Tag

#Vulnerability

40 published stories tagged with Vulnerability.

mediumVulnerabilityMay 8, 2026·4 min read

Brief: Linux Kernel xfrm6 Source Address Handling Bug Fixed

The Linux kernel fixed an xfrm6 issue where xfrm6_get_saddr() failed to check the return value of ipv6_dev_get_saddr(), leaving a source address uninitialized when address selection failed.

mediumVulnerabilityMay 8, 2026·4 min read

Defender Guidance: Linux Kernel xfrm6 Source Address Handling Bug Fixed

The Linux kernel fixed an xfrm6 issue where xfrm6_get_saddr() failed to check the return value of ipv6_dev_get_saddr(), leaving a source address uninitialized when address selection failed.

mediumVulnerabilityMay 8, 2026·4 min read

Detection Notes: Linux Kernel xfrm6 Source Address Handling Bug Fixed

The Linux kernel fixed an xfrm6 issue where xfrm6_get_saddr() failed to check the return value of ipv6_dev_get_saddr(), leaving a source address uninitialized when address selection failed.

mediumVulnerabilityMay 8, 2026·4 min read

Risk Brief: Linux Kernel xfrm6 Source Address Handling Bug Fixed

The Linux kernel fixed an xfrm6 issue where xfrm6_get_saddr() failed to check the return value of ipv6_dev_get_saddr(), leaving a source address uninitialized when address selection failed.

mediumVulnerabilityMay 8, 2026·4 min read

Brief: Linux Kernel AMDGPU VCN Poison IRQ Release Issue Fixed in Stable Kernel Code

A Linux kernel AMDGPU issue was fixed by skipping VCN poison IRQ release on VF because VCNv2.5 VF does not enable VCN poison IRQ.

mediumVulnerabilityMay 8, 2026·4 min read

Defender Guidance: Linux Kernel AMDGPU VCN Poison IRQ Release Issue Fixed in Stable Kernel Code

A Linux kernel AMDGPU issue was fixed by skipping VCN poison IRQ release on VF because VCNv2.5 VF does not enable VCN poison IRQ.

mediumVulnerabilityMay 8, 2026·4 min read

Detection Notes: Linux Kernel AMDGPU VCN Poison IRQ Release Issue Fixed in Stable Kernel Code

A Linux kernel AMDGPU issue was fixed by skipping VCN poison IRQ release on VF because VCNv2.5 VF does not enable VCN poison IRQ.

mediumVulnerabilityMay 8, 2026·4 min read

Risk Brief: Linux Kernel AMDGPU VCN Poison IRQ Release Issue Fixed in Stable Kernel Code

A Linux kernel AMDGPU issue was fixed by skipping VCN poison IRQ release on VF because VCNv2.5 VF does not enable VCN poison IRQ.

mediumVulnerabilityMay 8, 2026·4 min read

Brief: Linux Kernel MCTP Route Race Condition Patched in Stable Kernel Updates

A Linux kernel MCTP route issue was fixed by holding key->lock in mctp_flow_prepare_output(), preventing a race around key->dev access.

mediumVulnerabilityMay 8, 2026·4 min read

Defender Guidance: Linux Kernel MCTP Route Race Condition Patched in Stable Kernel Updates

A Linux kernel MCTP route issue was fixed by holding key->lock in mctp_flow_prepare_output(), preventing a race around key->dev access.

mediumVulnerabilityMay 8, 2026·4 min read

Detection Notes: Linux Kernel MCTP Route Race Condition Patched in Stable Kernel Updates

A Linux kernel MCTP route issue was fixed by holding key->lock in mctp_flow_prepare_output(), preventing a race around key->dev access.

mediumVulnerabilityMay 8, 2026·4 min read

Risk Brief: Linux Kernel MCTP Route Race Condition Patched in Stable Kernel Updates

A Linux kernel MCTP route issue was fixed by holding key->lock in mctp_flow_prepare_output(), preventing a race around key->dev access.

lowVulnerabilityMay 8, 2026·4 min read

Brief: Tor Client Crash Vulnerability Fixed Before Version 0.4.9.7

Tor before 0.4.9.7 can experience a client crash when circuit queue memory pressure exists due to a double close of a circuit, tracked as TROVE-2026-009.

lowVulnerabilityMay 8, 2026·4 min read

Defender Guidance: Tor Client Crash Vulnerability Fixed Before Version 0.4.9.7

Tor before 0.4.9.7 can experience a client crash when circuit queue memory pressure exists due to a double close of a circuit, tracked as TROVE-2026-009.

lowVulnerabilityMay 8, 2026·4 min read

Detection Notes: Tor Client Crash Vulnerability Fixed Before Version 0.4.9.7

Tor before 0.4.9.7 can experience a client crash when circuit queue memory pressure exists due to a double close of a circuit, tracked as TROVE-2026-009.

lowVulnerabilityMay 8, 2026·4 min read

Risk Brief: Tor Client Crash Vulnerability Fixed Before Version 0.4.9.7

Tor before 0.4.9.7 can experience a client crash when circuit queue memory pressure exists due to a double close of a circuit, tracked as TROVE-2026-009.

highVulnerabilityMay 8, 2026·4 min read

Brief: Acer PredatorSense Named Pipe Misconfiguration Enables SYSTEM Privilege Escalation

Acer PredatorSense versions 3.00.3136 through 3.00.3196 contain a local privilege escalation vulnerability caused by a misconfigured Windows named pipe.

highVulnerabilityMay 8, 2026·4 min read

Defender Guidance: Acer PredatorSense Named Pipe Misconfiguration Enables SYSTEM Privilege Escalation

Acer PredatorSense versions 3.00.3136 through 3.00.3196 contain a local privilege escalation vulnerability caused by a misconfigured Windows named pipe.

highVulnerabilityMay 8, 2026·4 min read

Detection Notes: Acer PredatorSense Named Pipe Misconfiguration Enables SYSTEM Privilege Escalation

Acer PredatorSense versions 3.00.3136 through 3.00.3196 contain a local privilege escalation vulnerability caused by a misconfigured Windows named pipe.

highVulnerabilityMay 8, 2026·4 min read

Risk Brief: Acer PredatorSense Named Pipe Misconfiguration Enables SYSTEM Privilege Escalation

Acer PredatorSense versions 3.00.3136 through 3.00.3196 contain a local privilege escalation vulnerability caused by a misconfigured Windows named pipe.

mediumVulnerabilityMay 8, 2026·4 min read

Brief: Mozilla Firefox ESR Audio/Video Boundary Condition Issue Fixed

Mozilla fixed incorrect boundary conditions in the Audio/Video Playback component of Firefox ESR releases.

mediumVulnerabilityMay 8, 2026·4 min read

Defender Guidance: Mozilla Firefox ESR Audio/Video Boundary Condition Issue Fixed

Mozilla fixed incorrect boundary conditions in the Audio/Video Playback component of Firefox ESR releases.

mediumVulnerabilityMay 8, 2026·4 min read

Detection Notes: Mozilla Firefox ESR Audio/Video Boundary Condition Issue Fixed

Mozilla fixed incorrect boundary conditions in the Audio/Video Playback component of Firefox ESR releases.

mediumVulnerabilityMay 8, 2026·4 min read

Risk Brief: Mozilla Firefox ESR Audio/Video Boundary Condition Issue Fixed

Mozilla fixed incorrect boundary conditions in the Audio/Video Playback component of Firefox ESR releases.

highVulnerabilityMay 8, 2026·4 min read

Brief: Mozilla Fixes High-Impact Memory Safety Bugs in Firefox and Thunderbird

Mozilla fixed memory safety bugs in Firefox and Thunderbird. Mozilla states some bugs showed evidence of memory corruption and could potentially be exploited to run arbitrary code with enough effort.

highVulnerabilityMay 8, 2026·4 min read

Defender Guidance: Mozilla Fixes High-Impact Memory Safety Bugs in Firefox and Thunderbird

Mozilla fixed memory safety bugs in Firefox and Thunderbird. Mozilla states some bugs showed evidence of memory corruption and could potentially be exploited to run arbitrary code with enough effort.

highVulnerabilityMay 8, 2026·4 min read

Detection Notes: Mozilla Fixes High-Impact Memory Safety Bugs in Firefox and Thunderbird

Mozilla fixed memory safety bugs in Firefox and Thunderbird. Mozilla states some bugs showed evidence of memory corruption and could potentially be exploited to run arbitrary code with enough effort.

highVulnerabilityMay 8, 2026·4 min read

Risk Brief: Mozilla Fixes High-Impact Memory Safety Bugs in Firefox and Thunderbird

Mozilla fixed memory safety bugs in Firefox and Thunderbird. Mozilla states some bugs showed evidence of memory corruption and could potentially be exploited to run arbitrary code with enough effort.

highVulnerabilityMay 8, 2026·4 min read

Brief: Mozilla Thunderbird 150.0.2 Fixes Memory Safety Bugs

Mozilla fixed memory safety bugs in Thunderbird 150.0.2. The NVD/Mozilla record says some bugs showed evidence of memory corruption and could potentially be exploited to run arbitrary code with enough effort.

highVulnerabilityMay 8, 2026·4 min read

Defender Guidance: Mozilla Thunderbird 150.0.2 Fixes Memory Safety Bugs

Mozilla fixed memory safety bugs in Thunderbird 150.0.2. The NVD/Mozilla record says some bugs showed evidence of memory corruption and could potentially be exploited to run arbitrary code with enough effort.

highVulnerabilityMay 8, 2026·4 min read

Detection Notes: Mozilla Thunderbird 150.0.2 Fixes Memory Safety Bugs

Mozilla fixed memory safety bugs in Thunderbird 150.0.2. The NVD/Mozilla record says some bugs showed evidence of memory corruption and could potentially be exploited to run arbitrary code with enough effort.

highVulnerabilityMay 8, 2026·4 min read

Risk Brief: Mozilla Thunderbird 150.0.2 Fixes Memory Safety Bugs

Mozilla fixed memory safety bugs in Thunderbird 150.0.2. The NVD/Mozilla record says some bugs showed evidence of memory corruption and could potentially be exploited to run arbitrary code with enough effort.

mediumVulnerabilityMay 8, 2026·4 min read

Brief: Mozilla Firefox ESR WebRTC Issue Fixed in Firefox ESR 140.10.2

Mozilla fixed CVE-2026-8094, described by NVD as another issue in the WebRTC component, in Firefox ESR 140.10.2.

mediumVulnerabilityMay 8, 2026·4 min read

Defender Guidance: Mozilla Firefox ESR WebRTC Issue Fixed in Firefox ESR 140.10.2

Mozilla fixed CVE-2026-8094, described by NVD as another issue in the WebRTC component, in Firefox ESR 140.10.2.

mediumVulnerabilityMay 8, 2026·4 min read

Detection Notes: Mozilla Firefox ESR WebRTC Issue Fixed in Firefox ESR 140.10.2

Mozilla fixed CVE-2026-8094, described by NVD as another issue in the WebRTC component, in Firefox ESR 140.10.2.

mediumVulnerabilityMay 8, 2026·4 min read

Risk Brief: Mozilla Firefox ESR WebRTC Issue Fixed in Firefox ESR 140.10.2

Mozilla fixed CVE-2026-8094, described by NVD as another issue in the WebRTC component, in Firefox ESR 140.10.2.

highVulnerabilityMay 8, 2026·4 min read

Brief: NAVER MYBOX Explorer for Windows Privilege Escalation Fixed in Version 3.0.11.160

NAVER MYBOX Explorer for Windows before 3.0.11.160 contains an improper privilege check that can allow a local attacker to escalate privileges to NT AUTHORITY\SYSTEM through registry manipulation.

highVulnerabilityMay 8, 2026·4 min read

Defender Guidance: NAVER MYBOX Explorer for Windows Privilege Escalation Fixed in Version 3.0.11.160

NAVER MYBOX Explorer for Windows before 3.0.11.160 contains an improper privilege check that can allow a local attacker to escalate privileges to NT AUTHORITY\SYSTEM through registry manipulation.

highVulnerabilityMay 8, 2026·4 min read

Detection Notes: NAVER MYBOX Explorer for Windows Privilege Escalation Fixed in Version 3.0.11.160

NAVER MYBOX Explorer for Windows before 3.0.11.160 contains an improper privilege check that can allow a local attacker to escalate privileges to NT AUTHORITY\SYSTEM through registry manipulation.

highVulnerabilityMay 8, 2026·4 min read

Risk Brief: NAVER MYBOX Explorer for Windows Privilege Escalation Fixed in Version 3.0.11.160

NAVER MYBOX Explorer for Windows before 3.0.11.160 contains an improper privilege check that can allow a local attacker to escalate privileges to NT AUTHORITY\SYSTEM through registry manipulation.