|
cve-2026-9545
|
In this scenario, libcurl first uses a proper HTTP/3 server for the initial
transfers, and when it makes a second tra... |
HIGH
|
7.5
|
0.41%
|
cvelistv5 |
2026-09-15 |
|
cve-2026-9539
|
SUSE CVE CVE-2026-9539 |
MEDIUM
|
6.5
|
0.22%
|
cvelistv5 |
2026-07-28 |
|
cve-2026-9256
|
SUSE CVE CVE-2026-9256 |
HIGH
|
8.1
|
2.70%
|
cvelistv5 |
2026-08-26 |
|
cve-2026-9080
|
libcurl: libcurl: Use-after-free via curl_easy_pause() in CURLMOPT_SOCKETFUNCTION callback |
HIGH
|
7.3
|
0.49%
|
cvelistv5 |
2026-09-01 |
|
cve-2026-9079
|
libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials |
HIGH
|
7.5
|
0.58%
|
cvelistv5 |
2026-08-31 |
|
cve-2026-9064
|
389-ds-base: 389-ds-base: unbounded LDAP controls count in get_ldapmessage_controls_ext() causes CPU and heap amplification (remote DoS) |
HIGH
|
7.5
|
1.08%
|
cvelistv5 |
2026-08-21 |
|
cve-2026-8927
|
When reusing a libcurl handle for sequential transfers driven by
environment-variable proxy configuration, libcurl fa... |
CRITICAL
|
9.1
|
0.50%
|
cvelistv5 |
2026-09-15 |
|
cve-2026-8924
|
A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set
"super cookies" that bypass the Public ... |
CRITICAL
|
9.1
|
0.66%
|
cvelistv5 |
2026-09-15 |
|
cve-2026-8631
|
SUSE CVE CVE-2026-8631 |
CRITICAL
|
9.8
|
1.14%
|
cvelistv5 |
2026-07-31 |
|
cve-2026-8458
|
libcurl might in some circumstances reuse the wrong connection when asked to
do Negotiate-authenticated ones, even wh... |
MEDIUM
|
6.5
|
0.37%
|
cvelistv5 |
2026-09-15 |
|
cve-2026-8357
|
libreoffice: LibreOffice Calc: Arbitrary code execution via heap buffer overflow in formula compilation |
HIGH
|
7.8
|
0.23%
|
cvelistv5 |
2026-07-28 |
|
cve-2026-8286
|
curl: curl: Insecure connection establishment due to TLS configuration mismatch |
HIGH
|
8.1
|
0.52%
|
cvelistv5 |
2026-09-02 |
|
cve-2026-8177
|
XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing tr... |
HIGH
|
7.5
|
0.88%
|
cvelistv5 |
2026-09-18 |
|
cve-2026-7568
|
php: signed integer overflow in metaphone() |
HIGH
|
7.5
|
0.84%
|
cvelistv5 |
2026-07-01 |
|
cve-2026-7511
|
PKCS7_verify signer confusion allows forged signatures to be accepted |
MEDIUM
|
5.9
|
0.26%
|
cvelistv5 |
2026-06-26 |
|
cve-2026-7263
|
SUSE CVE CVE-2026-7263 |
HIGH
|
7.5
|
0.63%
|
cvelistv5 |
2026-07-15 |
|
cve-2026-7262
|
SUSE CVE CVE-2026-7262 |
MEDIUM
|
5.3
|
1.05%
|
cvelistv5 |
2026-07-15 |
|
cve-2026-7258
|
PHP: PHP: Denial of Service via improper handling of signed characters in ctype functions |
MEDIUM
|
5.9
|
0.40%
|
cvelistv5 |
2026-07-01 |
|
cve-2026-6735
|
SUSE CVE CVE-2026-6735 |
MEDIUM
|
6.3
|
0.31%
|
cvelistv5 |
2026-07-07 |
|
cve-2026-6734
|
SUSE CVE CVE-2026-6734 |
HIGH
|
8.8
|
0.39%
|
cvelistv5 |
2026-08-30 |
|
cve-2026-6733
|
undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery. |
LOW
|
3.7
|
0.27%
|
cvelistv5 |
2026-08-19 |
|
cve-2026-6731
|
X.509 name constraint bypass via Subject CN treated as a DNS name |
MEDIUM
|
6.0
|
0.20%
|
cvelistv5 |
2026-06-26 |
|
cve-2026-6681
|
PKCS#7 decode ignores caller output buffer size, writing past buffer bounds |
LOW
|
1.0
|
0.38%
|
cvelistv5 |
2026-06-26 |
|
cve-2026-6678
|
Integer underflow in wc_PKCS7_DecryptOri handling crafted Other Recipient Info |
LOW
|
1.0
|
0.33%
|
cvelistv5 |
2026-07-01 |
|
cve-2026-6478
|
SUSE CVE CVE-2026-6478 |
MEDIUM
|
6.5
|
0.56%
|
cvelistv5 |
2026-09-11 |
|
cve-2026-6477
|
postgresql: PostgreSQL libpq: Buffer overflow allows server superuser to overwrite client stack memory |
HIGH
|
8.4
|
0.45%
|
cvelistv5 |
2026-08-25 |
|
cve-2026-6475
|
SUSE CVE CVE-2026-6475 |
HIGH
|
8.8
|
0.32%
|
cvelistv5 |
2026-09-11 |
|
cve-2026-6473
|
SUSE CVE CVE-2026-6473 |
HIGH
|
8.8
|
1.01%
|
cvelistv5 |
2026-09-11 |
|
cve-2026-6450
|
CRL critical extension bypass in ParseCRL_Extensions |
LOW
|
1.0
|
0.33%
|
cvelistv5 |
2026-06-26 |
|
cve-2026-6331
|
HMAC zero-length tag forgery in EVP_DigestVerifyFinal |
LOW
|
2.1
|
0.19%
|
cvelistv5 |
2026-06-26 |