CVE-2017-5400: Schwachstellen-Eintrag (NVD)
JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
- 🔗 rhn.redhat.com/errata/RHSA-2017-0459.html
- 🔗 rhn.redhat.com/errata/RHSA-2017-0461.html
- 🔗 rhn.redhat.com/errata/RHSA-2017-0498.html
- 🔗 www.securityfocus.com/bid/96654
- 🔗 www.securitytracker.com/id/1037966
- 🔗 bugzilla.mozilla.org/show_bug.cgi
- 🔗 security.gentoo.org/glsa/201705-06
- 🔗 security.gentoo.org/glsa/201705-07
Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-13 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
CVE-2023-24288 | Simon Tatham Portable Puzzle Collection denial of service (EUVD-2023-60646)
A vulnerability was found in Simon Tatham Portable Puzzle Collection. It has been rated as problematic. This affects an unknown function. Performing a manipulation results in denial of service. This vulnerability is cataloged as CVE-2023-24
CVE-2023-24291 | Simon Tatham Portable Puzzle Collection record length parameter buffer overflow (EUVD-2023-60647)
A vulnerability was found in Simon Tatham Portable Puzzle Collection. It has been declared as problematic. The impacted element is an unknown function. Such manipulation of the argument record length parameter leads to buffer overflow. This
CVE-2023-24287 | Simon Tatham Portable Puzzle Collection buffer overflow (EUVD-2023-60645)
A vulnerability was found in Simon Tatham Portable Puzzle Collection. It has been classified as problematic. The affected element is an unknown function. This manipulation causes buffer overflow. This vulnerability is tracked as CVE-2023-24
CVE-2023-24286 | Simon Tatham Portable Puzzle Collection game description buffer overflow (EUVD-2023-60644)
A vulnerability was found in Simon Tatham Portable Puzzle Collection and classified as problematic. Impacted is an unknown function. The manipulation of the argument game description results in buffer overflow. This vulnerability is identif
CVE-2023-32778 | ILIAS up to 6.23/7.21/8.1 unrestricted upload (EUVD-2023-60650)
A vulnerability, which was classified as problematic, was found in ILIAS up to 6.23/7.21/8.1. The affected element is an unknown function. The manipulation results in unrestricted upload. This vulnerability was named CVE-2023-32778. The att
CVE-2023-28148 | Paessler PRTG Network Monitor up to 23.2.83.1760 cross site scripting (EUVD-2023-60648)
A vulnerability categorized as problematic has been discovered in Paessler PRTG Network Monitor up to 23.2.83.1760. This impacts an unknown function. Executing a manipulation can lead to cross site scripting. This vulnerability is registere
CVE-2023-29377 | Softing Secure Integration Server path traversal (ZDI-23-1055 / EUVD-2023-60649)
A vulnerability was found in Softing Secure Integration Server. It has been classified as critical. This vulnerability affects unknown code. Performing a manipulation results in path traversal. This vulnerability is known as CVE-2023-29377.
CVE-2023-34854 | Digital Druid HotelDruid up to 3.0.5 Backup/Restore backup/restore unrestricted upload (EUVD-2023-60662)
A vulnerability was found in Digital Druid HotelDruid up to 3.0.5. It has been classified as problematic. This impacts the function backup/restore of the component Backup/Restore. Performing a manipulation results in unrestricted upload. Th
CVE-2023-37252 | MediaWiki CheckUser Extension up to 1.35.10/1.38.6/1.39.3 access control (EUVD-2023-60663)
A vulnerability was found in MediaWiki CheckUser Extension up to 1.35.10/1.38.6/1.39.3 and classified as problematic. This affects an unknown function of the component CheckUser. Such manipulation leads to improper access controls. This vul
CVE-2023-32803 | Amazon Linux AMI CA-Certificate certificate validation (EUVD-2023-60651)
A vulnerability was found in Amazon Linux AMI and classified as critical. This vulnerability affects unknown code of the component CA-Certificate Handler. Such manipulation leads to improper certificate validation. This vulnerability is tra
CVE-2023-37253 | MediaWiki ProofreadPage Extension up to 1.35.10/1.38.6/1.39.3 information disclosure (EUVD-2023-60664)
A vulnerability classified as problematic has been found in MediaWiki ProofreadPage Extension up to 1.35.10/1.38.6/1.39.3. The affected element is an unknown function. The manipulation leads to information disclosure. This vulnerability is
CVE-2026-90680 | D-Link DIR-823G 1.0.2B05_20181207 HNAP1 SetStaticRouteSettings strcpy PAddress/SubnetMask/Gateway stack-based overflow (EUVD-2026-77191)
A vulnerability described as very critical has been identified in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is the function strcpy of the file /HNAP1/SetStaticRouteSettings of the component HNAP1. The manipulation of the argum
CVE-2026-89637 | Linux Kernel up to 6.18.50/7.2.3 SMB Client cifs_check_trans2 use after free (Nessus ID 345354)
A vulnerability has been found in Linux Kernel up to 6.18.50/7.2.3 and classified as very critical. Impacted is the function cifs_check_trans2 of the component SMB Client. This manipulation causes use after free. The identification of this
CVE-2026-89671 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 NFSv3 ACL Decoder nfsd3_proc_setacl mask/acl_access/acl_default null pointer dereference (Nessus ID 345353)
A vulnerability was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3 and classified as very critical. This vulnerability affects the function nfsd3_proc_setacl of the component NFSv3 ACL Decoder. The manipulation of the argument mask/acl_
CVE-2026-89626 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 Sysfs Group Cleanup hid_sensor_custom_add_attributes use after free (Nessus ID 345355)
A vulnerability was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. It has been classified as very critical. This affects the function hid_sensor_custom_add_attributes of the component Sysfs Group Cleanup. This manipulation causes use a
CVE-2026-89495 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 ocfs2 dlm_migrate_request_handler namelen/lockname_len/num_locks out-of-bounds write (Nessus ID 345356)
A vulnerability was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3 and classified as very critical. The impacted element is the function dlm_migrate_request_handler of the component ocfs2. The manipulation of the argument namelen/lockna
CVE-2026-87020 | Orthanc DICOM Server up to 1.12.x integer overflow (Nessus ID 345560)
A vulnerability categorized as problematic has been discovered in Orthanc DICOM Server up to 1.12.x. This vulnerability affects unknown code. The manipulation results in integer overflow. This vulnerability was named CVE-2026-87020. The att
CVE-2023-45858 | Paessler PRTG Network Monitor up to 23.3.86.1520 path traversal (EUVD-2023-60668)
A vulnerability was found in Paessler PRTG Network Monitor up to 23.3.86.1520. It has been classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to path traversal. This vulnerability is refe
CVE-2023-37366 | Samsung Exynos infinite loop (EUVD-2023-60665)
A vulnerability described as critical has been identified in Samsung Exynos. Impacted is an unknown function. Executing a manipulation can lead to infinite loop. This vulnerability appears as CVE-2023-37366. The attack requires local access
CVE-2026-90681 | Matthias-Wandel jhead up to 3.3 EXIF Parsing exif.c Get16u out-of-bounds (Issue 98 / EUVD-2026-77197)
A vulnerability classified as problematic has been found in Matthias-Wandel jhead up to 3.3. This affects the function Get16u of the file exif.c of the component EXIF Parsing. This manipulation causes out-of-bounds read. This vulnerability
CVE-2023-46273 | Extreme Networks IQ Engine up to 10.6r4 Bonjour Gateway ah_event_send buffer overflow (EUVD-2023-60670)
A vulnerability was found in Extreme Networks IQ Engine up to 10.6r4. It has been declared as very critical. This affects the function ah_event_send of the component Bonjour Gateway. The manipulation results in buffer overflow. This vulnera
CVE-2026-90682 | Matthias-Wandel jhead up to 3.3 WebP EXIF gpsinfo.c ProcessGpsInfo TAG_GPS_LAT/TAG_GPS_LONG heap-based overflow (Issue 99 / EUVD-2026-77198)
A vulnerability classified as problematic was found in Matthias-Wandel jhead up to 3.3. This impacts the function ProcessGpsInfo of the file gpsinfo.c of the component WebP EXIF Handler. Such manipulation of the argument TAG_GPS_LAT/TAG_GPS
CVE-2026-16726 | Panasonic PANATERM/RTEX LogReader USB Driver buffer overflow (EUVD-2026-77207)
A vulnerability was found in Panasonic PANATERM and RTEX LogReader. It has been rated as critical. This vulnerability affects unknown code of the component USB Driver. This manipulation causes buffer overflow. This vulnerability is tracked
CVE-2026-90686 | GPAC up to f1219cde MP4Box loader_bt.c gf_bt_report memory corruption (Issue 3798 / EUVD-2026-77205)
A vulnerability was found in GPAC up to f1219cde and classified as problematic. This affects the function gf_bt_report of the file scene_manager/loader_bt.c of the component MP4Box. The manipulation results in memory corruption. This vulner
CVE-2026-90684 | GPAC up to f1219cde MP4Box base_scenegraph.c gf_node_get_field_count assertion (Issue 3824 / EUVD-2026-77203)
A vulnerability, which was classified as problematic, was found in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field_count of the file scenegraph/base_scenegraph.c of the component MP4Box. Executing a man
CVE-2026-90683 | GPAC up to f1219cde MP4Box base_scenegraph.c gf_node_unregister assertion (Issue 3823 / EUVD-2026-77199)
A vulnerability, which was classified as problematic, has been found in GPAC up to f1219cde. Affected is the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. Performing a manipulation results in
CVE-2026-90687 | GPAC up to f1219cde MP4Box base_scenegraph.c gf_node_changed_internal use after free (Issue 3800 / EUVD-2026-77206)
A vulnerability was found in GPAC up to f1219cde. It has been classified as critical. This vulnerability affects the function gf_node_changed_internal of the file scenegraph/base_scenegraph.c of the component MP4Box. This manipulation cause
CVE-2026-90685 | GPAC up to f1219cde MP4Box laser/lsr_dec.c lsr_exec_command_list assertion (Issue 3825 / EUVD-2026-77204)
A vulnerability has been found in GPAC up to f1219cde and classified as problematic. Affected by this issue is the function lsr_exec_command_list of the file laser/lsr_dec.c of the component MP4Box. The manipulation leads to reachable asser
CVE-2026-85152 | OpenJS Foundation Undici up to 8.10.1 Cache cross-domain policy
A vulnerability was found in OpenJS Foundation Undici up to 8.10.1. It has been rated as problematic. This affects an unknown function of the component Cache. The manipulation leads to permissive cross-domain policy with untrusted domains.
CVE-2026-89468 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 lp8788-charger lp8788-charger.c lp8788_charger_remove use after free (Nessus ID 345358)
A vulnerability classified as very critical was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. This affects the function lp8788_charger_remove of the file lp8788-charger.c of the component lp8788-charger. Executing a manipulation can l
CVE-2026-89715 | Linux Kernel up to 6.18.49/7.2.3 localio nfs_open_local_fh nf_net allocation of resources (Nessus ID 345357)
A vulnerability labeled as critical has been found in Linux Kernel up to 6.18.49/7.2.3. The impacted element is the function nfs_open_local_fh of the component localio. The manipulation of the argument nf_net results in allocation of resour
CVE-2026-89707 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 nfsd nfsd_cross_mnt denial of service (Nessus ID 345361)
A vulnerability identified as critical has been detected in Linux Kernel up to 6.12.108/6.18.49/7.2.3. The affected element is the function nfsd_cross_mnt of the component nfsd. The manipulation leads to denial of service. This vulnerabilit
CVE-2026-80993 | Linux Kernel up to 6.18.49/7.2.3 phylink phylink_inband_caps null pointer dereference (Nessus ID 345360)
A vulnerability was found in Linux Kernel up to 6.18.49/7.2.3. It has been classified as critical. The affected element is the function phylink_inband_caps of the component phylink. Performing a manipulation results in null pointer derefere
CVE-2026-89729 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 Sensor Hub sensor_hub_get_feature out-of-bounds write (Nessus ID 345359)
A vulnerability described as very critical has been identified in Linux Kernel up to 6.12.108/6.18.49/7.2.3. Affected by this issue is the function sensor_hub_get_feature of the component Sensor Hub. Executing a manipulation can lead to out
CVE-2026-89557 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 Badblocks block/badblocks.c super_1_load bblog_shift buffer overflow (Nessus ID 345363)
A vulnerability, which was classified as very critical, has been found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. Affected by this issue is the function super_1_load of the file block/badblocks.c of the component Badblocks. This manipula
CVE-2026-89645 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 btrfs btrfs_recover_relocation denial of service (Nessus ID 345364)
A vulnerability categorized as problematic has been discovered in Linux Kernel up to 6.12.108/6.18.49/7.2.3. Affected by this issue is the function btrfs_recover_relocation of the component btrfs. The manipulation results in denial of servi
CVE-2026-18369 | Red Hat Certificate System/Enterprise Linux ACME responder server-side request forgery (EUVD-2026-51078)
A vulnerability marked as problematic has been reported in Red Hat Certificate System and Enterprise Linux. The impacted element is an unknown function of the component ACME responder. This manipulation causes server-side request forgery. T
CVE-2026-47883 | VMware Spring Framework up to 7.0.8/6.2.19 UrlHandlerFilter redirect (Nessus ID 341190 / WID-SEC-2026-2955)
A vulnerability was found in VMware Spring Framework up to 7.0.8/6.2.19 and classified as problematic. This issue affects some unknown processing of the component UrlHandlerFilter. Such manipulation leads to open redirect. This vulnerabilit
CVE-2026-47878 | Spring Batch up to 5.2.6/6.0.4 DefaultExecutionContextSerializer ObjectInputStream.readObject deserialization
A vulnerability, which was classified as critical, was found in Spring Batch up to 5.2.6/6.0.4. This affects the function ObjectInputStream.readObject of the component DefaultExecutionContextSerializer. The manipulation results in deseriali
CVE-2026-47886 | VMware Spring Framework up to 7.0.8 resource consumption (Nessus ID 341189 / WID-SEC-2026-2955)
A vulnerability labeled as problematic has been found in VMware Spring Framework up to 7.0.8. The impacted element is an unknown function. The manipulation results in resource consumption. This vulnerability is cataloged as CVE-2026-47886.
CVE-2026-47884 | Spring Framework up to 7.0.8 XsltView path traversal (WID-SEC-2026-2955)
A vulnerability identified as critical has been detected in Spring Framework up to 7.0.8. The affected element is an unknown function of the component XsltView. The manipulation leads to path traversal. This vulnerability is listed as CVE-2
CVE-2026-47879 | VMware Spring Cloud Gateway up to 3.1.13/4.2.9/4.3.5/5.0.2 server-side request forgery (WID-SEC-2026-2952)
A vulnerability categorized as problematic has been discovered in VMware Spring Cloud Gateway up to 3.1.13/4.2.9/4.3.5/5.0.2. Impacted is an unknown function. Executing a manipulation can lead to server-side request forgery. This vulnerabil
CVE-2026-47885 | Spring Framework up to 6.1.28/6.2.19/7.0.8 PartEventHttpMessageReader allocation of resources (Nessus ID 341187 / WID-SEC-2026-2955)
A vulnerability was found in Spring Framework up to 6.1.28/6.2.19/7.0.8 and classified as problematic. Affected by this issue is some unknown functionality of the component PartEventHttpMessageReader. The manipulation results in allocation
CVE-2026-89490 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 ocfs2 ocfs2_dir_foreach_blk_el pos/s_blocksize denial of service (Nessus ID 345365)
A vulnerability was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. It has been rated as critical. This issue affects the function ocfs2_dir_foreach_blk_el of the component ocfs2. This manipulation of the argument pos/s_blocksize causes
CVE-2026-80995 | Linux Kernel up to 7.2.3 MCTP mctp_route_lookup use after free (Nessus ID 345366)
A vulnerability categorized as very critical has been discovered in Linux Kernel up to 7.2.3. This impacts the function mctp_route_lookup of the component MCTP. The manipulation results in use after free. This vulnerability is cataloged as
CVE-2023-3439 | Linux Kernel MCTP net/mctp/device.c mctp_unregister use after free (EUVD-2023-44103 / Nessus ID 345366)
A vulnerability was found in Linux Kernel. It has been declared as critical. This affects the function mctp_unregister of the file net/mctp/device.c of the component MCTP Handler. Executing a manipulation can lead to use after free. This vu
CVE-2026-89642 | Linux Kernel up to 7.2.3 cifs cifs_setsize information disclosure (Nessus ID 345369)
A vulnerability was found in Linux Kernel up to 7.2.3. It has been declared as problematic. This affects the function cifs_setsize of the component cifs. Executing a manipulation can lead to information disclosure. This vulnerability is tra
CVE-2026-89581 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 BPF add_1mod memory corruption (Nessus ID 345368)
A vulnerability was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3 and classified as problematic. This affects the function add_1mod of the component BPF. The manipulation results in memory corruption. This vulnerability is identified a
CVE-2026-89717 | Linux Kernel up to 6.18.50/7.2.3 zram zram_destroy_comps null pointer dereference (Nessus ID 345367)
A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.18.50/7.2.3. This affects the function zram_destroy_comps of the component zram. The manipulation results in null pointer dereference. This vulnerability is
CVE-2026-89483 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 nvme nvme_setup_discard uninitialized pointer (Nessus ID 345371)
A vulnerability has been found in Linux Kernel up to 6.12.108/6.18.49/7.2.3 and classified as critical. This issue affects the function nvme_setup_discard of the component nvme. Performing a manipulation results in uninitialized pointer. Th
CVE-2026-90848 | Governikus AusweisApp up to 2.5.4 StartPAOSResponse ResultMessage cross site scripting
A vulnerability was found in Governikus AusweisApp up to 2.5.4. It has been declared as problematic. Affected is an unknown function of the component StartPAOSResponse Handler. Executing a manipulation of the argument ResultMessage can lead
Weekly Cybersecurity Newsletter Bulletin – Microsoft 0-day, FortiOS, PAN-OS Flaw, Revolut Data Breach, and 20+ Stories
This week’s roundup covers a massive Microsoft Patch Tuesday with two exploited zero-days, active FortiGate exploitation, a critical PAN-OS root-level RCE flaw, the Revolut KYC data breach, and more than 20 other stories spanning AI-driven
GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read – Exploited Within 24 Hours
CVE-2026-85706, a CVSS 10.0 GitLab path traversal, was under active exploitation within 24 hours of disclosure. GitLab disclosed CVE-2026-85706 (CVSS score of 10.0) on September 10, 2026, a path traversal vulnerability in its repository com
Plesk Backup Manager Flaw Lets Low-Privileged Users Gain Root Access to Servers
A newly disclosed vulnerability in Plesk Backup Manager could allow low-privileged users to escalate privileges and gain full root access on affected Linux servers. Tracked as CVE-2026-68488, the flaw stems from a symlink race condition dur
Microsoft-Patchday: 966 Schwachstellen, davon 105 kritisch - BornCity
... Windows 10, Windows 11 und Windows Server zu erlangen. Dabei werde eine frühere Korrektur für die Lücke CVE-2026-69414 umgangen. Microsoft ... Weiterlesen
Multiple VLC Media Player Vulnerabilities Allow Attackers to Corrupt or Read Heap Memory
Two security vulnerabilities in VLC Media Player could allow attackers to corrupt heap memory or disclose sensitive data from a victim’s memory. The flaws, tracked as CVE-2026-56711 and CVE-2026-73324, affect VLC Media Player versions 3.0.0
China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks
China-linked threat actors UTA0560 and JungleBamboo chained a Google Chrome zero-day with a Windows kernel privilege-escalation flaw in phishing campaigns targeting NGOs and other victims. Volexity documented the operations, detected on Sep
China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks
China-linked threat actors UTA0560 and JungleBamboo chained a Google Chrome zero-day with a Windows kernel privilege-escalation flaw in phishing campaigns targeting NGOs and other victims. Volexity documented the operations, detected on Sep
CISA Warns of Critical GitLab Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab flaw, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog after confirming it was exploited in attacks. The issue affects bot
CISA Warns of Critical GitLab Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab flaw, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog after confirming it was exploited in attacks. The issue affects bot