong. It can lead to undersized DMA buffer access and possible memory corruption. use correct buffer size in dma_alloc_coherent and memcpy.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31743">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-33447 – CVE-2026-33447 is a buffer overflow in a message parsing function of the
 Secure...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33447</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33447</guid>
    <pubDate>Thu, 30 Apr 2026 20:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-33447</strong></p>
  <p>CVE-2026-33447 is a buffer overflow in a message parsing function of the  Secure Access client prior to 14.50. Attackers with control of a  modified server can send a special packet that can overwrite a small  portion of memory conceivably leading to memory corruption or denial of  service.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33447">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-33446 – CVE-2026-33446 is a buffer overflow in the authentication sub-system of 
the Sec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33446</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33446</guid>
    <pubDate>Thu, 30 Apr 2026 20:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-33446</strong></p>
  <p>CVE-2026-33446 is a buffer overflow in the authentication sub-system of  the Secure Access client prior to 14.50. Attackers with control of a  modified server can send a special packet that can overwrite a small  portion of memory conceivably leading to memory corruption or a denial  of service.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33446">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7426 – Insufficient validation of the prefix length field in IPv6 Router Advertisement ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7426</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7426</guid>
    <pubDate>Wed, 29 Apr 2026 20:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7426</strong></p>
  <p>Insufficient validation of the prefix length field in IPv6 Router Advertisement processing in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to cause memory corruption by sending a crafted Router Advertisement with a prefix length value exceeding the maximum valid length, resulting in a heap buffer overflow. Users processing IPv4 RA only are not impacted.    To mitiga…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7426">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7111 – Text::CSV_XS versions before 1.62 for Perl have a use-after-free when registered...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7111</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7111</guid>
    <pubDate>Wed, 29 Apr 2026 15:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7111</strong></p>
  <p>Text::CSV_XS versions before 1.62 for Perl have a use-after-free when registered callbacks extend the Perl argument stack, which may enable type confusion or memory corruption.  The Parse, print, getline, and getline_all methods invoke registered callbacks (for example after_parse, before_print, or on_error) and cache the Perl argument stack pointer across the call. If a callback extends the argu…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7111">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7324 – Memory safety bugs present in Thunderbird 150.0.0. Some of these bugs showed evi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7324</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7324</guid>
    <pubDate>Tue, 28 Apr 2026 15:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7324</strong></p>
  <p>Memory safety bugs present in Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1 and Thunderbird 150.0.1.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7324">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7323 – Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7323</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7323</guid>
    <pubDate>Tue, 28 Apr 2026 15:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7323</strong></p>
  <p>Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Thunderbird 150.0.1, and Thunderbird 140.10.1.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7323">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7322 – Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7322</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7322</guid>
    <pubDate>Tue, 28 Apr 2026 15:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7322</strong></p>
  <p>Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Firefox ESR 115.35.1, Thunderbird 150.0.1, and Thunderbird 140.10.1.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7322">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6786 – Memory safety bugs present in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6786</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6786</guid>
    <pubDate>Sun, 26 Apr 2026 19:53:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6786</strong></p>
  <p>Memory safety bugs present in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6786">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6785 – Memory safety bugs present in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6785</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6785</guid>
    <pubDate>Sun, 26 Apr 2026 19:53:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6785</strong></p>
  <p>Memory safety bugs present in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbir…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6785">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41429 – arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ES...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41429</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41429</guid>
    <pubDate>Fri, 24 Apr 2026 20:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41429</strong></p>
  <p>arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, there is a remotely reachable memory corruption issue in the NBNS packet handling path. When NetBIOS is enabled by calling NBNS.begin(...), the device listens on UDP port 137 and processes untrusted NBNS requests from the local network. The request parser trusts th…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41429">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41416 – PJSIP is a free and open source multimedia communication library written in C. I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41416</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41416</guid>
    <pubDate>Fri, 24 Apr 2026 19:17:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41416</strong></p>
  <p>PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an integer overflow in media stream buffer size calculation when processing SDP with asymmetric ptime configuration. The overflow may result in an undersized buffer allocation, which can lead to unexpected application termination or memory corruption This vulnerability is fixed in 2.17.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41416">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-31649 – In the Linux kernel, the following vulnerability has been resolved:

net: stmmac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31649</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31649</guid>
    <pubDate>Fri, 24 Apr 2026 15:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-31649</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  net: stmmac: fix integer underflow in chain mode  The jumbo_frm() chain-mode implementation unconditionally computes      len = nopaged_len - bmax;  where nopaged_len = skb_headlen(skb) (linear bytes only) and bmax is BUF_SIZE_8KiB or BUF_SIZE_2KiB.  However, the caller stmmac_xmit() decides to invoke jumbo_frm() based on skb->l…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31649">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34001 – A flaw was found in the X.Org X server. This use-after-free vulnerability occurs...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34001</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34001</guid>
    <pubDate>Thu, 23 Apr 2026 16:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34001</strong></p>
  <p>A flaw was found in the X.Org X server. This use-after-free vulnerability occurs in the XSYNC fence triggering logic, specifically within the miSyncTriggerFence() function. An attacker with access to the X11 server can exploit this without user interaction, leading to a server crash and potentially enabling memory corruption. This could result in a denial of service or further compromise of the s…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-825</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34001">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31530 – In the Linux kernel, the following vulnerability has been resolved:

cxl/port: F...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31530</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31530</guid>
    <pubDate>Wed, 22 Apr 2026 14:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31530</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  cxl/port: Fix use after free of parent_port in cxl_detach_ep()  cxl_detach_ep() is called during bottom-up removal when all CXL memory devices beneath a switch port have been removed. For each port in the hierarchy it locks both the port and its parent, removes the endpoint, and if the port is now empty, marks it dead and unregi…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31530">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31433 – In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31433</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31433</guid>
    <pubDate>Wed, 22 Apr 2026 09:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31433</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ksmbd: fix potencial OOB in get_file_all_info() for compound requests  When a compound request consists of QUERY_DIRECTORY + QUERY_INFO (FILE_ALL_INFORMATION) and the first command consumes nearly the entire max_trans_size, get_file_all_info() would blindly call smbConvertToUTF16() with PATH_MAX, causing out-of-bounds write beyo…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31433">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6784 – Memory safety bugs present in Firefox 149 and Thunderbird 149. Some of these bug...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6784</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6784</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6784</strong></p>
  <p>Memory safety bugs present in Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150 and Thunderbird 150.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6784">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32623 – xrdp is an open source RDP server. Versions through 0.10.5 contain a heap-based ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32623</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32623</guid>
    <pubDate>Fri, 17 Apr 2026 20:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32623</strong></p>
  <p>xrdp is an open source RDP server. Versions through 0.10.5 contain a heap-based buffer overflow vulnerability in the NeutrinoRDP module. When proxying RDP sessions from xrdp to another server, the module fails to properly validate the size of reassembled fragmented virtual channel data against its allocated memory buffer. A malicious downstream RDP server (or an attacker capable of performing a M…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32623">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6507 – A flaw was found in dnsmasq. A remote attacker could exploit an out-of-bounds wr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6507</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6507</guid>
    <pubDate>Fri, 17 Apr 2026 13:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6507</strong></p>
  <p>A flaw was found in dnsmasq. A remote attacker could exploit an out-of-bounds write vulnerability by sending a specially crafted BOOTREPLY (Bootstrap Protocol Reply) packet to a dnsmasq server configured with the `--dhcp-split-relay` option. This can lead to memory corruption, causing the dnsmasq daemon to crash and resulting in a denial of service (DoS).</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6507">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-27820 – zlib is a Ruby interface for the zlib compression/decompression library. Version...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27820</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27820</guid>
    <pubDate>Thu, 16 Apr 2026 18:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-27820</strong></p>
  <p>zlib is a Ruby interface for the zlib compression/decompression library. Versions 3.0.0 and below, 3.1.0, 3.1.1, 3.2.0 and 3.2.1 contain a buffer overflow vulnerability in the Zlib::GzipReader. The zstream_buffer_ungets function prepends caller-provided bytes ahead of previously produced output but fails to guarantee the backing Ruby string has enough capacity before the memmove shifts the existi…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27820">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33023 – libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33023</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33023</guid>
    <pubDate>Tue, 14 Apr 2026 23:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33023</strong></p>
  <p>libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. In versions 1.8.7 and prior, when built with the --with-gdk-pixbuf2 option, a use-after-free vulnerability exists in load_with_gdkpixbuf() in loader.c. The cleanup path manually frees the sixel_frame_t object and its internal buffers without consulting the reference count, even though the object was created via the ref…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33023">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40200 – An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40200</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40200</guid>
    <pubDate>Fri, 10 Apr 2026 17:17:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40200</strong></p>
  <p>An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur during qsort of very large arrays, due to incorrectly implemented double-word primitives. The number of elements must exceed about seven million, i.e., the 32nd Leonardo number on 32-bit platforms (or the 64th Leonardo number on 64-bit platforms, which is not practical).</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-670</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40200">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27144 – The compiler is meant to unwrap pointers which are the operands of a memory move...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27144</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27144</guid>
    <pubDate>Wed, 08 Apr 2026 02:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27144</strong></p>
  <p>The compiler is meant to unwrap pointers which are the operands of a memory move; a no-op interface conversion prevented the compiler from making the correct determination about non-overlapping moves, potentially leading to memory corruption at runtime.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-843</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27144">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-27143 – Arithmetic over induction variables in loops were not correctly checked for unde...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27143</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27143</guid>
    <pubDate>Wed, 08 Apr 2026 02:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-27143</strong></p>
  <p>Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid indexing to occur at runtime, potentially leading to memory corruption.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27143">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32864 – There is a memory corruption vulnerability due to an out-of-bounds read in mgcor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32864</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32864</guid>
    <pubDate>Tue, 07 Apr 2026 20:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32864</strong></p>
  <p>There is a memory corruption vulnerability due to an out-of-bounds read in mgcore_SH_25_3!aligned_free() in NI LabVIEW.  This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI file. This vulnerability affects NI LabVIEW 2026 Q1 (26.1.0) and prior versions.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32864">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32863 – There is a memory corruption vulnerability due to an out-of-bounds read in sentr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32863</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32863</guid>
    <pubDate>Tue, 07 Apr 2026 20:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32863</strong></p>
  <p>There is a memory corruption vulnerability due to an out-of-bounds read in sentry_transaction_context_set_operation() in NI LabVIEW.  This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI file. This vulnerability affects NI LabVIEW 2026 Q1 (26.1.0) and prior versions.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32863">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32862 – There is a memory corruption vulnerability due to an out-of-bounds write in ResF...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32862</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32862</guid>
    <pubDate>Tue, 07 Apr 2026 20:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32862</strong></p>
  <p>There is a memory corruption vulnerability due to an out-of-bounds write in ResFileFactory::InitResourceMgr() in NI LabVIEW.  This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI file. This vulnerability affects NI LabVIEW 2026 Q1 (26.1.0) and prior versions.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32862">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32861 – There is a memory corruption vulnerability due to an out-of-bounds write when lo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32861</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32861</guid>
    <pubDate>Tue, 07 Apr 2026 20:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32861</strong></p>
  <p>There is a memory corruption vulnerability due to an out-of-bounds write when loading a corrupted LVCLASS file in NI LabVIEW.  This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted .lvclass file. This vulnerability affects NI LabVIEW 2026 Q1 (26.1.0) and prior versions.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32861">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32860 – There is a memory corruption vulnerability due to an out-of-bounds write when lo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32860</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32860</guid>
    <pubDate>Tue, 07 Apr 2026 20:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32860</strong></p>
  <p>There is a memory corruption vulnerability due to an out-of-bounds write when loading a corrupted LVLIB file in NI LabVIEW.  This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted .lvlib file. This vulnerability affects NI LabVIEW 2026 Q1 (26.1.0) and prior versions.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32860">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-5735 – Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5735</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5735</guid>
    <pubDate>Tue, 07 Apr 2026 13:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-5735</strong></p>
  <p>Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149.0.2 and Thunderbird 149.0.2.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5735">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-5734 – Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Fire...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5734</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5734</guid>
    <pubDate>Tue, 07 Apr 2026 13:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-5734</strong></p>
  <p>Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149.0.2, Firefox ESR 140.9.1, Thunderbird 149.0.2, and Thunderbird 140.9.1.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5734">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-5731 – Memory safety bugs present in Firefox ESR 115.34.0, Firefox ESR 140.9.0, Thunder...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5731</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5731</guid>
    <pubDate>Tue, 07 Apr 2026 13:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-5731</strong></p>
  <p>Memory safety bugs present in Firefox ESR 115.34.0, Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149.0.2, Firefox ESR 115.34.1, Firefox ESR 140.9.1, Thunderbir…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5731">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-21382 – Memory Corruption when handling power management requests with improperly sized ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21382</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21382</guid>
    <pubDate>Mon, 06 Apr 2026 16:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-21382</strong></p>
  <p>Memory Corruption when handling power management requests with improperly sized input/output buffers.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21382">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-21380 – Memory Corruption when using deprecated DMABUF IOCTL calls to manage video memor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21380</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21380</guid>
    <pubDate>Mon, 06 Apr 2026 16:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-21380</strong></p>
  <p>Memory Corruption when using deprecated DMABUF IOCTL calls to manage video memory.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21380">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-21378 – Memory Corruption when accessing an output buffer without validating its size du...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21378</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21378</guid>
    <pubDate>Mon, 06 Apr 2026 16:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-21378</strong></p>
  <p>Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-126</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21378">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-21376 – Memory Corruption when accessing an output buffer without validating its size du...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21376</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21376</guid>
    <pubDate>Mon, 06 Apr 2026 16:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-21376</strong></p>
  <p>Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-126</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21376">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-21375 – Memory Corruption when accessing an output buffer without validating its size du...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21375</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21375</guid>
    <pubDate>Mon, 06 Apr 2026 16:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-21375</strong></p>
  <p>Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-126</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21375">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-21374 – Memory Corruption when processing auxiliary sensor input/output control commands...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21374</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21374</guid>
    <pubDate>Mon, 06 Apr 2026 16:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-21374</strong></p>
  <p>Memory Corruption when processing auxiliary sensor input/output control commands with insufficient buffer size validation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-126</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21374">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-21373 – Memory Corruption when accessing an output buffer without validating its size du...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21373</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21373</guid>
    <pubDate>Mon, 06 Apr 2026 16:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-21373</strong></p>
  <p>Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-126</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21373">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-21372 – Memory Corruption when sending IOCTL requests with invalid buffer sizes during m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21372</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21372</guid>
    <pubDate>Mon, 06 Apr 2026 16:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-21372</strong></p>
  <p>Memory Corruption when sending IOCTL requests with invalid buffer sizes during memcpy operations.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21372">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-21371 – Memory Corruption when retrieving output buffer with insufficient size validatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21371</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21371</guid>
    <pubDate>Mon, 06 Apr 2026 16:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-21371</strong></p>
  <p>Memory Corruption when retrieving output buffer with insufficient size validation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-126</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21371">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-47392 – Memory corruption when decoding corrupted satellite data files with invalid sign...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47392</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47392</guid>
    <pubDate>Mon, 06 Apr 2026 16:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-47392</strong></p>
  <p>Memory corruption when decoding corrupted satellite data files with invalid signature offsets.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47392">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-47391 – Memory corruption while processing a frame request from user.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47391</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47391</guid>
    <pubDate>Mon, 06 Apr 2026 16:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-47391</strong></p>
  <p>Memory corruption while processing a frame request from user.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47391">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-47390 – Memory corruption while preprocessing IOCTL request in JPEG driver.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47390</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47390</guid>
    <pubDate>Mon, 06 Apr 2026 16:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-47390</strong></p>
  <p>Memory corruption while preprocessing IOCTL request in JPEG driver.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-126</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47390">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-47389 – Memory corruption when buffer copy operation fails due to integer overflow durin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47389</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47389</guid>
    <pubDate>Mon, 06 Apr 2026 16:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-47389</strong></p>
  <p>Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47389">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34774 – Electron is a framework for writing cross-platform desktop applications using Ja...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34774</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34774</guid>
    <pubDate>Sat, 04 Apr 2026 00:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34774</strong></p>
  <p>Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 39.8.1, 40.7.0, and 41.0.0, apps that use offscreen rendering and allow child windows via window.open() may be vulnerable to a use-after-free. If the parent offscreen WebContents is destroyed while a child window remains open, subsequent paint frames on the child dereference f…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34774">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34771 – Electron is a framework for writing cross-platform desktop applications using Ja...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34771</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34771</guid>
    <pubDate>Sat, 04 Apr 2026 00:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34771</strong></p>
  <p>Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, apps that register an asynchronous session.setPermissionRequestHandler() may be vulnerable to a use-after-free when handling fullscreen, pointer-lock, or keyboard-lock permission requests. If the requesting frame navigates or the wind…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34771">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34770 – Electron is a framework for writing cross-platform desktop applications using Ja...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34770</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34770</guid>
    <pubDate>Sat, 04 Apr 2026 00:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34770</strong></p>
  <p>Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, apps that use the powerMonitor module may be vulnerable to a use-after-free. After the native PowerMonitor object is garbage-collected, the associated OS-level resources (a message window on Windows, a shutdown handler on macOS) retai…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34770">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31395 – In the Linux kernel, the following vulnerability has been resolved:

bnxt_en: fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31395</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31395</guid>
    <pubDate>Fri, 03 Apr 2026 16:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31395</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  bnxt_en: fix OOB access in DBG_BUF_PRODUCER async event handler  The ASYNC_EVENT_CMPL_EVENT_ID_DBG_BUF_PRODUCER handler in bnxt_async_event_process() uses a firmware-supplied 'type' field directly as an index into bp->bs_trace[] without bounds validation.  The 'type' field is a 16-bit value extracted from DMA-mapped completion r…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31395">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-43202 – This issue was addressed with improved memory handling. This issue is fixed in i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43202</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43202</guid>
    <pubDate>Thu, 02 Apr 2026 19:20:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-43202</strong></p>
  <p>This issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6. Processing a file may lead to memory corruption.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43202">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-34877 – An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34877</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34877</guid>
    <pubDate>Thu, 02 Apr 2026 17:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-34877</strong></p>
  <p>An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of serialized SSL context or session structures allows an attacker who can modify the serialized structures to induce memory corruption, leading to arbitrary code execution. This is caused by Incorrect Use of Privileged APIs.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34877">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5190 – Out-of-bounds write in the streaming decoder component in aws-c-event-stream bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5190</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5190</guid>
    <pubDate>Tue, 31 Mar 2026 18:16:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5190</strong></p>
  <p>Out-of-bounds write in the streaming decoder component in aws-c-event-stream before 0.6.0 might allow a third party operating a server to cause memory corruption leading to arbitrary code execution on a client application that processes crafted event-stream messages.  To remediate this issue, users should upgrade to version 0.6.0 or later.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5190">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33009 – EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a dat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33009</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33009</guid>
    <pubDate>Thu, 26 Mar 2026 17:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33009</strong></p>
  <p>EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to C++ UB (potential memory corruption). This is triggered by an MQTT `everest_external/nodered/{connector}/cmd/switch_three_phases_while_charging` message and results in `Charger::shared_context` / `internal_context` accessed concurrently without lock. Version 2026.02.0 contains a patch.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33009">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26008 – EVerest is an EV charging software stack. Versions prior to 2026.02.0 have an ou...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26008</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26008</guid>
    <pubDate>Thu, 26 Mar 2026 15:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26008</strong></p>
  <p>EVerest is an EV charging software stack. Versions prior to 2026.02.0 have an out-of-bounds access (std::vector) that leads to possible remote crash/memory corruption. This is because the CSMS sends UpdateAllowedEnergyTransferModes over the network. Version 2026.2.0 contains a patch.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26008">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23343 – In the Linux kernel, the following vulnerability has been resolved:

xdp: produc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23343</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23343</guid>
    <pubDate>Wed, 25 Mar 2026 11:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23343</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  xdp: produce a warning when calculated tailroom is negative  Many ethernet drivers report xdp Rx queue frag size as being the same as DMA write size. However, the only user of this field, namely bpf_xdp_frags_increase_tail(), clearly expects a truesize.  Such difference leads to unspecific memory corruption issues under certain…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23343">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23288 – In the Linux kernel, the following vulnerability has been resolved:

accel/amdxd...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23288</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23288</guid>
    <pubDate>Wed, 25 Mar 2026 11:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23288</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  accel/amdxdna: Fix out-of-bounds memset in command slot handling  The remaining space in a command slot may be smaller than the size of the command header. Clearing the command header with memset() before verifying the available slot space can result in an out-of-bounds write and memory corruption.  Fix this by moving the memset…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23288">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
