Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

37305 risultati

VulnerabilitàAlta
CVE-2026-37525 - AGL app-framework-binder (afb-daemon) Privilege Escalation Vulnerability

CVE ID :CVE-2026-37525 Published : May 1, 2026, 5:16 p.m. | 1 hour, 2 minutes ago Description :AGL app-framework-binder (afb-daemon) through v19.90.0 contains a privilege escalation vulnerability in the supervision Do command. The on_supervision_call function in src/afb-supervision.c explicitly nullifies the request credentials by calling afb_context_change_cred(&xreq->context, NULL) before dispatching an attacker-controlled API call via xapi->itf->call(xapi->closure, xreq). The NULL propagation chain through afb-context.c:110 (context->credentials = afb_cred_addref(NULL)) and afb-cred.c:163 (returns NULL when cred is NULL) confirms that credentials are zeroed before the target API executes. The attacker controls both api and verb parameters via JSON input, allowing execution of any registered API with a NULL credential context. APIs that rely on context->credentials for authorization decisions may fail open when receiving NULL credentials, enabling privilege escalation. This vulnerability was introduced in commit abbb4599f0b921c6f434b6bd02bcfb277eecf745 on 2018-02-14. Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 mag 2026
VulnerabilitàAlta
CVE-2026-37530 - AGL agl-service-can-low-level Stack Buffer Overflow Vulnerability

CVE ID :CVE-2026-37530 Published : May 1, 2026, 5:16 p.m. | 1 hour, 2 minutes ago Description :AGL agl-service-can-low-level thru 17.1.12 contains a stack buffer overflow in the uds-c library. The send_diagnostic_request function in uds.c allocates a 6-byte stack buffer (MAX_DIAGNOSTIC_PAYLOAD_SIZE=6) but copies up to 7 bytes (MAX_UDS_REQUEST_PAYLOAD_LENGTH=7) via memcpy at an offset of 1+pid_length (2-3 bytes), resulting in 1-4 bytes of controlled stack overflow. The payload_length field (uint8_t) has no bounds check against the destination buffer. On 32-bit ARM automotive ECUs without stack canaries, this can lead to return address overwrite and RCE. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 mag 2026
VulnerabilitàAlta
CVE-2026-7585 - Open5GS AMF nudm-handler.c amf_nudm_sdm_handle_provisioned denial of service

CVE ID :CVE-2026-7585 Published : May 1, 2026, 4:16 p.m. | 2 hours, 2 minutes ago Description :A vulnerability was determined in Open5GS up to 2.7.7. The impacted element is the function amf_nudm_sdm_handle_provisioned of the file /src/amf/nudm-handler.c of the component AMF. Executing a manipulation can lead to denial of service. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 mag 2026
VulnerabilitàAlta
CVE-2026-42480 - Open CASCADE Technology (OCCT) VRML Parser Stack-Based Out-of-Bounds Read Denial of Service

CVE ID :CVE-2026-42480 Published : May 1, 2026, 4:16 p.m. | 2 hours, 2 minutes ago Description :A stack-based out-of-bounds read vulnerability in VrmlData_Scene::ReadLine in the VRML parser in Open CASCADE Technology (OCCT) V8_0_0_rc5 allows attackers to cause a denial of service via a crafted VRML file. The issue occurs because the quoted-string escape handler uses ptr[++anOffset] without proper bounds checking, which can read past the end of a fixed-size stack buffer. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 mag 2026
VulnerabilitàAlta
CVE-2026-42481 - Open CASCADE Technology (OCCT) Geometry Library IGES/STEP File Parsing vulnerabilities

CVE ID :CVE-2026-42481 Published : May 1, 2026, 4:16 p.m. | 2 hours, 2 minutes ago Description :Open CASCADE Technology (OCCT) V8_0_0_rc5 contains multiple vulnerabilities in its IGES and STEP file parsers that can be triggered by crafted IGES or STEP files. These issues include an out-of-bounds read in Geom2d_BSplineCurve::EvalD0 during IGES B-spline curve evaluation, an out-of-bounds read in MakeBSplineCurveCommon during STEP B-spline curve construction, and infinite recursion in StepShape_OrientedEdge::EdgeStart when processing a self-referential OrientedEdge entity. Successful exploitation may result in denial of service or unintended memory disclosure. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 mag 2026
VulnerabilitàAlta
CVE-2026-23866 - WhatsApp iOS/Android Media Content URL Injection Vulnerability

CVE ID :CVE-2026-23866 Published : May 1, 2026, 4:02 p.m. | 17 minutes ago Description :Incomplete validation of AI rich response messages for Instagram Reels in WhatsApp for iOS v2.25.8.0 to v2.26.15.72 and WhatsApp for Android v2.25.8.0 to v2.26.7.10 could have allowed a user to trigger processing of media content from an arbitrary URL on another user’s device, including triggering OS-controlled custom URL scheme handlers. We have not seen evidence of exploitation in the wild. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 mag 2026
VulnerabilitàAlta
CVE-2026-23863 - WhatsApp for Windows Attachment Spoofing Vulnerability

CVE ID :CVE-2026-23863 Published : May 1, 2026, 4:01 p.m. | 17 minutes ago Description :An attachment spoofing issue in WhatsApp for Windows prior to v2.3000.1032164386.258709 could have allowed maliciously formatted documents with embedded NUL bytes in the filename to be shown in the application as one type of file but run as an executable when opened. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 mag 2026
VulnerabilitàAlta
CVE-2026-7586 - Open5GS AMF nudm-handler.c ogs_id_get_value denial of service

CVE ID :CVE-2026-7586 Published : May 1, 2026, 4:16 p.m. | 2 hours, 2 minutes ago Description :A weakness has been identified in Open5GS up to 2.7.7. Affected is the function ogs_id_get_value of the file /src/amf/nudm-handler.c of the component AMF. This manipulation causes denial of service. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 mag 2026
VulnerabilitàAlta
CVE-2026-22166 - GPU DDK - Write UAF in KEGLGetPoolBuffers, WebGL reachable

CVE ID :CVE-2026-22166 Published : May 1, 2026, 3:59 p.m. | 19 minutes ago Description :A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger write UAF crash in the GPU GLES user-space shared library. On certain platforms, when the process executing graphics workload has system privileges this could enable subsequent exploit on the system. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 mag 2026
VulnerabilitàAlta
CVE-2026-22165 - GPU DDK - UAF read of GLES3Context::psDrawParams and GLES3Context::psMode and UAF read/write of RMJob::apsCCBs

CVE ID :CVE-2026-22165 Published : May 1, 2026, 3:56 p.m. | 22 minutes ago Description :A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger a write UAF crash in the GPU GLES user-space shared library. On certain platforms, when the process executing graphics workload has system privileges this could enable further exploits on the device. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 mag 2026
VulnerabilitàAlta
CVE-2026-22167 - GPU DDK - Cache resident PM buffers writable by other GPU requestors, leading to arbitrary write to physical memory

CVE ID :CVE-2026-22167 Published : May 1, 2026, 3:48 p.m. | 30 minutes ago Description :Software installed and run as a non-privileged user may conduct improper GPU system calls to force GPU to write to arbitrary physical memory pages. Under certain circumstances this exploit could be used to corrupt data pages not allocated by the GPU driver but memory pages in use by the kernel and drivers running on the platform altering their behaviour. This attack can lead the GPU to perform write operations on restricted internal GPU buffers that can lead to a second order affect of corrupted arbitrary physical memory. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 mag 2026
VulnerabilitàAlta
CVE-2026-7583 - Open5GS BSF context.c bsf_sess_find_by_ipv6prefix denial of service

CVE ID :CVE-2026-7583 Published : May 1, 2026, 3:16 p.m. | 1 hour, 2 minutes ago Description :A flaw has been found in Open5GS up to 2.7.7. This issue affects the function bsf_sess_find_by_ipv6prefix of the file /src/bsf/context.c of the component BSF. This manipulation of the argument ipv6Prefix causes denial of service. It is possible to initiate the attack remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 mag 2026

Pagina 1924 di 3109

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.