Published issues
wireshark: security issues < 4.6.7
Permalink
CVE-2026-15165
5.5 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): Required (R)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): High (H)
updated
2 weeks, 6 days ago
by @LeSuisse
Activity log
-
Created suggestion
2 weeks, 6 days ago
-
@LeSuisse
accepted
2 weeks, 6 days ago
-
@LeSuisse
published on GitHub
2 weeks, 6 days ago
Heap-based Buffer Overflow in Wireshark
Permalink
CVE-2026-15174
5.5 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): Required (R)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): High (H)
updated
2 weeks, 6 days ago
by @LeSuisse
Activity log
-
Created suggestion
2 weeks, 6 days ago
-
@LeSuisse
accepted
2 weeks, 6 days ago
-
@LeSuisse
published on GitHub
2 weeks, 6 days ago
Heap-based Buffer Overflow in Wireshark
Permalink
CVE-2026-15163
5.5 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): Required (R)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): High (H)
updated
2 weeks, 6 days ago
by @LeSuisse
Activity log
-
Created suggestion
2 weeks, 6 days ago
-
@LeSuisse
accepted
2 weeks, 6 days ago
-
@LeSuisse
published on GitHub
2 weeks, 6 days ago
Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
Permalink
CVE-2026-15169
5.5 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): Required (R)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): High (H)
updated
2 weeks, 6 days ago
by @LeSuisse
Activity log
-
Created suggestion
2 weeks, 6 days ago
-
@LeSuisse
accepted
2 weeks, 6 days ago
-
@LeSuisse
published on GitHub
2 weeks, 6 days ago
Heap-based Buffer Overflow in Wireshark
Permalink
CVE-2026-15166
5.5 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): Required (R)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): High (H)
updated
2 weeks, 6 days ago
by @LeSuisse
Activity log
-
Created suggestion
2 weeks, 6 days ago
-
@LeSuisse
accepted
2 weeks, 6 days ago
-
@LeSuisse
published on GitHub
2 weeks, 6 days ago
Stack-based Buffer Overflow in Wireshark
Permalink
CVE-2026-15172
5.5 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): Required (R)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): High (H)
updated
2 weeks, 6 days ago
by @LeSuisse
Activity log
-
Created suggestion
2 weeks, 6 days ago
-
@LeSuisse
accepted
2 weeks, 6 days ago
-
@LeSuisse
published on GitHub
2 weeks, 6 days ago
Unchecked Input for Loop Condition in Wireshark
Permalink
CVE-2026-15167
7.5 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): High (H)
updated
2 weeks, 6 days ago
by @LeSuisse
Activity log
-
Created suggestion
2 weeks, 6 days ago
-
@LeSuisse
accepted
2 weeks, 6 days ago
-
@LeSuisse
published on GitHub
2 weeks, 6 days ago
Stack-based Buffer Overflow in Wireshark
Permalink
CVE-2026-15170
5.5 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): Required (R)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): High (H)
updated
2 weeks, 6 days ago
by @LeSuisse
Activity log
-
Created suggestion
2 weeks, 6 days ago
-
@LeSuisse
accepted
2 weeks, 6 days ago
-
@LeSuisse
published on GitHub
2 weeks, 6 days ago
Heap-based Buffer Overflow in Wireshark
Permalink
CVE-2026-15168
2.5 LOW
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): Required (R)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): Low (L)
-
Integrity (I): None (N)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): Low (L)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): None (N)
updated
2 weeks, 6 days ago
by @LeSuisse
Activity log
-
Created suggestion
2 weeks, 6 days ago
-
@LeSuisse
accepted
2 weeks, 6 days ago
-
@LeSuisse
published on GitHub
2 weeks, 6 days ago
Use of Uninitialized Variable in Wireshark
Permalink
CVE-2026-15171
5.5 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): Required (R)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): High (H)
updated
2 weeks, 6 days ago
by @LeSuisse
Activity log
-
Created suggestion
2 weeks, 6 days ago
-
@LeSuisse
accepted
2 weeks, 6 days ago
-
@LeSuisse
published on GitHub
2 weeks, 6 days ago
NULL Pointer Dereference in Wireshark
nats-server: security issues < 2.14.3
Permalink
CVE-2026-58207
7.7 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Changed (C)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Changed (C)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): High (H)
updated
2 weeks, 6 days ago
by @LeSuisse
Activity log
-
Created suggestion
2 weeks, 6 days ago
-
@LeSuisse
accepted
2 weeks, 6 days ago
-
@LeSuisse
published on GitHub
2 weeks, 6 days ago
NATS Server: Remote crash via integer overflow in Connz pagination
nats-server
-
==>= 2.14.0-RC.1, < 2.14.3
-
==< 2.12.12
Permalink
CVE-2026-58214
4.3 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): Low (L)
-
Integrity (I): None (N)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): Low (L)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): None (N)
updated
2 weeks, 6 days ago
by @LeSuisse
Activity log
-
Created suggestion
2 weeks, 6 days ago
-
@LeSuisse
accepted
2 weeks, 6 days ago
-
@LeSuisse
published on GitHub
2 weeks, 6 days ago
NATS Server: MQTT subscribe ACL bypass via $MQTT.deliver.pubrel prefix (incomplete fix for CVE-2026-33217)
nats-server
-
==>= 2.14.0-RC.1, < 2.14.3
-
==< 2.12.12
Permalink
CVE-2026-58211
5.4 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): Low (L)
-
Integrity (I): Low (L)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): Low (L)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): Low (L)
-
Modified Availability (MA): None (N)
updated
2 weeks, 6 days ago
by @LeSuisse
Activity log
-
Created suggestion
2 weeks, 6 days ago
-
@LeSuisse
accepted
2 weeks, 6 days ago
-
@LeSuisse
published on GitHub
2 weeks, 6 days ago
NATS Server: `no_auth_user` pre-CONNECT fast path bypasses user connection restrictions
nats-server
-
==>= 2.14.0-RC.1, < 2.14.3
-
==< 2.12.12
Permalink
CVE-2026-58209
4.3 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): Low (L)
-
Integrity (I): None (N)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): Low (L)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): None (N)
updated
2 weeks, 6 days ago
by @LeSuisse
Activity log
-
Created suggestion
2 weeks, 6 days ago
-
@LeSuisse
accepted
2 weeks, 6 days ago
-
@LeSuisse
published on GitHub
2 weeks, 6 days ago
NATS Server: MQTT retained and QoS replay bypass subscribe deny filters
nats-server
-
==>= 2.14.0-RC.1, < 2.14.3
-
==< 2.12.12
Permalink
CVE-2026-58254
5.3 MEDIUM
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): Low (L)
-
Vulnerable System Impact Integrity (VI): Low (L)
-
Vulnerable System Impact Availability (VA): Low (L)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
-
Modified Vulnerable System Impact Integrity (MVI): Low (L)
-
Modified Vulnerable System Impact Availability (MVA): Low (L)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
2 weeks, 6 days ago
by @LeSuisse
Activity log
-
Created suggestion
2 weeks, 6 days ago
-
@LeSuisse
accepted
2 weeks, 6 days ago
-
@LeSuisse
published on GitHub
2 weeks, 6 days ago
NATS Server: Incomplete fix for CVE-2026-33249: Leaf node connections bypass Nats-Trace-Dest permission check
nats-server
-
==>= 2.14.0-RC.1, < 2.14.3
-
==< 2.12.8
Permalink
CVE-2026-58210
7.5 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): High (H)
updated
2 weeks, 6 days ago
by @LeSuisse
Activity log
-
Created suggestion
2 weeks, 6 days ago
-
@LeSuisse
accepted
2 weeks, 6 days ago
-
@LeSuisse
published on GitHub
2 weeks, 6 days ago
NATS Server: MQTT partial CONNECT packets can exhaust pre-auth memory
nats-server
-
==>= 2.14.0-RC.1, < 2.14.3
-
==< 2.12.12
Permalink
CVE-2026-58208
6.8 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Changed (C)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Changed (C)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): High (H)
updated
2 weeks, 6 days ago
by @LeSuisse
Activity log
-
Created suggestion
2 weeks, 6 days ago
-
@LeSuisse
accepted
2 weeks, 6 days ago
-
@LeSuisse
published on GitHub
2 weeks, 6 days ago
NATS Server: MQTT-over-WebSocket Path Can Crash WebSocket-Only JetStream Servers Before MQTT Is Enabled
nats-server
-
==>= 2.14.0-RC.1, < 2.14.3
-
==< 2.12.12
openssh: security issues < 10.4
Permalink
CVE-2026-59999
5.9 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): High (H)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): None (N)
updated
2 weeks, 6 days ago
by @LeSuisse
Activity log
-
Created suggestion
2 weeks, 6 days ago
-
@LeSuisse
ignored
5 packages
- opensshTest
- openssh-askpass
- perlPackages.NetOpenSSH
- perl5Packages.NetOpenSSH
- lxqt.lxqt-openssh-askpass
2 weeks, 6 days ago
-
@LeSuisse
accepted
2 weeks, 6 days ago
-
@LeSuisse
published on GitHub
2 weeks, 6 days ago
In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to …
Permalink
CVE-2026-60002
7.7 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): High (H)
-
Integrity (I): High (H)
-
Availability (A): Low (L)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): Low (L)
updated
2 weeks, 6 days ago
by @LeSuisse
Activity log
-
Created suggestion
2 weeks, 6 days ago
-
@LeSuisse
ignored
5 packages
- opensshTest
- openssh-askpass
- perlPackages.NetOpenSSH
- perl5Packages.NetOpenSSH
- lxqt.lxqt-openssh-askpass
2 weeks, 6 days ago
-
@LeSuisse
accepted
2 weeks, 6 days ago
-
@LeSuisse
published on GitHub
2 weeks, 6 days ago
ssh in OpenSSH before 10.4 can have a use-after-free when …
Permalink
CVE-2026-59995
4.2 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): Required (R)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): Low (L)
-
Availability (A): Low (L)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): Low (L)
-
Modified Availability (MA): Low (L)
updated
2 weeks, 6 days ago
by @LeSuisse
Activity log
-
Created suggestion
2 weeks, 6 days ago
-
@LeSuisse
ignored
5 packages
- opensshTest
- openssh-askpass
- perlPackages.NetOpenSSH
- perl5Packages.NetOpenSSH
- lxqt.lxqt-openssh-askpass
2 weeks, 6 days ago
-
@LeSuisse
accepted
2 weeks, 6 days ago
-
@LeSuisse
published on GitHub
2 weeks, 6 days ago
sftp in OpenSSH before 10.4 does not properly constrain the …
Permalink
CVE-2026-59996
4.2 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): Required (R)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): Low (L)
-
Availability (A): Low (L)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): Low (L)
-
Modified Availability (MA): Low (L)
updated
2 weeks, 6 days ago
by @LeSuisse
Activity log
-
Created suggestion
2 weeks, 6 days ago
-
@LeSuisse
ignored
5 packages
- opensshTest
- openssh-askpass
- perlPackages.NetOpenSSH
- perl5Packages.NetOpenSSH
- lxqt.lxqt-openssh-askpass
2 weeks, 6 days ago
-
@LeSuisse
accepted
2 weeks, 6 days ago
-
@LeSuisse
published on GitHub
2 weeks, 6 days ago
scp in OpenSSH before 10.4 may place a file in …
Permalink
CVE-2026-60001
6.5 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): Low (L)
-
Availability (A): Low (L)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): Low (L)
-
Modified Availability (MA): Low (L)
updated
2 weeks, 6 days ago
by @LeSuisse
Activity log
-
Created suggestion
2 weeks, 6 days ago
-
@LeSuisse
ignored
5 packages
- opensshTest
- perlPackages.NetOpenSSH
- perl5Packages.NetOpenSSH
- lxqt.lxqt-openssh-askpass
- openssh-askpass
2 weeks, 6 days ago
-
@LeSuisse
accepted
2 weeks, 6 days ago
-
@LeSuisse
published on GitHub
2 weeks, 6 days ago
sshd in OpenSSH before 10.4 does not always honor the …
Permalink
CVE-2026-60000
3.7 LOW
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): Low (L)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): Low (L)
updated
2 weeks, 6 days ago
by @LeSuisse
Activity log
-
Created suggestion
2 weeks, 6 days ago
-
@LeSuisse
ignored
5 packages
- opensshTest
- lxqt.lxqt-openssh-askpass
- perl5Packages.NetOpenSSH
- perlPackages.NetOpenSSH
- openssh-askpass
2 weeks, 6 days ago
-
@LeSuisse
accepted
2 weeks, 6 days ago
-
@LeSuisse
published on GitHub
2 weeks, 6 days ago
sshd in OpenSSH before 10.4 allows remote attackers to cause …
Permalink
CVE-2026-59997
4.2 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): Required (R)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): Low (L)
-
Integrity (I): Low (L)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): Low (L)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): Low (L)
-
Modified Availability (MA): None (N)
updated
2 weeks, 6 days ago
by @LeSuisse
Activity log
-
Created suggestion
2 weeks, 6 days ago
-
@LeSuisse
ignored
5 packages
- lxqt.lxqt-openssh-askpass
- perl5Packages.NetOpenSSH
- perlPackages.NetOpenSSH
- opensshTest
- openssh-askpass
2 weeks, 6 days ago
-
@LeSuisse
accepted
2 weeks, 6 days ago
-
@LeSuisse
published on GitHub
2 weeks, 6 days ago
internal-sftp in sshd in OpenSSH before 10.4 recognizes only the …
Permalink
CVE-2026-59998
4.8 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): Low (L)
-
Integrity (I): Low (L)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): Low (L)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): Low (L)
-
Modified Availability (MA): None (N)
updated
2 weeks, 6 days ago
by @LeSuisse
Activity log
-
Created suggestion
2 weeks, 6 days ago
-
@LeSuisse
ignored
5 packages
- opensshTest
- openssh-askpass
- perlPackages.NetOpenSSH
- perl5Packages.NetOpenSSH
- lxqt.lxqt-openssh-askpass
2 weeks, 6 days ago
-
@LeSuisse
accepted
2 weeks, 6 days ago
-
@LeSuisse
published on GitHub
2 weeks, 6 days ago
sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: …
n8n - Improper Authorization in Workflow Assignment to Folders
Permalink
CVE-2026-59253
5.3 MEDIUM
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): None (N)
-
Vulnerable System Impact Integrity (VI): Low (L)
-
Vulnerable System Impact Availability (VA): None (N)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): Low (L)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): None (N)
-
Modified Vulnerable System Impact Integrity (MVI): Low (L)
-
Modified Vulnerable System Impact Availability (MVA): None (N)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Low (L)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
2 weeks, 6 days ago
by @LeSuisse
Activity log
-
Created suggestion
2 weeks, 6 days ago
-
@LeSuisse
ignored
3 packages
- n8n-nodes-carbonejs
- n8n-nodes-evolution-api
- n8n-task-runner-launcher
2 weeks, 6 days ago
-
@LeSuisse
accepted
2 weeks, 6 days ago
-
@LeSuisse
published on GitHub
2 weeks, 6 days ago
n8n - Improper Authorization in Workflow Assignment to Folders
wget: security issues <= 1.25.0 (patches available)
String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service
updated
3 weeks ago
by @LeSuisse
Activity log
-
Created suggestion
3 weeks ago
-
@LeSuisse
ignored
reference https://g…
3 weeks ago
-
@LeSuisse
ignored
3 packages
- chickenPackages_5.chickenEggs.string-utils
- python314Packages.python-string-utils
- python313Packages.python-string-utils
3 weeks ago
-
@LeSuisse
accepted
3 weeks ago
-
@LeSuisse
published on GitHub
3 weeks ago
String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service
Gimp: gimp: integer overflow in read_rle_channel()
Permalink
CVE-2026-58384
7.3 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): Required (R)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): High (H)
-
Integrity (I): High (H)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): High (H)
updated
3 weeks ago
by @LeSuisse
Activity log
-
Created suggestion
3 weeks ago
-
@LeSuisse
ignored
20 packages
- gimp2
- gimp3
- gimp3-with-plugins
- gimp2Plugins.fourier
- gimp2Plugins.farbfeld
- gimpPlugins.lightning
- gimp2Plugins.lightning
- gimp2Plugins.lqrPlugin
- gimp2Plugins.texturize
- gimp2Plugins.gimplensfun
- gimpPlugins.resynthesizer
- gimp2Plugins.waveletSharpen
- zigimports
- gimpPlugins.gimp
- gimpPlugins.gmic
- gimp-with-plugins
- gimp2Plugins.bimp
- gimp2Plugins.gmic
- gimp2-with-plugins
- gimp2Plugins.gimp
3 weeks ago
-
@LeSuisse
restored
package gimp3
3 weeks ago
-
@LeSuisse
accepted
3 weeks ago
-
@LeSuisse
published on GitHub
3 weeks ago
Gimp: gimp: integer overflow in read_rle_channel()
Dashy: XSS in workspace url parameter
Permalink
CVE-2026-55592
3.9 LOW
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): Required (R)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): Low (L)
-
Integrity (I): Low (L)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): Low (L)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): Low (L)
-
Modified Availability (MA): None (N)
updated
3 weeks ago
by @LeSuisse
Activity log
-
Created suggestion
3 weeks ago
-
@LeSuisse
ignored
8 packages
- typstPackages.dashy-todo_0_0_2
- typstPackages.dashy-todo_0_0_1
- typstPackages.dashy-todo_0_0_3
- typstPackages.dashy-todo_0_1_0
- typstPackages.dashy-todo_0_1_1
- typstPackages.dashy-todo_0_1_2
- typstPackages.dashy-todo_0_1_3
- typstPackages.dashy-todo
3 weeks ago
-
@LeSuisse
ignored
reference https://g…
3 weeks ago
-
@LeSuisse
accepted
3 weeks ago
-
@LeSuisse
published on GitHub
3 weeks ago
Dashy: XSS in workspace url parameter
calibre: Arbitrary Code Execution in Template Formatter via Book Metadata
Permalink
CVE-2026-53511
8.5 HIGH
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): Passive (P)
-
Vulnerable System Impact Confidentiality (VC): High (H)
-
Vulnerable System Impact Integrity (VI): High (H)
-
Vulnerable System Impact Availability (VA): High (H)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): Passive (P)
-
Modified Vulnerable System Impact Confidentiality (MVC): High (H)
-
Modified Vulnerable System Impact Integrity (MVI): High (H)
-
Modified Vulnerable System Impact Availability (MVA): High (H)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
3 weeks ago
by @LeSuisse
Activity log
-
Created suggestion
3 weeks ago
-
@LeSuisse
ignored
3 packages
- calibre-web
- calibre-no-speech
- pkgsRocm.calibre-no-speech
3 weeks ago
-
@LeSuisse
ignored
reference https://g…
3 weeks ago
-
@LeSuisse
accepted
3 weeks ago
-
@LeSuisse
published on GitHub
3 weeks ago
calibre: Arbitrary Code Execution in Template Formatter via Book Metadata
Actual: Shared users can perform owner-only file management actions
Permalink
CVE-2026-50007
7.2 HIGH
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): None (N)
-
Vulnerable System Impact Integrity (VI): High (H)
-
Vulnerable System Impact Availability (VA): High (H)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): None (N)
-
Modified Vulnerable System Impact Integrity (MVI): High (H)
-
Modified Vulnerable System Impact Availability (MVA): High (H)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
3 weeks ago
by @LeSuisse
Activity log
-
Created suggestion
3 weeks ago
-
@LeSuisse
ignored
package gnomeExtensions.maximized-by-default-actually-reborn
3 weeks ago
-
@LeSuisse
accepted
3 weeks ago
-
@LeSuisse
published on GitHub
3 weeks ago
Actual: Shared users can perform owner-only file management actions