home.social
  1. 🚨 EUVD-2026-94130

    📊 Score: 8.1/10 (CVSS v3.1)
    📦 Product: Langflow OSS
    🏢 Vendor: IBM
    📅 Updated: 2026-10-06

    📝 IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  2. 🚨 EUVD-2026-94131

    📊 Score: 9.8/10 (CVSS v3.1)
    📦 Product: Langflow OSS
    🏢 Vendor: IBM
    📅 Updated: 2026-10-06

    📝 IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper control of code generation.

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  3. 🚨 EUVD-2026-94129

    📊 Score: 7.7/10 (CVSS v3.1)
    📦 Product: Langflow OSS
    🏢 Vendor: IBM
    📅 Updated: 2026-10-06

    📝 IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to insufficiently protected credentials.

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  4. 🚨 EUVD-2026-94128

    📊 Score: 6.5/10 (CVSS v3.1)
    📦 Product: Langflow OSS
    🏢 Vendor: IBM
    📅 Updated: 2026-10-06

    📝 IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper access control.

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  5. 🚨 EUVD-2026-94127

    📊 Score: 8.8/10 (CVSS v3.1)
    📦 Product: Langflow OSS
    🏢 Vendor: IBM
    📅 Updated: 2026-10-06

    📝 IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in code, resulting in a sandbox escape.

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  6. 🚨 EUVD-2026-94125

    📊 Score: 8.3/10 (CVSS v3.1)
    📦 Product: Langflow OSS
    🏢 Vendor: IBM
    📅 Updated: 2026-10-06

    📝 IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information or inject malicious data due to improper access control in the vertex result caching subsystem.

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  7. 🚨 EUVD-2026-94126

    📊 Score: 8.8/10 (CVSS v3.1)
    📦 Product: Langflow OSS
    🏢 Vendor: IBM
    📅 Updated: 2026-10-06

    📝 IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to an incomplete blocklist in the code security scanner.

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  8. 🚨 EUVD-2026-94124

    📊 Score: 8.8/10 (CVSS v3.1)
    📦 Product: Langflow OSS
    🏢 Vendor: IBM
    📅 Updated: 2026-10-06

    📝 IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command ('Code Injection') related to improper input validation.

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  9. 🚨 EUVD-2026-94123

    📊 Score: 8.8/10 (CVSS v3.1)
    📦 Product: Langflow OSS
    🏢 Vendor: IBM
    📅 Updated: 2026-10-06

    📝 IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper input validation.

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  10. 🚨 EUVD-2026-94122

    📊 Score: 8.1/10 (CVSS v3.1)
    📦 Product: Langflow OSS
    🏢 Vendor: IBM
    📅 Updated: 2026-10-06

    📝 IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command ('Code Injection'), aka improper control of code generation.

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  11. 🚨 EUVD-2026-94121

    📊 Score: 8.8/10 (CVSS v3.1)
    📦 Product: Langflow OSS
    🏢 Vendor: IBM
    📅 Updated: 2026-10-07

    📝 IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper input validation.

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  12. 🚨 EUVD-2026-94120

    📊 Score: 6.5/10 (CVSS v3.1)
    📦 Product: Langflow OSS
    🏢 Vendor: IBM
    📅 Updated: 2026-10-07

    📝 IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to a path traversal vulnerability.

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  13. 🚨 EUVD-2026-94119

    📊 Score: 9.8/10 (CVSS v3.1)
    📦 Product: Langflow OSS
    🏢 Vendor: IBM
    📅 Updated: 2026-10-07

    📝 IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  14. 🚨 EUVD-2026-94118

    📊 Score: 4.3/10 (CVSS v3.1)
    📦 Product: Langflow OSS
    🏢 Vendor: IBM
    📅 Updated: 2026-10-07

    📝 IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to cause a denial of service due to uncontrolled resource consumption during ZIP file extraction.

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  15. 🚨 EUVD-2026-94117

    📊 Score: 7.6/10 (CVSS v3.1)
    📦 Product: Langflow OSS
    🏢 Vendor: IBM
    📅 Updated: 2026-10-07

    📝 IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper authorization.

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  16. 🚨 EUVD-2026-94116

    📊 Score: 7.7/10 (CVSS v3.1)
    📦 Product: Langflow OSS
    🏢 Vendor: IBM
    📅 Updated: 2026-10-07

    📝 IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to exposure of sensitive information to an unauthorized actor.

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  17. 🚨 EUVD-2026-94115

    📊 Score: 8.8/10 (CVSS v3.1)
    📦 Product: Langflow OSS
    🏢 Vendor: IBM
    📅 Updated: 2026-10-07

    📝 IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to an expected dependency confusion.

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  18. 🚨 EUVD-2026-94114

    📊 Score: 7.5/10 (CVSS v3.1)
    📦 Product: Langflow OSS
    🏢 Vendor: IBM
    📅 Updated: 2026-10-07

    📝 IBM Langflow OSS 1.0.0 through 1.12.2 could allow an attacker with access to the server secret and Redis write access to submit a malicious serialized cache value. When the value was retrieved, deserialization could have executed attacker-controlled code wi...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  19. 🚨 EUVD-2026-94112

    📊 Score: 8.5/10 (CVSS v3.1)
    📦 Product: Langflow OSS
    🏢 Vendor: IBM
    📅 Updated: 2026-10-07

    📝 IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper control of code generation.

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  20. 🚨 EUVD-2026-94113

    📊 Score: 8.1/10 (CVSS v3.1)
    📦 Product: Langflow OSS
    🏢 Vendor: IBM
    📅 Updated: 2026-10-07

    📝 IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper control of generation of code.

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  21. 🚨 EUVD-2026-94111

    📊 Score: 6.5/10 (CVSS v3.1)
    📦 Product: Langflow OSS
    🏢 Vendor: IBM
    📅 Updated: 2026-10-07

    📝 IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  22. 🚨 EUVD-2026-94109

    📊 Score: 7.5/10 (CVSS v3.1)
    📦 Product: Langflow OSS
    🏢 Vendor: IBM
    📅 Updated: 2026-10-07

    📝 IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in code.

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  23. 🚨 EUVD-2026-94110

    📊 Score: 8.8/10 (CVSS v3.1)
    📦 Product: Langflow OSS
    🏢 Vendor: IBM
    📅 Updated: 2026-10-07

    📝 IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper control of code generation.

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  24. 🚨 EUVD-2026-4495

    📊 Score: 6.0/10 (CVSS v3.1)
    📦 Product: Omada Gateway (ER605W 2.0), Omada Access Point (EAP653 UR v1.0), Omada Access Point (EAP603GP-Desktop, EAP615GP-Wall 1.20, EAP625GP-Wall 1.0/1.20, EAP610GP-Desktop 1.0/1.20/1.26), EAP650-Desktop v1.0) (+27 more)
    🏢 Vendor: TP-Link Systems Inc.
    📅 Published: 2026-01-22 | Updated: 2026-10-06

    📝 An authentication w...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  25. 🚨 EUVD-2026-94103

    📊 Score: n/a
    📅 Updated: 2026-10-06

    📝 A flaw was found in `sssd-kcm`. A local user or process able to connect to the `sssd-kcm` UNIX socket can exploit this vulnerability. By sending a large request length header and then stalling the connection, an attacker can cause the system to preallocate significant memory. This leads to memory exhaustion w...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  26. 🚨 EUVD-2026-94105

    📊 Score: 8.8/10 (CVSS v3.1)
    📦 Product: Langflow OSS
    🏢 Vendor: IBM
    📅 Updated: 2026-10-06

    📝 IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper access control.

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  27. 🚨 EUVD-2026-94104

    📊 Score: 2.5/10 (CVSS v3.1)
    📦 Product: OpenSSH
    🏢 Vendor: OpenBSD
    📅 Updated: 2026-10-06

    📝 In ssh in OpenSSH before 10.6, a $ or \ character can occur in a command-line username, leading to injection.

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  28. 🚨 EUVD-2026-94047

    📊 Score: 5.5/10 (CVSS v3.1)
    📦 Product: TensorRT
    🏢 Vendor: NVIDIA
    📅 Updated: 2026-10-06

    📝 NVIDIA TensorRT contains a vulnerability where an attacker can cause an out of bounds read. A successful exploit of this vulnerability may lead to denial of service.

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  29. 🚨 EUVD-2026-93812

    📊 Score: 9.6/10 (CVSS v3.1)
    📦 Product: Chrome
    🏢 Vendor: Google
    📅 Updated: 2026-10-06

    📝 Integer overflow in WebGL in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  30. 🚨 EUVD-2026-94049

    📊 Score: 7.8/10 (CVSS v3.1)
    📦 Product: Model-Optimizer
    🏢 Vendor: NVIDIA
    📅 Updated: 2026-10-06

    📝 NVIDIA Model-Optimizer contains a vulnerability where an attacker may cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  31. 🚨 EUVD-2026-93572

    📊 Score: 8.3/10 (CVSS v3.1)
    📦 Product: quasar, app-vite
    🏢 Vendor: @quasar, quasarframework
    📅 Updated: 2026-10-06

    📝 Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 3.3.0, several @quasar/app-vite SSR and SSG rendering paths interpolated ssrContext.nonce directly into quoted HTML attributes. An applic...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  32. 🚨 EUVD-2026-93571

    📊 Score: 7.1/10 (CVSS v3.1)
    📦 Product: app-vite, quasar, render-ssr-error
    🏢 Vendor: @quasar, quasarframework
    📅 Updated: 2026-10-06

    📝 Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to @quasar/render-ssr-error 2.2.4 and @quasar/app-vite 3.3.0, renderSSRError() in utils/render-ssr-error/src/index.js used...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  33. 🚨 EUVD-2025-211038

    📊 Score: n/a
    📅 Updated: 2026-10-06

    📝 LogicalDOC Enterprise up to and for 9.1.1 is vulnerable to blind SQL injection in the WorkflowsDataServlet component, allowing authenticated user to manipulate SQL queries via crafted workflow template name.

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  34. 🚨 EUVD-2025-12236

    📊 Score: 5.4/10 (CVSS v3.1)
    📦 Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9.4 Extended Update Support, Red Hat Enterprise Linux 10 (+2 more)
    🏢 Vendor: Red Hat
    📅 Published: 2025-04-23 | Updated: 2026-10-06

    📝 A vulnerability was found in mod_proxy_cluster. The issue is that the <Directory> directive should be replaced by the <Lo...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  35. 🚨 EUVD-2026-93573

    📊 Score: 4.1/10 (CVSS v3.1)
    📦 Product: quasar, app-vite
    🏢 Vendor: @quasar, quasarframework
    📅 Updated: 2026-10-06

    📝 Quasar Framework is a framework for building high-performance Vue.js user interfaces. From 1.0.0 until 3.3.0, @quasar/app-vite recursively removed the resolved build.distDir before building without rejecting the project root, user h...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  36. 🚨 EUVD-2026-93574

    📊 Score: 7.5/10 (CVSS v3.1)
    📦 Product: ImageSharp
    🏢 Vendor: SixLabors
    📅 Updated: 2026-10-06

    📝 ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, the TIFF CCITT Group 3 encoder allocates an undersized compressed-data buffer for narrow 1-bit images. TiffCcittCompressor.Initialize does not reserve enough space for the row data and T4 end-...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  37. 🚨 EUVD-2026-86316

    📊 Score: 6.2/10 (CVSS v3.1)
    📅 Published: 2026-09-24 | Updated: 2026-10-06

    📝 libical 4.0.6 contains an incompatible function pointer in icalparameter_string_to_kind(). When parsing iCalendar data containing a parameterized property, the function passes icalparameter_compare_kind_map() to bsearch() through an incompatible comparator function point...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  38. 🚨 EUVD-2026-86270

    📊 Score: 5.5/10 (CVSS v3.1)
    📅 Published: 2026-09-24 | Updated: 2026-10-06

    📝 ZBar commit 2ea2ca58 contains an undefined-behavior vulnerability in the Code 128 decode6() function. When processing specially crafted Code 128 input, decode_e() can return -1 for an invalid edge pattern, and decode6() subsequently left-shifts this negative signed value...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  39. 🚨 EUVD-2026-86265

    📊 Score: 7.5/10 (CVSS v3.1)
    📅 Published: 2026-09-24 | Updated: 2026-10-06

    📝 NanoSVG commit 239e102ec contains an incorrect numeric conversion vulnerability in nsvg__pathArcTo() when parsing SVG arc commands. A specially crafted SVG document containing extreme arc radius values can cause intermediate arc calculations to produce a NaN delta angle....

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  40. 🚨 EUVD-2026-84551

    📊 Score: 6.1/10 (CVSS v3.1)
    📅 Published: 2026-09-22 | Updated: 2026-10-06

    📝 webpy web.py 0.76 is vulnerable to Cross Site Scripting (XSS) via render_jinja.__init__().

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  41. 🚨 EUVD-2026-86286

    📊 Score: 7.5/10 (CVSS v3.1)
    📅 Published: 2026-09-24 | Updated: 2026-10-06

    📝 An incorrect buffer size calculation vulnerability exists in tinyexpr commit 4a7456e in new_expr(). For arity-0 expression nodes, including constants, variables, and zero-argument functions, the function allocates less memory than sizeof(te_expr) but treats the returned ...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  42. 🚨 EUVD-2026-93575

    📊 Score: 8.8/10 (CVSS v3.1)
    📦 Product: OpenManage Integration
    🏢 Vendor: Dell
    📅 Updated: 2026-10-06

    📝 Dell OpenManage Integration with Microsoft Windows Admin Center, versions prior to 3.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote ...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  43. 🚨 EUVD-2026-93576

    📊 Score: 5.9/10 (CVSS v3.1)
    📦 Product: ImageSharp
    🏢 Vendor: SixLabors
    📅 Updated: 2026-10-06

    📝 ImageSharp is a 2D graphics library. From 4.0.0 until 4.1.2, ExrBaseDecompressor.UndoZipCompression accepts a nonempty ZIP or ZIPS inflate result that is shorter than the EXR block's required size. ZipExrCompression.Decompress reconstructs the returned ...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  44. 🚨 EUVD-2026-93553

    📊 Score: 7.5/10 (CVSS v3.1)
    📦 Product: ImageSharp
    🏢 Vendor: SixLabors
    📅 Updated: 2026-10-06

    📝 ImageSharp is a 2D graphics library. From 4.0.0 until 4.1.2, ICC LUT16 conversion accepts more than four output channels even though ClutCalculator.Calculate and LutEntryCalculator.CalculateLut store intermediate and output values in Vector4. When Decod...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  45. 🚨 EUVD-2026-93554

    📊 Score: 7.5/10 (CVSS v3.1)
    📦 Product: ImageSharp
    🏢 Vendor: SixLabors
    📅 Updated: 2026-10-06

    📝 ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, decoding an attacker-supplied 32-bit floating-point TIFF as Image<HalfVector4> and applying HistogramEqualization can produce a non-finite or out-of-range luminance in ColorNumerics.GetBT709Lu...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  46. 🚨 EUVD-2026-93556

    📊 Score: 5.3/10 (CVSS v3.1)
    📦 Product: ImageSharp
    🏢 Vendor: SixLabors
    📅 Updated: 2026-10-06

    📝 ImageSharp is a 2D graphics library. From 1.0.0-beta0001 until 4.1.2, ICC CLUT parsing calculates allocation sizes from attacker-declared channel and grid dimensions before confirming that the profile contains the declared values. IccDataReader.ReadClut...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  47. 🚨 EUVD-2026-93558

    📊 Score: 4.7/10 (CVSS v3.1)
    📅 Updated: 2026-10-06

    📝 A flaw was found in sssd. A local user can cause a Denial of Service (DoS) by exhausting the responder service's available file descriptors (system handles used for open connections). By opening and maintaining many concurrent connections to a responder socket while continuing to queue new conn...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  48. 🚨 EUVD-2026-93557

    📊 Score: 7.5/10 (CVSS v3.1)
    📦 Product: ImageSharp
    🏢 Vendor: SixLabors
    📅 Updated: 2026-10-06

    📝 ImageSharp is a 2D graphics library. From 2.1.0 until 4.1.2, the TIFF CCITT Group 4 encoder allocates Width times rowsPerStrip bytes even though T6BitCompressor.CompressStrip can emit encoded row data and two 12-bit end-of-facsimile-block codes beyond t...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  49. 🚨 EUVD-2026-93559

    📊 Score: 5.3/10 (CVSS v3.1)
    📦 Product: ImageSharp
    🏢 Vendor: SixLabors
    📅 Updated: 2026-10-06

    📝 ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, ExifReader.ReadValues64 trusts the 64-bit BigTIFF IFD entry count and iterates once per declared entry. When fewer than 20 bytes remain, ExifReader.ReadValue64 returns without advancing the st...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  50. 🚨 EUVD-2026-93560

    📊 Score: 7.5/10 (CVSS v3.1)
    📦 Product: ImageSharp
    🏢 Vendor: SixLabors
    📅 Updated: 2026-10-06

    📝 ImageSharp is a 2D graphics library. From 3.0.0 until 4.1.1, decoding a strip TIFF using CCITT Group 3 or Modified Huffman compression can pass attacker-expanded runs to BitWriterUtils.WriteBits without first checking the current row width. T4TiffCompre...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

Share on Mastodon

Enter the server where you have an account.