Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

46931 risultati

VulnerabilitàAlta
CVE-2026-95270 - dgtlmoon changedetection.io Hash Comparison flask_app.py check_password timing discrepancy

CVE ID :CVE-2026-95270 Published : Sept. 22, 2026, 11:15 a.m. | 1 hour, 12 minutes ago Description :A flaw has been found in dgtlmoon changedetection.io up to 0.60.7. The affected element is the function check_password of the file changedetectionio/flask_app.py of the component Hash Comparison. This manipulation of the argument Password causes observable timing discrepancy. The attack is possible to be carried out remotely. A high degree of complexity is needed for the attack. The exploitability is described as difficult. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 set 2026
VulnerabilitàAlta
CVE-2026-63279 - Out of bounds read in PICT image import

CVE ID :CVE-2026-63279 Published : Sept. 22, 2026, 11:10 a.m. | 1 hour, 17 minutes ago Description :LibreOffice can import PICT images, which may be embedded in documents. An out of bounds read existed when importing an image that uses a colour palette. The palette index held in the image data was used without being checked against the number of entries the palette has, so an index past the last entry read memory outside the palette. In fixed versions the palette index is limited to the entries present. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 set 2026
VulnerabilitàAlta
CVE-2026-63278 - Package URLs can be used to exfiltrate arbitrary INI file values and environment variables

CVE ID :CVE-2026-63278 Published : Sept. 22, 2026, 11:10 a.m. | 1 hour, 17 minutes ago Description :URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links. The check added for CVE-2024-12426 did not recognise every way of naming the package content provider, so a URL that named it differently still reached the expansion. In fixed versions the package content provider is matched when the URL is checked. Severity: 6.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 set 2026
VulnerabilitàAlta
CVE-2026-63276 - Stack buffer overflow in CFF to Type 1 font conversion

CVE ID :CVE-2026-63276 Published : Sept. 22, 2026, 11:10 a.m. | 1 hour, 17 minutes ago Description :LibreOffice converts CFF fonts to Type 1 when it subsets a font, which happens when a document is exported to PDF, and CFF fonts may be embedded in documents. A stack buffer overflow existed in that conversion. The converted operators were written into a fixed size buffer with no check that they still fit, so a glyph emitting many operators wrote past the end of the buffer. In fixed versions the remaining capacity is tracked and the conversion stops when it is used up. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 set 2026
VulnerabilitàAlta
CVE-2026-63275 - Stack buffer overflow in CFF font hint handling

CVE ID :CVE-2026-63275 Published : Sept. 22, 2026, 11:10 a.m. | 1 hour, 17 minutes ago Description :LibreOffice can read CFF fonts, which may be embedded in documents. A stack buffer overflow existed when reading the hints of a glyph. The number of hints was checked against the wrong bound, so a glyph declaring more hints than the array can hold wrote past its end. In fixed versions the hint count is checked against the capacity the array really has. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 set 2026
VulnerabilitàAlta
CVE-2026-63274 - Heap buffer overflow in PDF import stream handling

CVE ID :CVE-2026-63274 Published : Sept. 22, 2026, 11:10 a.m. | 1 hour, 17 minutes ago Description :LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing a stream object. The length of the stream was taken from the object's own dictionary and was not checked against the number of bytes actually present, so copying the stream read and wrote past the end of the buffer holding it. In fixed versions the declared length is clamped to the bytes actually read. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 set 2026
VulnerabilitàAlta
CVE-2026-63273 - Heap buffer overflow in PDF import encryption handling

CVE ID :CVE-2026-63273 Published : Sept. 22, 2026, 11:10 a.m. | 1 hour, 17 minutes ago Description :LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing an encrypted document. The length of the decryption key was taken from the document's own encryption dictionary and was used to fill a fixed size key buffer without being checked against it, so a length larger than that buffer wrote past its end. In fixed versions a declared key length larger than the buffer is rejected. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 set 2026
VulnerabilitàAlta
CVE-2026-63272 - Heap buffer overflow in WMF text record import

CVE ID :CVE-2026-63272 Published : Sept. 22, 2026, 11:10 a.m. | 1 hour, 17 minutes ago Description :LibreOffice can import WMF graphics, which may be embedded in documents. A heap buffer overflow existed when importing a text record that carries its own character advance widths. The count of advance values and the length of the text were read separately from the file and were not required to agree, so drawing the text walked the advance array by character position and ran past its end when the array was the shorter of the two. In fixed versions an advance array shorter than its text is ignored. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 set 2026
News
Slechts één van 225 aan Anthropic gelinkte kwetsbaarheden actief misbruikt

Slechts één van 225 aan Anthropic gelinkte kwetsbaarheden actief misbruikt Van de 225 kwetsbaarheden die zijn ontdekt door onderzoekers van Anthropic en deelnemers aan Project Glasswing, wordt voor zover bekend slechts één actief misbruikt. Dat stelt beveiligingsonderzoeker ... Read more Published Date: Sep 22, 2026 (1 day, 20 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-26980

CVEfeed Newsroom22 set 2026
VulnerabilitàAlta
CVE-2026-25265 - Creation of Temporary File with Insecure Permissions in Qualcomm Software Center

CVE ID :CVE-2026-25265 Published : Sept. 22, 2026, 10:17 a.m. | 2 hours, 10 minutes ago Description :Privilege escalation due to weak configuration while temporary file handling. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 set 2026
VulnerabilitàAlta
CVE-2026-25264 - Uncontrolled Search Path Element in Qualcomm Software Center

CVE ID :CVE-2026-25264 Published : Sept. 22, 2026, 10:17 a.m. | 2 hours, 10 minutes ago Description :Privilege escalation due to weak configuration during package extraction process. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 set 2026
VulnerabilitàAlta
CVE-2026-25262 - Write-what-where Condition in Primary Bootloader

CVE ID :CVE-2026-25262 Published : Sept. 22, 2026, 10:17 a.m. | 2 hours, 10 minutes ago Description :Memory corruption while processing a crafted ELF file in the Primary Bootloader. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 set 2026

Pagina 366 di 3911

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.