VulnScope — 以套件為主體的 CVE 查詢工具- HIGH7.8CVE-2026-52858Vim is an open source, command line text editor.
- HIGH7.8Vim is an open source, command line text editor.
- HIGH8.2Vim is an open source, command line text editor.
- HIGH7.5Issue summary: When an application drives an AES-OCB context through the public EVP_Cipher() one-shot interface, the application-supplied i…
- MEDIUM4.8Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) mishandle the authentication of AAD (Additional Authent…
- MEDIUM5.9Issue summary: A specially crafted password-encrypted CMS message can trigger a NULL pointer dereference during CMS decryption.
- LOW3.7Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to Bleichenbacher-style attack when an attacker is able to provid…
- HIGH7.5Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes in length may cause…
- HIGH7.5Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap) processes attacker-supplied CMS data, an attacker-chosen str…
- LOW3.7Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly checked for the subgroup…
- MEDIUM5.9Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer dereference in a CMP client…
- HIGH7.5Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer dereference in the OpenSSL QUIC server with…
- HIGH7.4Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files that use Password-Based Message Authentic…
- MEDIUM5.3Issue Summary: An error in the callback used to verify the certificate provided in a Root CA key update Certificate Management Protocol (CM…
- HIGH7.5Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing PATH_CHALLENGE frame…
- HIGH8.1Issue summary: A signed integer overflow when sizing the destination buffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap…
- MEDIUM4.3MariaDB: Authorization bypass in role-based routine-level privilege check exposes stored routine definitions
- MEDIUM6.3MariaDB: path traversal in mbstream
- HIGH8.0MariaDB: unsafe usage of `wsrep_sst_receive_address` values on the joiner side
- HIGH8.0MariaDB: wsrep SST unsafe parameter handling on the donor side (rsync)
- HIGH8.0MariaDB: wsrep SST unsafe parameter handling on the donor side
- MEDIUM5.0MariaDB: FILE privilege was not checked for subqueries in the FROM clause
- HIGH7.5Apache HTTP Server: mod_http2 denial of service
- MEDIUM6.5EPSS 0.07%A flaw was found in Samba’s vfs_worm module.
- HIGH7.1EPSS 0.06%A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes.