Export limit exceeded: 403660 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 403660 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (403660 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-107279 | 1 Asynchttpclient Project | 1 Async-http-client | 2026-10-09 | 8.2 High |
| The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. In 3.0.12, a peer offering only Digest qop=auth-int causes mutual-authentication verification to be skipped. AuthenticatorUtils.computeExpectedRspAuth returns no expected value for auth-int, and Interceptors treats that result as unverifiable but nonfatal, so a response with an invalid rspauth value is accepted. A peer that does not know the shared secret can therefore be accepted as the authenticated server. This issue is fixed in version 3.0.13. | ||||
| CVE-2026-107280 | 1 Asynchttpclient Project | 1 Async-http-client | 2026-10-09 | N/A |
| The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13 and 2.16.1, ThreadSafeCookieStore validates Domain attributes with domain matching but does not reject public suffixes. A host beneath a suffix such as co.uk can set a cookie for that suffix, after which the shared cookie store sends it to unrelated hosts under the suffix. This can inject or overwrite session-relevant cookie values across origins. This issue is fixed in versions 3.0.13 and 2.16.1. | ||||
| CVE-2026-107281 | 1 Asynchttpclient Project | 1 Async-http-client | 2026-10-09 | N/A |
| The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13 and 2.16.1, the HTTP/1.1 connection-pool key excludes the authenticated principal for connection-oriented NTLM and Negotiate authentication. A pooled socket authenticated for one request can be reused by a request carrying another principal, and the server executes that later request as the first identity. Basic and Digest are not affected because they authenticate each request. This issue is fixed in versions 3.0.13 and 2.16.1. | ||||
| CVE-2026-107282 | 1 Asynchttpclient Project | 1 Async-http-client | 2026-10-09 | N/A |
| The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13 and 2.16.1, cross-host request replay updates the current request but leaves the target request and related proxy context pointing at the original origin. Connection-pool selection, CONNECT handling, realm selection, and TLS setup can consequently send the original host's path, Host header, Authorization credentials, or plaintext request to the replay destination. Documented ResponseFilter failover and retry paths can trigger the replay. This issue is fixed in versions 3.0.13 and 2.16.1. | ||||
| CVE-2026-107283 | 1 Asynchttpclient Project | 1 Async-http-client | 2026-10-09 | 3.7 Low |
| The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 and 2.16.1, Realm.Builder generates the HTTP Digest client nonce with ThreadLocalRandom rather than a cryptographically secure random source. Digest relies on an unpredictable cnonce to resist chosen-plaintext and credential precomputation attacks, so an observer able to infer generator state can reduce the protection of the authentication exchange. This issue is fixed in versions 3.0.12 and 2.16.1. | ||||
| CVE-2026-107284 | 1 Asynchttpclient Project | 1 Async-http-client | 2026-10-09 | 3.7 Low |
| The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 and 2.16.1, WebSocketHandler.upgrade aborts a handshake whose Sec-WebSocket-Accept value is missing or invalid but continues into pipeline installation and onOpen delivery. Frames coalesced with the invalid 101 response can be decoded and delivered from a peer that did not prove the handshake, although the request future fails and the channel closes. This issue is fixed in versions 3.0.12 and 2.16.1. | ||||
| CVE-2026-107285 | 1 Asynchttpclient Project | 1 Async-http-client | 2026-10-09 | 5.9 Medium |
| The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 and 2.16.1, a proxied ws request is carried through CONNECT, but NettyRequestFactory.newNettyRequest and requestUri decide whether to attach proxy authentication and an absolute-form target only from whether the URI is secure. Because ws is not marked secure, the tunneled WebSocket upgrade sent to the origin includes the proxy's Proxy-Authorization value. Basic credentials are directly recoverable and Digest responses can be replayed or cracked offline. This issue is fixed in versions 3.0.12 and 2.16.1. | ||||
| CVE-2026-88647 | 1 Gnu | 1 Gnutls | 2026-10-09 | 7.4 High |
| A hostname verification bypass in GnuTLS v3.8.13 allows attackers to circumvent the Common Name fallback mechanism and eavesdrop on communications via a crafted certificate. | ||||
| CVE-2026-95209 | 1 Gnu | 1 Gnutls | 2026-10-09 | 7.5 High |
| An issue in gnutls v3.8.13 causes legitimate CA certificates to be rejected, leading to a Denial of Service (DoS). | ||||
| CVE-2026-107577 | 1 Progressive Robot | 1 Hmailserver | 2026-10-09 | 7.5 High |
| Inefficient algorithmic complexity and a non-terminating loop in the MIME processing of received messages in Progressive Robot hMailServer 6.0.0 through 6.3.5 allow a remote unauthenticated attacker to make the mail services unavailable by sending a message. Removing a MIME header parameter whose value is empty and directly followed by a semicolon (for example a Content-Disposition with 'filename=a.bat; filename=;') entered a loop that never terminates, holding a worker thread at full load until the server is restarted; this is reached when the attachment blocker renames a blocked attachment or a filename is set over the REST API. Separately, decoding a header field that holds many RFC 2047 encoded words of an encoding other than base64 or quoted-printable, removing a parameter with many RFC 2231 continuations, and deleting many header fields of one name each took time growing with the square of the message, on the small thread pools that serve IMAP, SMTP and POP3 connections, delivery and the REST API. | ||||
| CVE-2026-107587 | 1 Progressive Robot | 1 Hmailserver | 2026-10-09 | 5.9 Medium |
| Improper certificate validation in the webmail of Progressive Robot hMailServer 6.3.2 through 6.3.5 allows a remote unauthenticated attacker to have S/MIME-encrypted mail that the account later sends to another correspondent also encrypted to the attacker's key. When its recipient opened a signed message, the webmail kept the signer's certificate for encrypting replies whether or not the server found its chain trusted, under the first e-mail address the certificate listed rather than the message's From address, and beside any certificate already held for that address. Encrypted mail later sent from the webmail to that address was encrypted to every certificate held for it, so a holder of the kept certificate's key who obtains a copy of such a message can read it. | ||||
| CVE-2026-87108 | 1 Mongodb | 1 Ops Manager | 2026-10-09 | 3.1 Low |
| An authenticated Ops Manager user with a read-only project role can retrieve a daily host monitoring record associated with a different project when they possess the required record identifier. Insufficient ownership validation can expose deployment metadata, including host and configuration details. | ||||
| CVE-2026-95184 | 1 Gnu | 1 Gnutls | 2026-10-09 | 7.5 High |
| Improper certificate validation in gnutls v3.8.13 causes the application to reject legitimate certificates for valid users, leading to a Denial of Service (DoS). | ||||
| CVE-2026-95210 | 1 Gnu | 1 Gnutls | 2026-10-09 | 9.1 Critical |
| Improper certificate validation in gnutls v3.8.13 causes the application to accept certificates containing invalid extensions. | ||||
| CVE-2026-102488 | 1 Octopus | 1 Octopus Server | 2026-10-09 | N/A |
| In affected versions, Octopus Server incorrectly evaluates multiple scoped permission assignments, allowing a highly privileged user to obtain deployment permissions beyond those actually granted to them. | ||||
| CVE-2023-5649 | 1 Broadcom | 1 Brocade Active Support Connectivity Gateway | 2026-10-09 | N/A |
| An Improper Input Validation vulnerability for the registered case credentials in Brocade ASCG before v3.0 could allow a local authenticated user to provide invalid inputs like special characters leading to a Denial of Service (DoS) when collecting “supportsave” from a Brocade Switch. | ||||
| CVE-2026-5047 | 1 Broadcom | 1 Brocade Sannav | 2026-10-09 | N/A |
| A vulnerability in Brocade SANnav before 2.4.0b and 3.0.0 prints encoded passwords and authentication tokens in log files. The vulnerability could allow an authenticated attacker with access to the log file including the SANnav supportsave to access the passwords. | ||||
| CVE-2026-5048 | 1 Broadcom | 1 Brocade Sannav | 2026-10-09 | N/A |
| In Brocade SANnav before 3.0.0a, an SQL Injection vulnerability in various external API inventories have a vulnerability that allows an authenticated attacker to inject malicious data into some of the REST API -query parameters. | ||||
| CVE-2026-5049 | 1 Broadcom | 1 Brocade Sannav | 2026-10-09 | N/A |
| A path traversal vulnerability affects the The Zone Alias Import flow feature in Brocade SANnav before 3.0.0a. A local authenticated attacker can write an uploaded content outside the intended directory. | ||||
| CVE-2026-5769 | 1 Broadcom | 1 Brocade Sannav | 2026-10-09 | N/A |
| A vulnerability in Brocade SANnav before 3.0.1 can have the Brocade Fabric OS switch admin password captured in plaintext within a memory swap file on the server hosting the Brocade SANnav Virtual Machine (VM). This can happen when the SANnav server encounters an Out Of Memory (OOM) condition. The vulnerability could allow an authenticated admin user with access to the server hosting the SANnav to potentially view the memory swap file and access the password(s). | ||||