🎯 CVE-2017-5400 CRITICAL 9.8 🔥 EPSS 67.9%
📄 .md Alle CVEs anzeigen ✕

CVE-2017-5400: Schwachstellen-Eintrag (NVD)

JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.

Klassifikation & Betroffenheit:
redhat enterprise_linux_desktop 5.0redhat enterprise_linux_desktop 6.0redhat enterprise_linux_desktop 7.0redhat enterprise_linux_server 5.0redhat enterprise_linux_server 6.0redhat enterprise_linux_server 7.0redhat enterprise_linux_server_aus 7.3redhat enterprise_linux_server_aus 7.4
Improper Restriction of Operations within the Bounds of a Memory Buffer 🎯 High

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

🛡️ Empfohlene Mitigation: Use a language that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid. For example, many languages that perform their own memory management, such as Java and Perl, are not subject to buffer overflows. Other languages, such as Ada and C#, typically provide overflow prot…
Vollständige Definition bei MITRE ➔
📚 Referenzen & Quellen:
Ausnutzungs-Zeitleiste:
CVSS-Vektor-Analyse: 9.8
AV · Angriffsvektor Netzwerk
AC · Komplexität Gering
PR · Privilegien Keine
UI · Interaktion Keine
S · Scope Unverändert
C · Vertraulichkeit Hoch
I · Integrität Hoch
A · Verfügbarkeit Hoch
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Veröffentlicht:11.06.2018
Aktualisiert:17.06.2026 01:20
Assigner (CNA):NVD
Quellen: 🇪🇺 EUVD-Datenbank (ENISA) + 🇺🇸 NVD-Anreicherung · 24-h-Cache
CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

354k+ 🇪🇺 EUVD-Datenbank
4 🔴 Critical im Radar
3 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
0 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-09: 164 2025-10: 316 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 418 2026-03: 652 2026-04: 574 2026-05: 683 2026-06: 942 2026-07: 1333 2026-08: 1329 7.525 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-08-292026-09-13
≥90 %40
≥50 %40
≥10 %30
<10 %304300
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Schweregrad & Status:
Hersteller (Datenbank-weit, 90.597 Einträge):
Quelle:
🔍
5.8 MEDIUM
EPSS 4.6%
CVE-2023-24288 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2023-24288 | Simon Tatham Portable Puzzle Collection denial of service (EUVD-2023-60646)

A vulnerability was found in Simon Tatham Portable Puzzle Collection. It has been rated as problematic. This affects an unknown function. Performing a manipulation results in denial of service. This vulnerability is cataloged as CVE-2023-24

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.1%
CVE-2023-24291 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2023-24291 | Simon Tatham Portable Puzzle Collection record length parameter buffer overflow (EUVD-2023-60647)

A vulnerability was found in Simon Tatham Portable Puzzle Collection. It has been declared as problematic. The impacted element is an unknown function. Such manipulation of the argument record length parameter leads to buffer overflow. This

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.7%
CVE-2023-24287 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2023-24287 | Simon Tatham Portable Puzzle Collection buffer overflow (EUVD-2023-60645)

A vulnerability was found in Simon Tatham Portable Puzzle Collection. It has been classified as problematic. The affected element is an unknown function. This manipulation causes buffer overflow. This vulnerability is tracked as CVE-2023-24

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.5%
CVE-2023-24286 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2023-24286 | Simon Tatham Portable Puzzle Collection game description buffer overflow (EUVD-2023-60644)

A vulnerability was found in Simon Tatham Portable Puzzle Collection and classified as problematic. Impacted is an unknown function. The manipulation of the argument game description results in buffer overflow. This vulnerability is identif

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.2%
CVE-2023-32778 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2023-32778 | ILIAS up to 6.23/7.21/8.1 unrestricted upload (EUVD-2023-60650)

A vulnerability, which was classified as problematic, was found in ILIAS up to 6.23/7.21/8.1. The affected element is an unknown function. The manipulation results in unrestricted upload. This vulnerability was named CVE-2023-32778. The att

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.3%
CVE-2023-28148 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2023-28148 | Paessler PRTG Network Monitor up to 23.2.83.1760 cross site scripting (EUVD-2023-60648)

A vulnerability categorized as problematic has been discovered in Paessler PRTG Network Monitor up to 23.2.83.1760. This impacts an unknown function. Executing a manipulation can lead to cross site scripting. This vulnerability is registere

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.6%
CVE-2023-29377 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2023-29377 | Softing Secure Integration Server path traversal (ZDI-23-1055 / EUVD-2023-60649)

A vulnerability was found in Softing Secure Integration Server. It has been classified as critical. This vulnerability affects unknown code. Performing a manipulation results in path traversal. This vulnerability is known as CVE-2023-29377.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.2%
CVE-2023-34854 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2023-34854 | Digital Druid HotelDruid up to 3.0.5 Backup/Restore backup/restore unrestricted upload (EUVD-2023-60662)

A vulnerability was found in Digital Druid HotelDruid up to 3.0.5. It has been classified as problematic. This impacts the function backup/restore of the component Backup/Restore. Performing a manipulation results in unrestricted upload. Th

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.1%
CVE-2023-37252 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2023-37252 | MediaWiki CheckUser Extension up to 1.35.10/1.38.6/1.39.3 access control (EUVD-2023-60663)

A vulnerability was found in MediaWiki CheckUser Extension up to 1.35.10/1.38.6/1.39.3 and classified as problematic. This affects an unknown function of the component CheckUser. Such manipulation leads to improper access controls. This vul

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.6%
CVE-2023-32803 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2023-32803 | Amazon Linux AMI CA-Certificate certificate validation (EUVD-2023-60651)

A vulnerability was found in Amazon Linux AMI and classified as critical. This vulnerability affects unknown code of the component CA-Certificate Handler. Such manipulation leads to improper certificate validation. This vulnerability is tra

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
5.8 MEDIUM
EPSS 4.1%
CVE-2023-37253 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2023-37253 | MediaWiki ProofreadPage Extension up to 1.35.10/1.38.6/1.39.3 information disclosure (EUVD-2023-60664)

A vulnerability classified as problematic has been found in MediaWiki ProofreadPage Extension up to 1.35.10/1.38.6/1.39.3. The affected element is an unknown function. The manipulation leads to information disclosure. This vulnerability is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.5%
CVE-2026-90680 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90680 | D-Link DIR-823G 1.0.2B05_20181207 HNAP1 SetStaticRouteSettings strcpy PAddress/SubnetMask/Gateway stack-based overflow (EUVD-2026-77191)

A vulnerability described as very critical has been identified in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is the function strcpy of the file /HNAP1/SetStaticRouteSettings of the component HNAP1. The manipulation of the argum

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.3%
CVE-2026-89637 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89637 | Linux Kernel up to 6.18.50/7.2.3 SMB Client cifs_check_trans2 use after free (Nessus ID 345354)

A vulnerability has been found in Linux Kernel up to 6.18.50/7.2.3 and classified as very critical. Impacted is the function cifs_check_trans2 of the component SMB Client. This manipulation causes use after free. The identification of this

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 20.4%
CVE-2026-89671 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89671 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 NFSv3 ACL Decoder nfsd3_proc_setacl mask/acl_access/acl_default null pointer dereference (Nessus ID 345353)

A vulnerability was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3 and classified as very critical. This vulnerability affects the function nfsd3_proc_setacl of the component NFSv3 ACL Decoder. The manipulation of the argument mask/acl_

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 18.8%
CVE-2026-89626 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89626 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 Sysfs Group Cleanup hid_sensor_custom_add_attributes use after free (Nessus ID 345355)

A vulnerability was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. It has been classified as very critical. This affects the function hid_sensor_custom_add_attributes of the component Sysfs Group Cleanup. This manipulation causes use a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 28.3%
CVE-2026-89495 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89495 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 ocfs2 dlm_migrate_request_handler namelen/lockname_len/num_locks out-of-bounds write (Nessus ID 345356)

A vulnerability was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3 and classified as very critical. The impacted element is the function dlm_migrate_request_handler of the component ocfs2. The manipulation of the argument namelen/lockna

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 24.6%
CVE-2026-87020 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-87020 | Orthanc DICOM Server up to 1.12.x integer overflow (Nessus ID 345560)

A vulnerability categorized as problematic has been discovered in Orthanc DICOM Server up to 1.12.x. This vulnerability affects unknown code. The manipulation results in integer overflow. This vulnerability was named CVE-2026-87020. The att

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.6%
CVE-2023-45858 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2023-45858 | Paessler PRTG Network Monitor up to 23.3.86.1520 path traversal (EUVD-2023-60668)

A vulnerability was found in Paessler PRTG Network Monitor up to 23.3.86.1520. It has been classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to path traversal. This vulnerability is refe

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.4%
CVE-2023-37366 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2023-37366 | Samsung Exynos infinite loop (EUVD-2023-60665)

A vulnerability described as critical has been identified in Samsung Exynos. Impacted is an unknown function. Executing a manipulation can lead to infinite loop. This vulnerability appears as CVE-2023-37366. The attack requires local access

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.3%
CVE-2026-90681 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90681 | Matthias-Wandel jhead up to 3.3 EXIF Parsing exif.c Get16u out-of-bounds (Issue 98 / EUVD-2026-77197)

A vulnerability classified as problematic has been found in Matthias-Wandel jhead up to 3.3. This affects the function Get16u of the file exif.c of the component EXIF Parsing. This manipulation causes out-of-bounds read. This vulnerability

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20%
CVE-2023-46273 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2023-46273 | Extreme Networks IQ Engine up to 10.6r4 Bonjour Gateway ah_event_send buffer overflow (EUVD-2023-60670)

A vulnerability was found in Extreme Networks IQ Engine up to 10.6r4. It has been declared as very critical. This affects the function ah_event_send of the component Bonjour Gateway. The manipulation results in buffer overflow. This vulnera

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.5%
CVE-2026-90682 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90682 | Matthias-Wandel jhead up to 3.3 WebP EXIF gpsinfo.c ProcessGpsInfo TAG_GPS_LAT/TAG_GPS_LONG heap-based overflow (Issue 99 / EUVD-2026-77198)

A vulnerability classified as problematic was found in Matthias-Wandel jhead up to 3.3. This impacts the function ProcessGpsInfo of the file gpsinfo.c of the component WebP EXIF Handler. Such manipulation of the argument TAG_GPS_LAT/TAG_GPS

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.2%
CVE-2026-16726 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-16726 | Panasonic PANATERM/RTEX LogReader USB Driver buffer overflow (EUVD-2026-77207)

A vulnerability was found in Panasonic PANATERM and RTEX LogReader. It has been rated as critical. This vulnerability affects unknown code of the component USB Driver. This manipulation causes buffer overflow. This vulnerability is tracked

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.8%
CVE-2026-90686 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90686 | GPAC up to f1219cde MP4Box loader_bt.c gf_bt_report memory corruption (Issue 3798 / EUVD-2026-77205)

A vulnerability was found in GPAC up to f1219cde and classified as problematic. This affects the function gf_bt_report of the file scene_manager/loader_bt.c of the component MP4Box. The manipulation results in memory corruption. This vulner

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.8%
CVE-2026-90684 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90684 | GPAC up to f1219cde MP4Box base_scenegraph.c gf_node_get_field_count assertion (Issue 3824 / EUVD-2026-77203)

A vulnerability, which was classified as problematic, was found in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field_count of the file scenegraph/base_scenegraph.c of the component MP4Box. Executing a man

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.9%
CVE-2026-90683 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90683 | GPAC up to f1219cde MP4Box base_scenegraph.c gf_node_unregister assertion (Issue 3823 / EUVD-2026-77199)

A vulnerability, which was classified as problematic, has been found in GPAC up to f1219cde. Affected is the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. Performing a manipulation results in

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.6%
CVE-2026-90687 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90687 | GPAC up to f1219cde MP4Box base_scenegraph.c gf_node_changed_internal use after free (Issue 3800 / EUVD-2026-77206)

A vulnerability was found in GPAC up to f1219cde. It has been classified as critical. This vulnerability affects the function gf_node_changed_internal of the file scenegraph/base_scenegraph.c of the component MP4Box. This manipulation cause

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21%
CVE-2026-90685 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90685 | GPAC up to f1219cde MP4Box laser/lsr_dec.c lsr_exec_command_list assertion (Issue 3825 / EUVD-2026-77204)

A vulnerability has been found in GPAC up to f1219cde and classified as problematic. Affected by this issue is the function lsr_exec_command_list of the file laser/lsr_dec.c of the component MP4Box. The manipulation leads to reachable asser

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.3%
CVE-2026-85152 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-85152 | OpenJS Foundation Undici up to 8.10.1 Cache cross-domain policy

A vulnerability was found in OpenJS Foundation Undici up to 8.10.1. It has been rated as problematic. This affects an unknown function of the component Cache. The manipulation leads to permissive cross-domain policy with untrusted domains.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.1%
CVE-2026-89468 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89468 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 lp8788-charger lp8788-charger.c lp8788_charger_remove use after free (Nessus ID 345358)

A vulnerability classified as very critical was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. This affects the function lp8788_charger_remove of the file lp8788-charger.c of the component lp8788-charger. Executing a manipulation can l

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 23%
CVE-2026-89715 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89715 | Linux Kernel up to 6.18.49/7.2.3 localio nfs_open_local_fh nf_net allocation of resources (Nessus ID 345357)

A vulnerability labeled as critical has been found in Linux Kernel up to 6.18.49/7.2.3. The impacted element is the function nfs_open_local_fh of the component localio. The manipulation of the argument nf_net results in allocation of resour

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
5.8 MEDIUM
EPSS 2.5%
CVE-2026-89707 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89707 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 nfsd nfsd_cross_mnt denial of service (Nessus ID 345361)

A vulnerability identified as critical has been detected in Linux Kernel up to 6.12.108/6.18.49/7.2.3. The affected element is the function nfsd_cross_mnt of the component nfsd. The manipulation leads to denial of service. This vulnerabilit

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 26.9%
CVE-2026-80993 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-80993 | Linux Kernel up to 6.18.49/7.2.3 phylink phylink_inband_caps null pointer dereference (Nessus ID 345360)

A vulnerability was found in Linux Kernel up to 6.18.49/7.2.3. It has been classified as critical. The affected element is the function phylink_inband_caps of the component phylink. Performing a manipulation results in null pointer derefere

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 20.2%
CVE-2026-89729 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89729 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 Sensor Hub sensor_hub_get_feature out-of-bounds write (Nessus ID 345359)

A vulnerability described as very critical has been identified in Linux Kernel up to 6.12.108/6.18.49/7.2.3. Affected by this issue is the function sensor_hub_get_feature of the component Sensor Hub. Executing a manipulation can lead to out

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 21%
CVE-2026-89557 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89557 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 Badblocks block/badblocks.c super_1_load bblog_shift buffer overflow (Nessus ID 345363)

A vulnerability, which was classified as very critical, has been found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. Affected by this issue is the function super_1_load of the file block/badblocks.c of the component Badblocks. This manipula

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
5.8 MEDIUM
EPSS 6.6%
CVE-2026-89645 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89645 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 btrfs btrfs_recover_relocation denial of service (Nessus ID 345364)

A vulnerability categorized as problematic has been discovered in Linux Kernel up to 6.12.108/6.18.49/7.2.3. Affected by this issue is the function btrfs_recover_relocation of the component btrfs. The manipulation results in denial of servi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 30%
CVE-2026-18369 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-18369 | Red Hat Certificate System/Enterprise Linux ACME responder server-side request forgery (EUVD-2026-51078)

A vulnerability marked as problematic has been reported in Red Hat Certificate System and Enterprise Linux. The impacted element is an unknown function of the component ACME responder. This manipulation causes server-side request forgery. T

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 30.9%
CVE-2026-47883 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
VMware

CVE-2026-47883 | VMware Spring Framework up to 7.0.8/6.2.19 UrlHandlerFilter redirect (Nessus ID 341190 / WID-SEC-2026-2955)

A vulnerability was found in VMware Spring Framework up to 7.0.8/6.2.19 and classified as problematic. This issue affects some unknown processing of the component UrlHandlerFilter. Such manipulation leads to open redirect. This vulnerabilit

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28%
CVE-2026-47878 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-47878 | Spring Batch up to 5.2.6/6.0.4 DefaultExecutionContextSerializer ObjectInputStream.readObject deserialization

A vulnerability, which was classified as critical, was found in Spring Batch up to 5.2.6/6.0.4. This affects the function ObjectInputStream.readObject of the component DefaultExecutionContextSerializer. The manipulation results in deseriali

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.8%
CVE-2026-47886 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
VMware

CVE-2026-47886 | VMware Spring Framework up to 7.0.8 resource consumption (Nessus ID 341189 / WID-SEC-2026-2955)

A vulnerability labeled as problematic has been found in VMware Spring Framework up to 7.0.8. The impacted element is an unknown function. The manipulation results in resource consumption. This vulnerability is cataloged as CVE-2026-47886.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19%
CVE-2026-47884 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-47884 | Spring Framework up to 7.0.8 XsltView path traversal (WID-SEC-2026-2955)

A vulnerability identified as critical has been detected in Spring Framework up to 7.0.8. The affected element is an unknown function of the component XsltView. The manipulation leads to path traversal. This vulnerability is listed as CVE-2

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.6%
CVE-2026-47879 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
VMware

CVE-2026-47879 | VMware Spring Cloud Gateway up to 3.1.13/4.2.9/4.3.5/5.0.2 server-side request forgery (WID-SEC-2026-2952)

A vulnerability categorized as problematic has been discovered in VMware Spring Cloud Gateway up to 3.1.13/4.2.9/4.3.5/5.0.2. Impacted is an unknown function. Executing a manipulation can lead to server-side request forgery. This vulnerabil

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.4%
CVE-2026-47885 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-47885 | Spring Framework up to 6.1.28/6.2.19/7.0.8 PartEventHttpMessageReader allocation of resources (Nessus ID 341187 / WID-SEC-2026-2955)

A vulnerability was found in Spring Framework up to 6.1.28/6.2.19/7.0.8 and classified as problematic. Affected by this issue is some unknown functionality of the component PartEventHttpMessageReader. The manipulation results in allocation

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 6.8%
CVE-2026-89490 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89490 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 ocfs2 ocfs2_dir_foreach_blk_el pos/s_blocksize denial of service (Nessus ID 345365)

A vulnerability was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. It has been rated as critical. This issue affects the function ocfs2_dir_foreach_blk_el of the component ocfs2. This manipulation of the argument pos/s_blocksize causes

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 30.2%
CVE-2026-80995 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-80995 | Linux Kernel up to 7.2.3 MCTP mctp_route_lookup use after free (Nessus ID 345366)

A vulnerability categorized as very critical has been discovered in Linux Kernel up to 7.2.3. This impacts the function mctp_route_lookup of the component MCTP. The manipulation results in use after free. This vulnerability is cataloged as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 25.9%
CVE-2023-3439 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2023-3439 | Linux Kernel MCTP net/mctp/device.c mctp_unregister use after free (EUVD-2023-44103 / Nessus ID 345366)

A vulnerability was found in Linux Kernel. It has been declared as critical. This affects the function mctp_unregister of the file net/mctp/device.c of the component MCTP Handler. Executing a manipulation can lead to use after free. This vu

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
5.8 MEDIUM
EPSS 2.1%
CVE-2026-89642 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89642 | Linux Kernel up to 7.2.3 cifs cifs_setsize information disclosure (Nessus ID 345369)

A vulnerability was found in Linux Kernel up to 7.2.3. It has been declared as problematic. This affects the function cifs_setsize of the component cifs. Executing a manipulation can lead to information disclosure. This vulnerability is tra

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 24.6%
CVE-2026-89581 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89581 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 BPF add_1mod memory corruption (Nessus ID 345368)

A vulnerability was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3 and classified as problematic. This affects the function add_1mod of the component BPF. The manipulation results in memory corruption. This vulnerability is identified a

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 31.2%
CVE-2026-89717 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89717 | Linux Kernel up to 6.18.50/7.2.3 zram zram_destroy_comps null pointer dereference (Nessus ID 345367)

A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.18.50/7.2.3. This affects the function zram_destroy_comps of the component zram. The manipulation results in null pointer dereference. This vulnerability is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 23.9%
CVE-2026-89483 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89483 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 nvme nvme_setup_discard uninitialized pointer (Nessus ID 345371)

A vulnerability has been found in Linux Kernel up to 6.12.108/6.18.49/7.2.3 and classified as critical. This issue affects the function nvme_setup_discard of the component nvme. Performing a manipulation results in uninitialized pointer. Th

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 20.3%
CVE-2026-90848 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90848 | Governikus AusweisApp up to 2.5.4 StartPAOSResponse ResultMessage cross site scripting

A vulnerability was found in Governikus AusweisApp up to 2.5.4. It has been declared as problematic. Affected is an unknown function of the component StartPAOSResponse Handler. Executing a manipulation of the argument ResultMessage can lead

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

Weekly Cybersecurity Newsletter Bulletin – Microsoft 0-day, FortiOS, PAN-OS Flaw, Revolut Data Breach, and 20+ Stories

This week’s roundup covers a massive Microsoft Patch Tuesday with two exploited zero-days, active FortiGate exploitation, a critical PAN-OS root-level RCE flaw, the Revolut KYC data breach, and more than 20 other stories spanning AI-driven

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
10.0 CRITICAL
EPSS 79.1%
CVE-2026-85706 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read – Exploited Within 24 Hours

CVE-2026-85706, a CVSS 10.0 GitLab path traversal, was under active exploitation within 24 hours of disclosure. GitLab disclosed CVE-2026-85706 (CVSS score of 10.0) on September 10, 2026, a path traversal vulnerability in its repository com

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.3%
CVE-2026-68488 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Linux

Plesk Backup Manager Flaw Lets Low-Privileged Users Gain Root Access to Servers

A newly disclosed vulnerability in Plesk Backup Manager could allow low-privileged users to escalate privileges and gain full root access on affected Linux servers. Tracked as CVE-2026-68488, the flaw stems from a symlink race condition dur

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 32.8%
CVE-2026-69414 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

Microsoft-Patchday: 966 Schwachstellen, davon 105 kritisch - BornCity

... Windows 10, Windows 11 und Windows Server zu erlangen. Dabei werde eine frühere Korrektur für die Lücke CVE-2026-69414 umgangen. Microsoft ... Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 22.2%
CVE-2026-56711 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Multiple VLC Media Player Vulnerabilities Allow Attackers to Corrupt or Read Heap Memory

Two security vulnerabilities in VLC Media Player could allow attackers to corrupt heap memory or disclose sensitive data from a victim’s memory. The flaws, tracked as CVE-2026-56711 and CVE-2026-73324, affect VLC Media Player versions 3.0.0

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 💻 Lokal 🔓 Keine Authentifizierung nötig
Microsoft

China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks

China-linked threat actors UTA0560 and JungleBamboo chained a Google Chrome zero-day with a Windows kernel privilege-escalation flaw in phishing campaigns targeting NGOs and other victims. Volexity documented the operations, detected on Sep

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 💻 Lokal 🔓 Keine Authentifizierung nötig
Microsoft

China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks

China-linked threat actors UTA0560 and JungleBamboo chained a Google Chrome zero-day with a Windows kernel privilege-escalation flaw in phishing campaigns targeting NGOs and other victims. Volexity documented the operations, detected on Sep

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 32.1%
CVE-2026-85706 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CISA Warns of Critical GitLab Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab flaw, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog after confirming it was exploited in attacks. The issue affects bot

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.1%
CVE-2026-85706 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CISA Warns of Critical GitLab Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab flaw, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog after confirming it was exploited in attacks. The issue affects bot

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.