|
1921
|
9.8 |
CRITICAL
Network
|
exim
|
exim
|
In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrusted header, because of an incorrect implementation…
|
CWE-684 CWE-787
Incorrect Provision of Specified Functionality Out-of-bounds Write
|
CVE-2026-40685
|
2026-05-2 02:51 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1922
|
5.5 |
MEDIUM
Local
|
opencascade
|
open_cascade_technology
|
An out-of-bounds read vulnerability in VrmlData_IndexedLineSet::TShape in the VRML parser in Open CASCADE Technology (OCCT) V8_0_0_rc5 allows attackers to cause a denial of service via a crafted VRML…
|
CWE-125
Out-of-bounds Read
|
CVE-2026-42479
|
2026-05-2 02:48 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1923
|
6.5 |
MEDIUM
Adjacent
|
frrouting
|
frrouting
|
FRRouting before 10.5.3 contains an integer overflow vulnerability in seven OSPF Traffic Engineering and Segment Routing TLV parser functions where a uint16_t accumulator variable truncates uint32_t …
|
CWE-125 CWE-190
Out-of-bounds Read Integer Overflow or Wraparound
|
CVE-2026-28532
|
2026-05-2 02:48 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1924
|
7.5 |
HIGH
Network
|
opencascade
|
open_cascade_technology
|
An issue was discovered in VrmlData_IndexedFaceSet::TShape in the VRML V2.0 parser in Open CASCADE Technology (OCCT) V8_0_0_rc5 allows attackers to cause a denial of service via a crafted VRML file. …
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-42478
|
2026-05-2 02:48 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1925
|
7.1 |
HIGH
Local
|
opencascade
|
open_cascade_technology
|
A heap-based out-of-bounds read vulnerability in RWObj_Reader::read in the OBJ file parser in Open CASCADE Technology (OCCT) V8_0_0_rc5 allows user-assisted attackers to cause a denial of service or …
|
CWE-125
Out-of-bounds Read
|
CVE-2026-42477
|
2026-05-2 02:48 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1926
|
7.1 |
HIGH
Local
|
opencascade
|
open_cascade_technology
|
Two heap-based out-of-bounds read vulnerabilities in the STL ASCII file parser in Open CASCADE Technology (OCCT) V8_0_0_rc5 exist in RWStl_Reader::ReadAscii because buffers returned by Standard_ReadL…
|
CWE-125
Out-of-bounds Read
|
CVE-2026-42476
|
2026-05-2 02:47 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1927
|
9.8 |
CRITICAL
Network
|
hashcat
|
hashcat
|
A heap-based buffer overflow in hex_to_binary in the PKZIP hash parser in hashcat v7.1.2 allows an attacker to cause a denial of service or possibly execute arbitrary code via a crafted PKZIP hash fi…
|
CWE-787
Out-of-bounds Write
|
CVE-2026-42484
|
2026-05-2 02:45 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1928
|
10.0 |
CRITICAL
Network
|
traefik
|
traefik
|
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is an authentication bypass vulnerability in Traefik's ForwardAuth middleware when trustFo…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2026-35051
|
2026-05-2 02:45 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1929
|
9.8 |
CRITICAL
Network
|
hashcat
|
hashcat
|
A stack-based buffer overflow in mangle_to_hex_lower() and mangle_to_hex_upper() in src/rp_cpu.c in hashcat v7.1.2 allows an attacker to cause a denial of service or possibly execute arbitrary code v…
|
CWE-787
Out-of-bounds Write
|
CVE-2026-42482
|
2026-05-2 02:45 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1930
|
10.0 |
CRITICAL
Network
|
traefik
|
traefik
|
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high severity authentication bypass vulnerability in Traefik's ForwardAuth and snippe…
|
CWE-290 CWE-306
Authentication Bypass by Spoofing Missing Authentication for Critical Function
|
CVE-2026-39858
|
2026-05-2 02:44 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|