|
1071
|
6.3 |
MEDIUM
Local
|
uutils
|
coreutils
|
The touch utility in uutils coreutils is vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition during file creation. When the utility identifies a missing path, it later attempts creat…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-35360
|
2026-04-25 04:02 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1072
|
5.6 |
MEDIUM
Local
|
uutils
|
coreutils
|
A vulnerability in the rm utility of uutils coreutils allows the bypass of safeguard mechanisms intended to protect the current directory. While the utility correctly refuses to delete . or .., it fa…
|
CWE-22
Path Traversal
|
CVE-2026-35363
|
2026-04-25 04:02 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1073
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
nvme: fix admin queue leak on controller reset
When nvme_alloc_admin_tag_set() is called during a controller reset,
a previous ad…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2026-23360
|
2026-04-25 03:59 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1074
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:
nvme: corrige la fuga de la cola de administración al reiniciar el controlador
Cuando se llama a nvme_alloc_admin_tag_set() dura…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2026-23360
|
2026-04-25 03:59 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1075
|
4.3 |
MEDIUM
Adjacent
|
openbsd
|
openbsd
|
In OpenBSD through 7.8, the slaacd and rad daemons have an infinite loop when they receive a crafted ICMPv6 Neighbor Discovery (ND) option (over a local network) with length zero, because of an "nd_o…
|
CWE-1284 CWE-835
Improper Validation of Specified Quantity in Input Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2026-41285
|
2026-04-25 03:59 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1076
|
5.5 |
MEDIUM
Local
|
uutils
|
coreutils
|
The sort utility in uutils coreutils is vulnerable to a process panic when using the --files0-from option with inputs containing non-UTF-8 filenames. The implementation enforces UTF-8 encoding and ut…
|
CWE-248
Uncaught Exception
|
CVE-2026-35348
|
2026-04-25 03:57 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1077
|
- |
|
softbizscripts
|
dating_script
|
Multiple SQL injection vulnerabilities in Softbiz Dating 1.0 allow remote attackers to execute SQL commands via the (1) country and (2) sort_by parameters in (a) search_results.php; (3) browse parame…
|
NVD-CWE-Other
|
CVE-2006-3271
|
2026-04-25 03:56 |
2006-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1078
|
- |
|
softbizscripts
|
dating_script
|
Vulnerabilidad de múltiples inyección SQL en Softbiz Dating v1.0 permite a los atacantes remotos, ejecutar comandos SQL a través del parámetro (1) country y (2) sort_by en (a) search_results.php; par…
|
NVD-CWE-Other
|
CVE-2006-3271
|
2026-04-25 03:56 |
2006-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1079
|
- |
|
softbizscripts
|
image_gallery_script
|
Cross-site scripting (XSS) vulnerability in image_desc.php in Softbiz Image Gallery allows remote attackers to inject arbitrary web script or HTML via msg parameter. NOTE: the provenance of this inf…
|
NVD-CWE-Other
|
CVE-2006-1660
|
2026-04-25 03:56 |
2006-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1080
|
- |
|
softbizscripts
|
image_gallery_script
|
Multiple SQL injection vulnerabilities in Softbiz Image Gallery allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in image_desc.php, (2) provided parameter in template…
|
NVD-CWE-Other
|
CVE-2006-1659
|
2026-04-25 03:56 |
2006-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|