Published issues
Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step
updated
5 days, 9 hours ago
by @LeSuisse
Activity log
-
Created suggestion
5 days, 17 hours ago
-
@LeSuisse
ignored
2 packages
- perlPackages.AuthenSASLSASLprep
- perl5Packages.AuthenSASLSASLprep
5 days, 12 hours ago
-
@LeSuisse
accepted
5 days, 12 hours ago
-
@LeSuisse
published on GitHub
5 days, 9 hours ago
Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step
SiYuan before v3.8.2 Private Attribute View Key Enumeration
Permalink
CVE-2026-86191
5.3 MEDIUM
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): Low (L)
-
Vulnerable System Impact Integrity (VI): None (N)
-
Vulnerable System Impact Availability (VA): None (N)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
-
Modified Vulnerable System Impact Integrity (MVI): None (N)
-
Modified Vulnerable System Impact Availability (MVA): None (N)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
5 days, 21 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 17 hours ago
-
@LeSuisse
accepted
6 days, 8 hours ago
-
@LeSuisse
ignored
3 maintainers
- @TomaSajt
- @mtul0729
- @L-Trump
5 days, 21 hours ago
maintainer.ignore
-
@LeSuisse
published on GitHub
5 days, 21 hours ago
SiYuan before v3.8.2 Private Attribute View Key Enumeration
Grav before 2.0.20 Cross-Site Scripting via Assets Sandbox
Permalink
CVE-2026-86197
5.1 MEDIUM
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): Passive (P)
-
Vulnerable System Impact Confidentiality (VC): Low (L)
-
Vulnerable System Impact Integrity (VI): Low (L)
-
Vulnerable System Impact Availability (VA): None (N)
-
Subsequent System Impact Confidentiality (SC): Low (L)
-
Subsequent System Impact Integrity (SI): Low (L)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): Passive (P)
-
Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
-
Modified Vulnerable System Impact Integrity (MVI): Low (L)
-
Modified Vulnerable System Impact Availability (MVA): None (N)
-
Modified Subsequent System Impact Confidentiality (MSC): Low (L)
-
Modified Subsequent System Impact Integrity (MSI): Low (L)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
5 days, 21 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 17 hours ago
-
@LeSuisse
ignored
19 packages
- haskellPackages.gravatar
- gravit
- antigravity
- antigravity-cli
- antigravity-fhs
- antigravity-ide
- antigravity-ide-fhs
- stardust-xr-gravity
- kdePackages.libgravatar
- bulwark-plugins.gravatar
- gnomeExtensions.gravatar
- python313Packages.libgravatar
- python314Packages.libgravatar
- python314Packages.flask-gravatar
- python313Packages.django-gravatar2
- python313Packages.flask-gravatar
- python314Packages.django-gravatar2
- perlPackages.MojoliciousPluginGravatar
- perl5Packages.MojoliciousPluginGravatar
6 days, 8 hours ago
-
@LeSuisse
accepted
6 days, 8 hours ago
-
@LeSuisse
published on GitHub
5 days, 21 hours ago
Grav before 2.0.20 Cross-Site Scripting via Assets Sandbox
NetBox through 4.7.0 Credential Disclosure via REST and GraphQL APIs
NetBox through 4.7.0 Credential Disclosure via REST and GraphQL APIs
Pixelfed through 0.12.9 Unauthorized Story Access via API
Permalink
CVE-2026-86178
5.3 MEDIUM
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): Low (L)
-
Vulnerable System Impact Integrity (VI): Low (L)
-
Vulnerable System Impact Availability (VA): None (N)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
-
Modified Vulnerable System Impact Integrity (MVI): Low (L)
-
Modified Vulnerable System Impact Availability (MVA): None (N)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
5 days, 21 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 17 hours ago
-
@LeSuisse
accepted
5 days, 21 hours ago
-
@LeSuisse
published on GitHub
5 days, 21 hours ago
Pixelfed through 0.12.9 Unauthorized Story Access via API
gonic before 0.22.0 Missing Administrator Check on the Subsonic startScan Endpoint
Permalink
CVE-2026-86118
5.3 MEDIUM
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): None (N)
-
Vulnerable System Impact Integrity (VI): None (N)
-
Vulnerable System Impact Availability (VA): Low (L)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): None (N)
-
Modified Vulnerable System Impact Integrity (MVI): None (N)
-
Modified Vulnerable System Impact Availability (MVA): Low (L)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
5 days, 21 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 17 hours ago
-
@LeSuisse
accepted
5 days, 21 hours ago
-
@LeSuisse
published on GitHub
5 days, 21 hours ago
gonic before 0.22.0 Missing Administrator Check on the Subsonic startScan Endpoint
Metabase before 0.63.1 Missing Function-Level Authorization on the Glossary Management API
Permalink
CVE-2026-86116
7.1 HIGH
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): None (N)
-
Vulnerable System Impact Integrity (VI): High (H)
-
Vulnerable System Impact Availability (VA): None (N)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): None (N)
-
Modified Vulnerable System Impact Integrity (MVI): High (H)
-
Modified Vulnerable System Impact Availability (MVA): None (N)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
5 days, 21 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 17 hours ago
-
@LeSuisse
accepted
5 days, 21 hours ago
-
@LeSuisse
published on GitHub
5 days, 21 hours ago
Metabase before 0.63.1 Missing Function-Level Authorization on the Glossary Management API
PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse …
Permalink
CVE-2026-86145
8.2 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): High (H)
-
Availability (A): Low (L)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): Low (L)
updated
5 days, 22 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 17 hours ago
-
@LeSuisse
ignored
12 packages
- jpcre2
- ocamlPackages.pcre2
- haskellPackages.pcre2
- luaPackages.lrexlib-pcre2
- ocamlPackages_latest.pcre2
- haskellPackages.regex-pcre2
- lua51Packages.lrexlib-pcre2
- lua52Packages.lrexlib-pcre2
- lua53Packages.lrexlib-pcre2
- lua54Packages.lrexlib-pcre2
- lua55Packages.lrexlib-pcre2
- luajitPackages.lrexlib-pcre2
6 days, 3 hours ago
-
@LeSuisse
accepted
5 days, 22 hours ago
-
@LeSuisse
published on GitHub
5 days, 22 hours ago
PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse …
libpcap: security issues < 1.10.7
Permalink
CVE-2026-31911
5.5 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): High (H)
updated
6 days, 8 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 17 hours ago
-
@LeSuisse
ignored
3 packages
- darwin.libpcap
- python313Packages.libpcap
- python314Packages.libpcap
6 days, 8 hours ago
-
@LeSuisse
accepted
6 days, 8 hours ago
-
@LeSuisse
published on GitHub
6 days, 8 hours ago
abort() in libpcap before 1.10.7 on an invalid BPF opcode
Permalink
CVE-2026-0799
8.7 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Changed (C)
-
Confidentiality (C): Low (L)
-
Integrity (I): High (H)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): Low (L)
-
Modified Scope (MS): Changed (C)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): High (H)
updated
6 days, 8 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 17 hours ago
-
@LeSuisse
ignored
3 packages
- darwin.libpcap
- python313Packages.libpcap
- python314Packages.libpcap
6 days, 8 hours ago
-
@LeSuisse
accepted
6 days, 8 hours ago
-
@LeSuisse
published on GitHub
6 days, 8 hours ago
OOBR and OOBW in libpcap before 1.10.7
Permalink
CVE-2026-18238
5.0 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Changed (C)
-
Confidentiality (C): Low (L)
-
Integrity (I): None (N)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): Low (L)
-
Modified Scope (MS): Changed (C)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): None (N)
updated
6 days, 8 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 17 hours ago
-
@LeSuisse
ignored
3 packages
- darwin.libpcap
- python314Packages.libpcap
- python313Packages.libpcap
6 days, 8 hours ago
-
@LeSuisse
accepted
6 days, 8 hours ago
-
@LeSuisse
published on GitHub
6 days, 8 hours ago
OOBR in rpcap client in libpcap before 1.10.7
Permalink
CVE-2026-6554
5.5 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): High (H)
updated
6 days, 8 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 17 hours ago
-
@LeSuisse
ignored
3 packages
- darwin.libpcap
- python313Packages.libpcap
- python314Packages.libpcap
6 days, 8 hours ago
-
@LeSuisse
accepted
6 days, 8 hours ago
-
@LeSuisse
published on GitHub
6 days, 8 hours ago
infinte loop in libpcap before 1.10.7
Permalink
CVE-2026-31912
5.5 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): High (H)
updated
6 days, 8 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 17 hours ago
-
@LeSuisse
ignored
3 packages
- darwin.libpcap
- python313Packages.libpcap
- python314Packages.libpcap
6 days, 8 hours ago
-
@LeSuisse
accepted
6 days, 8 hours ago
-
@LeSuisse
published on GitHub
6 days, 8 hours ago
OOBR in libpcap before 1.10.7
Permalink
CVE-2026-6244
5.5 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): High (H)
updated
6 days, 8 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 17 hours ago
-
@LeSuisse
ignored
3 packages
- python314Packages.libpcap
- python313Packages.libpcap
- darwin.libpcap
6 days, 8 hours ago
-
@LeSuisse
accepted
6 days, 8 hours ago
-
@LeSuisse
published on GitHub
6 days, 8 hours ago
division by zero in libpcap before 1.10.7
Permalink
CVE-2026-18313
4.3 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): Low (L)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): Low (L)
updated
6 days, 8 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 17 hours ago
-
@LeSuisse
ignored
3 packages
- darwin.libpcap
- python313Packages.libpcap
- python314Packages.libpcap
6 days, 8 hours ago
-
@LeSuisse
accepted
6 days, 8 hours ago
-
@LeSuisse
published on GitHub
6 days, 8 hours ago
rpcapd memory leak in libpcap before 1.10.7
libxml2: security issues < 2.15.4
Permalink
CVE-2026-86143
6.9 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): High (H)
-
Integrity (I): High (H)
-
Availability (A): Low (L)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): Low (L)
updated
6 days, 8 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 17 hours ago
-
@LeSuisse
ignored
7 packages
- libxml2_13
- libxml2Python
- sbclPackages.cl-libxml2
- perlPackages.AlienLibxml2
- python313Packages.libxml2
- python314Packages.libxml2
- perl5Packages.AlienLibxml2
6 days, 8 hours ago
-
@LeSuisse
accepted
6 days, 8 hours ago
-
@LeSuisse
published on GitHub
6 days, 8 hours ago
In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback …
Permalink
CVE-2026-86142
6.9 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): High (H)
-
Integrity (I): High (H)
-
Availability (A): Low (L)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): Low (L)
updated
6 days, 8 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 17 hours ago
-
@LeSuisse
ignored
7 packages
- libxml2_13
- libxml2Python
- sbclPackages.cl-libxml2
- perlPackages.AlienLibxml2
- python313Packages.libxml2
- python314Packages.libxml2
- perl5Packages.AlienLibxml2
6 days, 8 hours ago
-
@LeSuisse
accepted
6 days, 8 hours ago
-
@LeSuisse
published on GitHub
6 days, 8 hours ago
In libxml2 before 2.15.4, there is a heap-based buffer overflow …
Permalink
CVE-2026-86138
6.9 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): High (H)
-
Integrity (I): High (H)
-
Availability (A): Low (L)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): Low (L)
updated
6 days, 8 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 17 hours ago
-
@LeSuisse
ignored
7 packages
- libxml2_13
- libxml2Python
- sbclPackages.cl-libxml2
- perlPackages.AlienLibxml2
- python313Packages.libxml2
- python314Packages.libxml2
- perl5Packages.AlienLibxml2
6 days, 8 hours ago
-
@LeSuisse
accepted
6 days, 8 hours ago
-
@LeSuisse
published on GitHub
6 days, 8 hours ago
In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer …
Permalink
CVE-2026-86144
5.6 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Changed (C)
-
Confidentiality (C): Low (L)
-
Integrity (I): Low (L)
-
Availability (A): Low (L)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): Low (L)
-
Modified Scope (MS): Changed (C)
-
Modified Integrity (MI): Low (L)
-
Modified Availability (MA): Low (L)
updated
6 days, 8 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 17 hours ago
-
@LeSuisse
ignored
7 packages
- libxml2Python
- sbclPackages.cl-libxml2
- perlPackages.AlienLibxml2
- python313Packages.libxml2
- python314Packages.libxml2
- perl5Packages.AlienLibxml2
- libxml2_13
6 days, 8 hours ago
-
@LeSuisse
accepted
6 days, 8 hours ago
-
@LeSuisse
published on GitHub
6 days, 8 hours ago
In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do …
Permalink
CVE-2026-86139
6.9 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): High (H)
-
Integrity (I): High (H)
-
Availability (A): Low (L)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): Low (L)
updated
6 days, 8 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 17 hours ago
-
@LeSuisse
ignored
7 packages
- libxml2_13
- libxml2Python
- sbclPackages.cl-libxml2
- perlPackages.AlienLibxml2
- python313Packages.libxml2
- python314Packages.libxml2
- perl5Packages.AlienLibxml2
6 days, 8 hours ago
-
@LeSuisse
accepted
6 days, 8 hours ago
-
@LeSuisse
published on GitHub
6 days, 8 hours ago
In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer …
Permalink
CVE-2026-86141
2.9 LOW
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): Low (L)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): Low (L)
updated
6 days, 8 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 17 hours ago
-
@LeSuisse
ignored
7 packages
- libxml2_13
- libxml2Python
- sbclPackages.cl-libxml2
- perlPackages.AlienLibxml2
- python313Packages.libxml2
- python314Packages.libxml2
- perl5Packages.AlienLibxml2
6 days, 8 hours ago
-
@LeSuisse
accepted
6 days, 8 hours ago
-
@LeSuisse
published on GitHub
6 days, 8 hours ago
xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference …
Permalink
CVE-2026-86137
2.9 LOW
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): Low (L)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): Low (L)
updated
6 days, 8 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 17 hours ago
-
@LeSuisse
ignored
7 packages
- libxml2_13
- libxml2Python
- sbclPackages.cl-libxml2
- perlPackages.AlienLibxml2
- python313Packages.libxml2
- python314Packages.libxml2
- perl5Packages.AlienLibxml2
6 days, 8 hours ago
-
@LeSuisse
accepted
6 days, 8 hours ago
-
@LeSuisse
published on GitHub
6 days, 8 hours ago
In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka …
Permalink
CVE-2026-86140
8.0 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): High (H)
-
Integrity (I): High (H)
-
Availability (A): Low (L)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): Low (L)
updated
6 days, 8 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 17 hours ago
-
@LeSuisse
ignored
7 packages
- libxml2_13
- libxml2Python
- sbclPackages.cl-libxml2
- perlPackages.AlienLibxml2
- python313Packages.libxml2
- python314Packages.libxml2
- perl5Packages.AlienLibxml2
6 days, 8 hours ago
-
@LeSuisse
accepted
6 days, 8 hours ago
-
@LeSuisse
published on GitHub
6 days, 8 hours ago
In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat …