Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

45548 risultati

VulnerabilitàAlta
CVE-2026-63276 - Stack buffer overflow in CFF to Type 1 font conversion

CVE ID :CVE-2026-63276 Published : Sept. 22, 2026, 11:10 a.m. | 1 hour, 17 minutes ago Description :LibreOffice converts CFF fonts to Type 1 when it subsets a font, which happens when a document is exported to PDF, and CFF fonts may be embedded in documents. A stack buffer overflow existed in that conversion. The converted operators were written into a fixed size buffer with no check that they still fit, so a glyph emitting many operators wrote past the end of the buffer. In fixed versions the remaining capacity is tracked and the conversion stops when it is used up. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 set 2026
VulnerabilitàAlta
CVE-2026-63275 - Stack buffer overflow in CFF font hint handling

CVE ID :CVE-2026-63275 Published : Sept. 22, 2026, 11:10 a.m. | 1 hour, 17 minutes ago Description :LibreOffice can read CFF fonts, which may be embedded in documents. A stack buffer overflow existed when reading the hints of a glyph. The number of hints was checked against the wrong bound, so a glyph declaring more hints than the array can hold wrote past its end. In fixed versions the hint count is checked against the capacity the array really has. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 set 2026
VulnerabilitàAlta
CVE-2026-63274 - Heap buffer overflow in PDF import stream handling

CVE ID :CVE-2026-63274 Published : Sept. 22, 2026, 11:10 a.m. | 1 hour, 17 minutes ago Description :LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing a stream object. The length of the stream was taken from the object's own dictionary and was not checked against the number of bytes actually present, so copying the stream read and wrote past the end of the buffer holding it. In fixed versions the declared length is clamped to the bytes actually read. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 set 2026
VulnerabilitàAlta
CVE-2026-63273 - Heap buffer overflow in PDF import encryption handling

CVE ID :CVE-2026-63273 Published : Sept. 22, 2026, 11:10 a.m. | 1 hour, 17 minutes ago Description :LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing an encrypted document. The length of the decryption key was taken from the document's own encryption dictionary and was used to fill a fixed size key buffer without being checked against it, so a length larger than that buffer wrote past its end. In fixed versions a declared key length larger than the buffer is rejected. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 set 2026
VulnerabilitàAlta
CVE-2026-63272 - Heap buffer overflow in WMF text record import

CVE ID :CVE-2026-63272 Published : Sept. 22, 2026, 11:10 a.m. | 1 hour, 17 minutes ago Description :LibreOffice can import WMF graphics, which may be embedded in documents. A heap buffer overflow existed when importing a text record that carries its own character advance widths. The count of advance values and the length of the text were read separately from the file and were not required to agree, so drawing the text walked the advance array by character position and ran past its end when the array was the shorter of the two. In fixed versions an advance array shorter than its text is ignored. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 set 2026
News
Slechts één van 225 aan Anthropic gelinkte kwetsbaarheden actief misbruikt

Slechts één van 225 aan Anthropic gelinkte kwetsbaarheden actief misbruikt Van de 225 kwetsbaarheden die zijn ontdekt door onderzoekers van Anthropic en deelnemers aan Project Glasswing, wordt voor zover bekend slechts één actief misbruikt. Dat stelt beveiligingsonderzoeker ... Read more Published Date: Sep 22, 2026 (1 day, 20 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-26980

CVEfeed Newsroom22 set 2026
VulnerabilitàAlta
CVE-2026-25265 - Creation of Temporary File with Insecure Permissions in Qualcomm Software Center

CVE ID :CVE-2026-25265 Published : Sept. 22, 2026, 10:17 a.m. | 2 hours, 10 minutes ago Description :Privilege escalation due to weak configuration while temporary file handling. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 set 2026
VulnerabilitàAlta
CVE-2026-25264 - Uncontrolled Search Path Element in Qualcomm Software Center

CVE ID :CVE-2026-25264 Published : Sept. 22, 2026, 10:17 a.m. | 2 hours, 10 minutes ago Description :Privilege escalation due to weak configuration during package extraction process. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 set 2026
VulnerabilitàAlta
CVE-2026-25262 - Write-what-where Condition in Primary Bootloader

CVE ID :CVE-2026-25262 Published : Sept. 22, 2026, 10:17 a.m. | 2 hours, 10 minutes ago Description :Memory corruption while processing a crafted ELF file in the Primary Bootloader. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 set 2026
VulnerabilitàAlta
CVE-2026-25255 - Exposed function in Qualcomm Package Manager and Qualcomm Software Center.

CVE ID :CVE-2026-25255 Published : Sept. 22, 2026, 10:17 a.m. | 2 hours, 10 minutes ago Description :Exposed dangerous function lead to privilege escalation via gRPC server. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 set 2026
VulnerabilitàAlta
CVE-2026-25254 - Improper authorization in Qualcomm Software Center

CVE ID :CVE-2026-25254 Published : Sept. 22, 2026, 10:17 a.m. | 2 hours, 10 minutes ago Description :Improper authorization leads to Remote Code Execution via SocketIO interface. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 set 2026
VulnerabilitàAlta
CVE-2026-90882 - Reflected arbitrary origins with credentials, allowing cross-origin reads of authenticated user data

CVE ID :CVE-2026-90882 Published : Sept. 22, 2026, 10:17 a.m. | 2 hours, 10 minutes ago Description :The open-vsx.org deployment returned Access-Control-Allow-Origin reflecting the requesting origin together with Access-Control-Allow-Credentials: true on the authenticated /user/ endpoints. A page on any origin could therefore issue credentialed requests to the service in a logged-in user's browser and read the responses. This exposed /user (login name, avatar, homepage, tokens URL), /user/tokens, /user/namespaces, /user/extensions, /user/search/{name} and /user/namespace/{name}/members, and — because /user/csrf was readable the same way — allowed the CSRF protection on write endpoints to be defeated. Chaining the two, an attacker page could call /user/token/create and exfiltrate a personal access token carrying publish and delete rights over the victim's namespaces. The headers were emitted by the CDN/edge layer, not by the application: the Open VSX software sets allowCredentials(true) in exactly one place, against a single exact origin derived from ovsx.webui.url, and defines no CORS mapping on /user/ beyond it. No configuration of the software produces origin reflection with credentials. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 set 2026

Pagina 251 di 3796

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.