|
2891
|
5.5 |
MEDIUM
Local
|
wireshark
|
wireshark
|
ZigBee protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-6537
|
2026-05-2 03:15 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2892
|
5.5 |
MEDIUM
Local
|
wireshark
|
wireshark
|
BEEP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-6538
|
2026-05-2 03:15 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2893
|
5.5 |
MEDIUM
Local
|
wireshark
|
wireshark
|
SMB2 protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
|
CWE-1325
Improperly Controlled Sequential Memory Allocation
|
CVE-2026-6867
|
2026-05-2 03:15 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2894
|
5.5 |
MEDIUM
Local
|
wireshark
|
wireshark
|
WebSocket protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
|
CWE-1325
Improperly Controlled Sequential Memory Allocation
|
CVE-2026-6869
|
2026-05-2 03:15 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2895
|
5.5 |
MEDIUM
Local
|
wireshark
|
wireshark
|
GSM RP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
|
CWE-824
Access of Uninitialized Pointer
|
CVE-2026-6870
|
2026-05-2 03:11 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2896
|
7.5 |
HIGH
Network
|
apache
|
neethi
|
Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy normalization. Specially crafted WS-Policy documents can trigger an exponential Cartesian cross-prod…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-42402
|
2026-05-2 03:08 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2897
|
7.5 |
HIGH
Network
|
apache
|
neethi
|
Apache Neethi does not properly detect circular references in policy definitions. When a WS-Policy document contains circular policy references (where Policy A references Policy B which references Po…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-42403
|
2026-05-2 03:08 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2898
|
7.2 |
HIGH
Network
|
apache
|
neethi
|
Apache Neethi does not impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API. When an application explicitly calls the API to retrieve a poli…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-42404
|
2026-05-2 03:06 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2899
|
9.8 |
CRITICAL
Network
|
apache
|
mina
|
The fix for CVE-2026-41409 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description:
The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was inc…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-42778
|
2026-05-2 02:55 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2900
|
9.8 |
CRITICAL
Network
|
apache
|
mina
|
The fix for CVE-2026-41635 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description:
Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, on…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-42779
|
2026-05-2 02:55 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|