863 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2026-6527
Wireshark General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-674 1 PoC

ASN.1 PER protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVE-2026-25541
bytes Web
5.5
MEDIUM
EPSS
0.0%
2026 CWE-680 1 PoC

Bytes is a utility library for working with bytes. From version 1.2.1 to before 1.11.1, Bytes is vulnerable to integer overflow in BytesMut::reserve. In the unique reclaim path of BytesMut::reserve, if the condition "v_capacity >= new_cap + offset" uses an unchecked addition. When new_cap + offset overflows usize in release builds, this condition may incorrectly pass, causing self.cap to be set to a value that exceeds the actual allocated capacity. Subsequent APIs such as spare_capacity_mut() then trust this corrupted cap value and may create out-of-bounds slices, leading to UB. This behavior

CVE-2026-6867
Wireshark Windows
5.5
MEDIUM
EPSS
0.0%
2026 CWE-1325 1 PoC

SMB2 protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVE-2026-22795
OpenSSL General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-754 1 PoC

Issue summary: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file. Impact summary: An application processing a malformed PKCS#12 file can be caused to dereference an invalid or NULL pointer on memory read, resulting in a Denial of Service. A type confusion vulnerability exists in PKCS#12 parsing code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid pointer read. The location is constrained to a 1-byte address space, meaning any attempted pointer manipulation can only target addresses betwee

CVE-2026-7379
Wireshark General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-401 1 PoC

Memory leak in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVE-2026-7378
Wireshark General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-122 1 PoC

Crash in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVE-2026-28288
dify Web ⚡ nuclei
5.5
MEDIUM
EPSS
0.5%
2026 CWE-204 0 PoCs

Dify is an open-source LLM app development platform. Prior to 1.9.0, responses from the Dify API to existing and non-existent accounts differ, allowing an attacker to enumerate email addresses registered with Dify. Version 1.9.0 fixes the issue.

CVE-2026-3777
Foxit PDF Editor Web
5.5
MEDIUM
EPSS
0.0%
2026 CWE-416 1 PoC

The application does not properly validate the lifetime and validity of internal view cache pointers after JavaScript changes the document zoom and page state. When a script modifies the zoom property and then triggers a page change, the original view object may be destroyed while stale pointers are still kept and later dereferenced, which under crafted JavaScript and document structures can lead to a use-after-free condition and potentially allow arbitrary code execution.

CVE-2026-7375
Wireshark General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-835 1 PoC

UDS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVE-2026-6521
Wireshark General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-835 1 PoC

OpenFlow v5 protocol dissector infinite loops in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVE-2026-3776
Foxit PDF Editor General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-476 1 PoC

The application does not validate the presence of required appearance (AP) data before accessing stamp annotation resources. When a PDF contains a stamp annotation missing its AP entry, the code continues to dereference the associated object without a prior null or validity check, which allows a crafted document to trigger a null pointer dereference and crash the application, resulting in denial of service.

CVE-2026-6519
Wireshark General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-835 1 PoC

MBIM protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVE-2026-6528
Wireshark General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-835 1 PoC

TLS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 allows denial of service

CVE-2026-3563
PowerShell Universal General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-1289 1 PoC

Improper input validation in the apps and endpoints configuration in PowerShell Universal before 2026.1.4 allows an authenticated user with permissions to create or modify Apps or Endpoints to override existing application or system routes, resulting in unintended request routing and denial of service via a conflicting URL path.

CVE-2026-6526
Wireshark General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-476 1 PoC

RTSP protocol dissector crash in Wireshark 4.6.0 to 4.6.4

CVE-2026-6529
Wireshark General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-122 1 PoC

iLBC audio codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVE-2026-6524
Wireshark Database
5.5
MEDIUM
EPSS
0.0%
2026 CWE-824 1 PoC

MySQL protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVE-2026-6869
Wireshark General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-1325 1 PoC

WebSocket protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVE-2026-7376
Wireshark General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-476 1 PoC

Crash in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVE-2026-6522
Wireshark Networking
5.5
MEDIUM
EPSS
0.0%
2026 CWE-835 1 PoC

RPKI-Router protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service