Aggregator
CVE-2026-44824 | Microsoft Office up to 16.0.10417.20128 heap-based overflow (Nessus ID 321311)
1 week 6 days ago
A vulnerability has been found in Microsoft Office and classified as critical. This issue affects some unknown processing. The manipulation leads to heap-based buffer overflow.
This vulnerability is traded as CVE-2026-44824. It is possible to initiate the attack remotely. There is no exploit available.
To fix this issue, it is recommended to deploy a patch.
vuldb.com
CVE-2026-44819 | Microsoft Office up to SharePoint Server Subscription Edition heap-based overflow (Nessus ID 321311)
1 week 6 days ago
A vulnerability described as critical has been identified in Microsoft Office. Affected is an unknown function. The manipulation results in heap-based buffer overflow.
This vulnerability is cataloged as CVE-2026-44819. The attack may be launched remotely. There is no exploit available.
It is best practice to apply a patch to resolve this issue.
vuldb.com
CVE-2026-46227 | Linux Kernel up to 7.1-rc3 sctp sctp_sendmsg_to_asoc use after free (EUVD-2026-32854 / Nessus ID 321327)
1 week 6 days ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.6.139/6.12.89/6.18.31/7.0.8/7.1-rc3. Affected is the function sctp_sendmsg_to_asoc of the component sctp. Performing a manipulation results in use after free.
This vulnerability is reported as CVE-2026-46227. The attacker must have access to the local network to execute the attack. No exploit exists.
It is advisable to upgrade the affected component.
vuldb.com
What’s new in Android 17? Anti-theft tools, scam detection, and parental controls
1 week 6 days ago
The Android 17 rollout has started for supported Pixel devices, delivering new security and privacy capabilities before expanding to other devices later this year. Security and privacy updates Google has improved location privacy features so users can choose to share their approximate location with websites and grant apps temporary access to their precise location when services require exact coordinates. In previous Android versions, users had no OS-level way to grant an app access to only … More →
The post What’s new in Android 17? Anti-theft tools, scam detection, and parental controls appeared first on Help Net Security.
Anamarija Pogorelec
2026攻防演练必修高危漏洞集合(1.0版)
1 week 6 days ago
CVE-2022-36362 | Siemens LOGO 8 BM IP Address input validation (ssa-955858 / EUVD-2022-39077)
1 week 6 days ago
A vulnerability, which was classified as critical, was found in Siemens LOGO 8 BM. This vulnerability affects unknown code of the component IP Address Handler. Such manipulation leads to improper input validation.
This vulnerability is uniquely identified as CVE-2022-36362. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2022-36363 | Siemens LOGO 8 BM TCP Packet improper validation of specified index, position, or offset in input (ssa-955858 / EUVD-2022-39078)
1 week 6 days ago
A vulnerability categorized as problematic has been discovered in Siemens LOGO 8 BM. This impacts an unknown function of the component TCP Packet Handler. Such manipulation leads to improper validation of specified index, position, or offset in input.
This vulnerability is listed as CVE-2022-36363. The attack may be performed from remote. There is no available exploit.
vuldb.com
CVE-2022-36361 | Siemens LOGO 8 BM TCP Packet buffer overflow (ssa-955858 / EUVD-2022-39076)
1 week 6 days ago
A vulnerability was found in Siemens LOGO 8 BM. It has been rated as critical. This affects an unknown function of the component TCP Packet Handler. This manipulation causes buffer overflow.
This vulnerability is tracked as CVE-2022-36361. The attack is only possible within the local network. No exploit exists.
vuldb.com
Firefox 用 Zlib 的 Rust 语言版本替代了 C 语言版本
1 week 6 days ago
Firefox 浏览器从 v151 开始,Gzip 压缩/解压缩就依赖于 zlib-rs 库,用 Rust 语言开发的版本替代了 C 语言版本改进了性能,提供了更好的内存安全性,以及带来了英特尔第 13 代/第 14 代酷睿 CPU 不稳定导致的崩溃问题。致力于用 Rust 语言重写关键库的非盈利组织 Trifecta Tech Foundation 在 2024 年夏天就与 Mozilla 讨论在浏览器中集成 zlib-rs,但从测试到落地花了两年时间,一个重要原因就是 zlib-rs 触发了臭名昭著的英特尔 CPU bug。测试中 zlib-rs 中的一些代码导致英特尔 Raptor Lake CPU 频繁崩溃,开发者最终发现问题与 Huffman 编码写入内存的一个特定指令相关,识别问题之后解决起来就容易了,开发者通过加入一段“不安全代码”修复了该问题。
Warner warns of CISA cuts, staffing gaps in letter to acting chief
1 week 6 days ago
Warner on Tuesday also wrote a letter to DHS Secretary Markwayne Mullin, underscoring that DHS must prioritize CISA and pay for the MS-ISAC.
The Top 10 Attack Surface Exposures in 2026
1 week 6 days ago
Breaches don't always start with a zero-day. An exposed admin panel can get brute-forced, or credentials reused from a previous attack. But when a vulnerability does drop — like MongoBleed earlier this year, which let attackers pull credentials and session tokens from server memory without authentication — anything internet-facing is immediately at risk.
With time-to-exploit now down to a
The Hacker News
CVE-2022-36360 | Siemens LOGO 8 BM up to 8.2 Firmware Update data authenticity (ssa-928782 / EUVD-2022-39075)
1 week 6 days ago
A vulnerability was found in Siemens LOGO 8 BM up to 8.2. It has been declared as critical. The impacted element is an unknown function of the component Firmware Update Handler. The manipulation results in insufficient verification of data authenticity.
This vulnerability is identified as CVE-2022-36360. The attack can only be performed from the local network. There is not any exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-36337 | Insyde Kernel up to 5.5 MebxConfiguration Driver stack-based overflow (EUVD-2022-39053)
1 week 6 days ago
A vulnerability categorized as critical has been discovered in Insyde Kernel up to 5.5. This affects an unknown function of the component MebxConfiguration Driver. Executing a manipulation can lead to stack-based buffer overflow.
This vulnerability is tracked as CVE-2022-36337. The attack is only possible within the local network. No exploit exists.
vuldb.com
CVE-2022-36320 | Mozilla Firefox up to 102 memory corruption (EUVD-2022-39036)
1 week 6 days ago
A vulnerability has been found in Mozilla Firefox up to 102 and classified as critical. This affects an unknown part. Performing a manipulation results in memory corruption.
This vulnerability was named CVE-2022-36320. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
vuldb.com
CVE-2022-36319 | Mozilla Thunderbird up to 102 CSS access control (Bug 1737722 / EUVD-2022-39035)
1 week 6 days ago
A vulnerability was found in Mozilla Thunderbird up to 102. It has been classified as critical. This issue affects some unknown processing of the component CSS Handler. The manipulation leads to improper access controls.
This vulnerability is referenced as CVE-2022-36319. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2022-36319 | Mozilla Firefox up to 102 CSS access control (Bug 1737722 / EUVD-2022-39035)
1 week 6 days ago
A vulnerability marked as critical has been reported in Mozilla Firefox up to 102. The impacted element is an unknown function of the component CSS Handler. Performing a manipulation results in improper access controls.
This vulnerability is reported as CVE-2022-36319. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.
vuldb.com
威胁情报|Arch Linux AUR 供应链投毒关联恶意 npm 包分析
1 week 6 days ago
本文分析了 Arch Linux AUR 供应链投毒事件,聚焦被篡改的 AUR 构建/安装脚本如何触发恶意 npm 包,并揭示其核心 ELF 载荷中的凭据采集、Tor onion C2 及 eBPF 隐身能力痕迹。
CVE-2025-40117 | Linux Kernel up to 6.17.2 misc pci_endpoint_test_ioctl buffer under-read (Nessus ID 298897 / WID-SEC-2025-2579)
1 week 6 days ago
A vulnerability classified as critical was found in Linux Kernel up to 6.17.2. Affected is the function pci_endpoint_test_ioctl of the component Misc. Executing a manipulation can lead to buffer under-read.
This vulnerability is tracked as CVE-2025-40117. The attack is only possible within the local network. No exploit exists.
Upgrading the affected component is advised.
vuldb.com
CVE-2025-40116 | Linux Kernel up to 6.17.2 usb kthread_run null pointer dereference (Nessus ID 276782 / WID-SEC-2025-2579)
1 week 6 days ago
A vulnerability described as critical has been identified in Linux Kernel up to 6.17.2. This vulnerability affects the function kthread_run of the component usb. The manipulation results in null pointer dereference.
This vulnerability was named CVE-2025-40116. The attack needs to be approached within the local network. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com