Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

35791 risultati

VulnerabilitàAlta
CVE-2026-45253 - Missing validation in ptrace(PT_SC_REMOTE)

CVE ID :CVE-2026-45253 Published : May 21, 2026, 10:16 a.m. | 2 hours, 1 minute ago Description :ptrace(PT_SC_REMOTE) failed to properly validate parameters for the syscall(2) and __syscall(2) meta-system calls. As a result, a user with the ability to debug a process may trigger arbitrary code execution in the kernel, even if the target process has no special privileges. The missing validation allows an unprivileged local user to escalate privileges, potentially gaining full control of the affected system. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mag 2026
VulnerabilitàAlta
CVE-2026-45250 - Stack buffer overflow via setcred(2)

CVE ID :CVE-2026-45250 Published : May 21, 2026, 9:16 a.m. | 3 hours, 1 minute ago Description :The setcred(2) system call is only available to privileged users. However, before the privilege level of the caller is checked, the user-supplied list of supplementary groups is copied into a fixed-size kernel stack buffer without first validating its length. If the supplied list exceeds the capacity of that buffer, a stack buffer overflow occurs. Because the bounds check on the supplementary groups list occurs after the kernel stack buffer has already been written, an unprivileged local user may trigger the overflow without holding any special privilege. Successful exploitation may allow an attacker to execute arbitrary code in the context of the kernel, allowing an unprivileged local user to gain elevated privileges on the affected system. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mag 2026
VulnerabilitàAlta
CVE-2026-7837 - TOCTOU with root privilege in ad_flush

CVE ID :CVE-2026-7837 Published : May 21, 2026, 9:16 a.m. | 3 hours, 1 minute ago Description :A time-of-check time-of-use (TOCTOU) condition in the ad_flush function in Netatalk 3.0.0 through 4.4.2 involves root-privileged file operations, which may allow a remote attacker to cause limited data modification under specific race conditions. Severity: 3.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mag 2026
VulnerabilitàAlta
CVE-2026-5433 - Improper Sanitization in CNM Web Interface

CVE ID :CVE-2026-5433 Published : May 21, 2026, 9:16 a.m. | 3 hours, 1 minute ago Description :Honeywell Control Network Module (CNM) contains command injection vulnerability in the web interface. An attacker could exploit this vulnerability via command delimiters, potentially resulting in Remote Code Execution (RCE). Severity: 9.1 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mag 2026
VulnerabilitàAlta
CVE-2026-5434 - Improper storage of sensitive information

CVE ID :CVE-2026-5434 Published : May 21, 2026, 9:16 a.m. | 3 hours, 1 minute ago Description :Honeywell Control Network Module (CNM) contains insertion of sensitive information into an unintended directory. An attacker could exploit this vulnerability through probing system files, potentially resulting in unintended access to protected data. Severity: 5.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mag 2026
VulnerabilitàAlta
CVE-2026-9157 - Remote Code Execution in Gmission Web FAX

CVE ID :CVE-2026-9157 Published : May 21, 2026, 9:16 a.m. | 3 hours, 1 minute ago Description :Improper input validation, Unrestricted upload of file with dangerous type vulnerability in Gmission Web Fax allows Remote Code Inclusion. This issue affects Web Fax: from 3.0 before 3.1. Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mag 2026
VulnerabilitàAlta
CVE-2026-4858 - Path traversal in integration action URL leading to arbitrary API execution via system admin’s auth token.

CVE ID :CVE-2026-4858 Published : May 21, 2026, 9:16 a.m. | 3 hours, 1 minute ago Description :Mattermost versions 11.6.x Severity: 8.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mag 2026
VulnerabilitàAlta
CVE-2026-44071 - FORTIFY_SOURCE disabled

CVE ID :CVE-2026-44071 Published : May 21, 2026, 9:16 a.m. | 3 hours, 1 minute ago Description :Netatalk 3.1.2 through 4.4.2 is compiled without FORTIFY_SOURCE, which disables built-in buffer overflow detection at runtime, potentially allowing a remote attacker to cause a minor denial of service via memory errors that would otherwise be caught and safely terminated by runtime protection. Severity: 3.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mag 2026
VulnerabilitàAlta
CVE-2026-44074 - Bitwise OR of errno values

CVE ID :CVE-2026-44074 Published : May 21, 2026, 9:16 a.m. | 3 hours, 1 minute ago Description :Netatalk 2.1.0 through 4.4.2 combines multiple errno values using bitwise OR, resulting in incorrect error codes when multiple error conditions occur simultaneously, which may allow a remote attacker to cause a minor service disruption via conditions that trigger incorrect error-handling paths. Severity: 3.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mag 2026
VulnerabilitàAlta
CVE-2026-44075 - Missing break in DSI OpenSession

CVE ID :CVE-2026-44075 Published : May 21, 2026, 9:16 a.m. | 3 hours, 1 minute ago Description :A missing break statement in DSI OpenSession processing in Netatalk 1.5.0 through 4.4.2 causes a DSIOPT_ATTNQUANT switch case to fall through into DSIOPT_SERVQUANT, resulting in unintended session option handling that may allow a remote attacker to cause a minor service disruption via crafted DSI session options. Severity: 3.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mag 2026
VulnerabilitàAlta
CVE-2026-44057 - Dead bounds check in Spotlight RPC unmarshaller

CVE ID :CVE-2026-44057 Published : May 21, 2026, 9:16 a.m. | 3 hours, 1 minute ago Description :A dead bounds check in the Spotlight RPC unmarshaller in Netatalk 3.0.0 through 4.4.2 results in an unreachable code path that provides no effective bounds protection, which may allow a remote authenticated attacker to obtain limited information via crafted Spotlight RPC requests. Severity: 3.1 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mag 2026
VulnerabilitàAlta
CVE-2026-22880 - Mobile SSO authentication flow allows credential theft via malicious server

CVE ID :CVE-2026-22880 Published : May 21, 2026, 9:16 a.m. | 1 hour ago Description :Mattermost Mobile Apps versions Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mag 2026

Pagina 1513 di 2983

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.