Export limit exceeded: 402993 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 402993 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (402993 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-87665 | 2026-10-08 | N/A | ||
| A stack-based buffer overflow vulnerability exists in the Internet Key Exchange (IKEv2) protocol handler on Brocade Fabric OS versions before 10.0.1. The vulnerability occurs when processing initial IKE key exchange requests on extension switches or blades running IPsec-enabled Fibre Channel over IP (FCIP) circuits. An unauthenticated remote attacker can exploit this vulnerability by sending a single, specifically crafted UDP packet (Port 500) containing an oversized Nonce payload. Successful exploitation results in a denial of service (data-plane process crash) | ||||
| CVE-2026-87672 | 2026-10-08 | N/A | ||
| An information disclosure vulnerability exists in the SupportLink diagnostic collection utilities of Brocade Fabric OS versions before 10.0.1. When SupportLink is configured to use an authenticated HTTP proxy, the system stores the full proxy URL. Anyone with access to the diagnostic support bundle, such as support personnel or users with access to file shares where support bundles are stored, can extract these cleartext proxy credentials. | ||||
| CVE-2026-92862 | 2026-10-08 | N/A | ||
| The Android application "Ticket Ryutsu Center" improperly handles custom URL schemes, allowing a malicious application to cause access to an arbitrary website via a crafted Intent. | ||||
| CVE-2026-92861 | 2026-10-08 | N/A | ||
| The Android application "Ticket Ryutsu Center" contains hard-coded credentials, which may allow an attacker to obtain an API key used by the application. | ||||
| CVE-2026-87670 | 2026-10-08 | N/A | ||
| An authorization logic vulnerability exists in the Brocade Fabric OS versions before 10.0.1 REST API gateway. The internal gate guarding restricted management endpoints relies exclusively on client-controlled HTTP headers. An authenticated user with any valid REST session can spoof these headers to gain unauthorized access to internal management endpoints. This allows low-privilege users to view sensitive chassis metadata, hardware memory patrolling state, and firmware integrity audit logs. | ||||
| CVE-2026-87669 | 2026-10-08 | N/A | ||
| A missing authorization check in Brocade Fabric OS versions before 10.0.1 REST API interface of affected platform releases allows an authenticated user, regardless of their assigned role or administrative scope, to retrieve complete Monitoring and Alerting Policy Suite (MAPS) violation data across all logical switches. An attacker with low-privilege API access can leverage this endpoint to dump chassis-wide system health metrics, port performance violations, and configuration data without appropriate privileges. | ||||
| CVE-2026-87678 | 2026-10-08 | N/A | ||
| An input validation and output encoding vulnerability exists in the web management interface of Brocade Fabric OS versions before 10.0.1. When configuring Federated Authentication (FA), the system fails to sanitize the Identity Provider (IdP) issuer parameter. An authenticated administrator—or an attacker capable of supplying crafted FA configuration files during an import routine—can inject arbitrary web server directives. This can lead to service denial by preventing the web management daemon from starting, or potentially alter web server security controls. | ||||
| CVE-2026-87679 | 2026-10-08 | N/A | ||
| When Brocade Fabric OS versions before 10.0.1 processes trunk configuration operations, the application parses user-supplied list strings into dynamically allocated heap arrays without enforcing boundary checks on the maximum allowable number of elements. An authenticated administrator can exploit this vulnerability via crafted REST API requests containing an excessive number of list delimiters, causing heap corruption that can result in service crash or arbitrary code execution. | ||||
| CVE-2026-87682 | 1 Brocade | 1 Fabric Os | 2026-10-08 | N/A |
| Multiple OS Command Injection vulnerabilities exist in the management interface and session processing routines of Brocade Fabric OS versions before 10.0.1. Input processing flaws during remote management connection validation and session verification for directory-based user accounts allow untrusted input containing shell metacharacters to reach internal system execution wrappers. An authenticated user or a compromised directory service account can exploit these vulnerabilities to execute arbitrary operating system commands with elevated privileges on the target device. | ||||
| CVE-2026-87683 | 1 Brocade | 1 Fabric Os | 2026-10-08 | N/A |
| Multiple stack-based buffer overflow vulnerabilities exist in the REST API management component of Brocade Fabric OS versions prior to 10.0.1. When processing API request payloads (such as device configuration attributes or port mapping requests) the REST API service fails to properly validate incoming array counts and string lengths against internal buffer capacities. An authenticated attacker with REST API access can transmit crafted, oversized request parameters to induce memory corruption on the execution stack. This may result in a denial-of-service condition (daemon crash) or potential arbitrary code execution within the management process context. | ||||
| CVE-2026-102488 | 2026-10-08 | N/A | ||
| In affected versions, Octopus Server incorrectly evaluates multiple scoped permission assignments, allowing a highly privileged user to obtain deployment permissions beyond those actually granted to them. | ||||
| CVE-2017-20283 | 1 Nxp | 1 Mqx | 2026-10-08 | 6.5 Medium |
| NXP MQX Classic before 5.0 contains an out-of-bounds write vulnerability in the RTCS UDP recvfrom() implementation. Improper enforcement of the application-supplied receive buffer length may allow a crafted UDP packet to overflow the destination buffer, resulting in memory corruption, or denial of service. | ||||
| CVE-2025-70516 | 2026-10-08 | 9.1 Critical | ||
| The websocket handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce proper authentication restrictions against sessionless users. The lack of restrictions grants anyone the ability to view any device resources such as operational logs or perform diagnostic requests. | ||||
| CVE-2026-95386 | 1 Wireshark | 1 Wireshark | 2026-10-08 | 5.5 Medium |
| TTL file parser infinite loop in 4.6.0 to 4.6.8 allows denial of service | ||||
| CVE-2026-95387 | 1 Wireshark | 1 Wireshark | 2026-10-08 | 8.1 High |
| SPDY protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | ||||
| CVE-2026-95388 | 1 Wireshark | 1 Wireshark | 2026-10-08 | 5.5 Medium |
| Sharkd utility crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | ||||
| CVE-2026-95389 | 1 Wireshark | 1 Wireshark | 2026-10-08 | 8.1 High |
| SCTP protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | ||||
| CVE-2026-95390 | 1 Wireshark | 1 Wireshark | 2026-10-08 | 5.5 Medium |
| PEAK CAN TRC file parser crash in 4.6.0 to 4.6.8 allows denial of service | ||||
| CVE-2026-95391 | 1 Wireshark | 1 Wireshark | 2026-10-08 | 5.5 Medium |
| ZigBee ZCL protocol dissector crash in 4.6.0 to 4.6.8 allows denial of service | ||||
| CVE-2026-95392 | 1 Wireshark | 1 Wireshark | 2026-10-08 | 5.5 Medium |
| MBIM protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | ||||