CVE-2026-34191 Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle
Information published.
Categories: Microsoft
CVE-2025-49506 Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack
Information published.
Categories: Microsoft
CVE-2026-47243 Kata guest escape: runtime-rs guest-root to host-root escape via virtiofs
Information published.
Categories: Microsoft
CVE-2026-64676 Kata Containers: Unauthorized mem-agent ttRPC methods let an untrusted host tamper with confidential-guest memory
Information published.
Categories: Microsoft
CVE-2026-50540 Kata Containers: Config Path Annotation Arbitrary File Loading
Information published.
Categories: Microsoft
CVE-2026-55995 Double-free in the iSNS attribute decoder in open-iscsi
Information published.
Categories: Microsoft
CVE-2026-44944 iscsiuio control-socket authentication bypass in open-iscsi
Information published.
Categories: Microsoft
CVE-2026-44943 remote limited file-write as root via discovery in open-iscsi
Information published.
Categories: Microsoft
CVE-2026-6879 Quadratic Behavior in xml.etree.ElementPath Index Predicates
Information published.
Categories: Microsoft
CVE-2026-32597 PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation)
Information published.
Categories: Microsoft
CVE-2026-48524 PyJWT: PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)
Information published.
Categories: Microsoft
CVE-2025-62725 Docker Compose Vulnerable to Path Traversal via OCI Artifact Layer Annotations
Information published.
Categories: Microsoft
CVE-2026-68480 x86/bugs: Make Safe-RET robust against interrupt injection
Information published.
Categories: Microsoft
CVE-2019-9192 In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion
Information published.
Categories: Microsoft
CVE-2019-9924 rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execute any command with the permissions of the shell.
Information published.
Categories: Microsoft
CVE-2010-4052 Stack consumption vulnerability in the regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent attackers to cause a denial of service (resource exhaustion) via a...
Information published.
Categories: Microsoft
CVE-2019-6706 Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example a crash outcome might be achieved by an attacker who is able to trigger a debug.upvaluejoin call in which the arguments have certain relationships.
Information published.
Categories: Microsoft
CVE-2018-6829 cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic...
Information published.
Categories: Microsoft
CVE-2018-1128 It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker having access to ceph cluster network who is able to sniff packets on network can use this...
Information published.
Categories: Microsoft
CVE-2018-5407 Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.
Information published.
Categories: Microsoft


