|
271
|
9.6 |
CRITICAL
Network
|
google
|
chrome
|
Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
New
|
CWE-787
Out-of-bounds Write
|
CVE-2026-9967
|
2026-06-2 02:22 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Out of bounds read and write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted…
New
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2026-9975
|
2026-06-2 02:21 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273
|
5.0 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in Input in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted …
New
|
CWE-20
Improper Input Validation
|
CVE-2026-9979
|
2026-06-2 02:21 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274
|
6.2 |
MEDIUM
Local
|
-
|
-
|
Text::LineFold versions through 2019.001 for Perl duplicate the output based on the number of special break characters.
Text::LineFold splits the input string by specific line break characters (such…
New
|
CWE-405 CWE-407
Asymmetric Resource Consumption (Amplification) Inefficient Algorithmic Complexity
|
CVE-2026-8594
|
2026-06-2 02:17 |
2026-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
275
|
- |
|
-
|
-
|
StrongDM Desktop Application before 23.74.0 (Desktop Client before 53.77.0) on Microsoft Windows stores authentication state, including a JSON Web Token and asymmetric key material, in cleartext in a…
New
|
CWE-312 CWE-522
Cleartext Storage of Sensitive Information Insufficiently Protected Credentials
|
CVE-2026-4387
|
2026-06-2 02:17 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276
|
4.3 |
MEDIUM
Network
|
-
|
-
|
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.221, FreeScout allows a non-admin user to permanently delete an internal note (private thread) from any…
New
|
CWE-862
Missing Authorization
|
CVE-2026-48811
|
2026-06-2 02:17 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277
|
- |
|
-
|
-
|
iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, the Avro array and map decoders looped over an attacker-controlled block-count value without checking the underlying reader's error state ins…
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-46385
|
2026-06-2 02:17 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278
|
8.8 |
HIGH
Adjacent
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
batman-adv: stop caching unowned originator pointers in BAT IV
BAT IV keeps the last-hop neighbor address in each neigh_node, but…
Update
|
-
|
CVE-2026-46238
|
2026-06-2 02:17 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279
|
7.1 |
HIGH
Local
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/vcn3: Avoid overflow on msg bound check
As pointed out by SDL, the previous condition may be vulnerable to
overflow.
…
Update
|
-
|
CVE-2026-46237
|
2026-06-2 02:17 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
media: rc: xbox_remote: heed DMA restrictions
The buffer for IO must not be part of the device structure
because that violates th…
Update
|
-
|
CVE-2026-46236
|
2026-06-2 02:17 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|