DE EN FR
hlukh.ch Updated: 2026-02-25T12:01:17.018Z · week: 2024-W07

Security Warnings

Curated from public advisories. Focus: visibility, context and fast export — no clickbait.

Latest warnings
CVE-2024-21386
.NET Denial of Service Vulnerability
2026‑02‑20 · CVE-2024-21386
MSRC 2026‑02‑20 High
CVE-2024-21404
.NET Denial of Service Vulnerability
2026‑02‑20 · CVE-2024-21404
MSRC 2026‑02‑20 High
CVE-2023-46838
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑20 · CVE-2023-46838
MSRC 2026‑02‑20 High
CVE-2021-38593
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑20 · CVE-2021-38593
MSRC 2026‑02‑20 High
CVE-2023-6200
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑20 · CVE-2023-6200
MSRC 2026‑02‑20 High
CVE-2024-24476
A buffer overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the pan/addr_resolv.c, and ws_manuf_lookup_str(), size components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected.
2026‑02‑20 · CVE-2024-24476
MSRC 2026‑02‑20 High
CVE-2024-24479
A Buffer Overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the wsutil/to_str.c, and format_fractional_part_nsecs components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected.
2026‑02‑20 · CVE-2024-24479
MSRC 2026‑02‑20 High
CVE-2024-1550
A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly, which could have led to user confusion and inadvertently granting permissions they did not intend to grant. This vulnerability affects Firefox &lt; 123, Firefox ESR &lt; 115.8, and Thunderbird &lt; 115.8.
2026‑02‑20 · CVE-2024-1550
MSRC 2026‑02‑20 Medium
CVE-2024-25740
A memory leak flaw was found in the UBI driver in drivers/mtd/ubi/attach.c in the Linux kernel through 6.7.4 for UBI_IOCATT, because kobj-&gt;name is not released.
2026‑02‑20 · CVE-2024-25740
MSRC 2026‑02‑20 Medium
CVE-2024-22019
A vulnerability in Node.js HTTP servers allows an attacker to send a specially crafted HTTP request with chunked encoding leading to resource exhaustion and denial of service (DoS). The server reads an unbounded number of bytes from a single connection exploiting the lack of limitations on chunk extension bytes. The issue can cause CPU and network bandwidth exhaustion bypassing standard safeguards like timeouts and body size limits.
2026‑02‑20 · CVE-2024-22019
MSRC 2026‑02‑20 High
CVE-2024-24478
An issue in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the packet-bgp.c, dissect_bgp_open(tvbuff_t*tvb, proto_tree*tree, packet_info*pinfo), optlen components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected.
2026‑02‑20 · CVE-2024-24478
MSRC 2026‑02‑20 High
CVE-2024-26328
An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c does not set NumVFs to PCI_SRIOV_TOTAL_VF, and thus interaction with hw/nvme/ctrl.c is mishandled.
2026‑02‑20 · CVE-2024-26328
MSRC 2026‑02‑20 Medium
CVE-2024-26327
An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c mishandles the situation where a guest writes NumVFs greater than TotalVFs, leading to a buffer overflow in VF implementations.
2026‑02‑20 · CVE-2024-26327
MSRC 2026‑02‑20 Medium
CVE-2024-25710
Apache Commons Compress: Denial of service caused by an infinite loop for a corrupted DUMP file
2026‑02‑20 · CVE-2024-25710
MSRC 2026‑02‑20 High
CVE-2024-26308
Apache Commons Compress: OutOfMemoryError unpacking broken Pack200 file
2026‑02‑20 · CVE-2024-26308
MSRC 2026‑02‑20 Medium
CVE-2024-23807
Apache Xerces C++: Use-after-free on external DTD scan
2026‑02‑20 · CVE-2024-23807
MSRC 2026‑02‑20 High
CVE-2023-52481
arm64: errata: Add Cortex-A520 speculative unprivileged load workaround
2026‑02‑20 · CVE-2023-52481
MSRC 2026‑02‑20 Medium
CVE-2024-21329
Azure Connected Machine Agent Elevation of Privilege Vulnerability
2026‑02‑20 · CVE-2024-21329
MSRC 2026‑02‑20 High
CVE-2024-20667
Azure DevOps Server Remote Code Execution Vulnerability
2026‑02‑20 · CVE-2024-20667
MSRC 2026‑02‑20 High
CVE-2024-20679
Azure Stack Hub Spoofing Vulnerability
2026‑02‑20 · CVE-2024-20679
MSRC 2026‑02‑20 Medium
CVE-2022-48624
close_altfile in filename.c in less before 606 omits shell_quote calls for LESSCLOSE.
2026‑02‑20 · CVE-2022-48624
MSRC 2026‑02‑20 High
CVE-2024-25739
create_empty_lvol in drivers/mtd/ubi/vtbl.c in the Linux kernel through 6.7.4 can attempt to allocate zero bytes and crash because of a missing check for ubi-&gt;leb_size.
2026‑02‑20 · CVE-2024-25739
MSRC 2026‑02‑20 Medium
CVE-2024-25112
Denial of service due to unbounded recursion in QuickTimeVideo::multipleEntriesDecoder in Exiv2
2026‑02‑20 · CVE-2024-25112
MSRC 2026‑02‑20 Medium
CVE-2023-52485
drm/amd/display: Wake DMCUB before sending a command
2026‑02‑20 · CVE-2023-52485
MSRC 2026‑02‑20 Medium
CVE-2024-26607
drm/bridge: sii902x: Fix probing race issue
2026‑02‑20 · CVE-2024-26607
MSRC 2026‑02‑20 Medium
CVE-2024-21394
Dynamics 365 Field Service Spoofing Vulnerability
2026‑02‑20 · CVE-2024-21394
MSRC 2026‑02‑20 High
CVE-2024-21396
Dynamics 365 Sales Spoofing Vulnerability
2026‑02‑20 · CVE-2024-21396
MSRC 2026‑02‑20 High
CVE-2024-21328
Dynamics 365 Sales Spoofing Vulnerability
2026‑02‑20 · CVE-2024-21328
MSRC 2026‑02‑20 High
CVE-2024-25260
elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.
2026‑02‑20 · CVE-2024-25260
MSRC 2026‑02‑20 Medium
CVE-2023-46045
Graphviz 2.36.0 through 9.x before 10.0.1 has an out-of-bounds read via a crafted config6a file. NOTE: exploitability may be uncommon because this file is typically owned by root.
2026‑02‑20 · CVE-2023-46045
MSRC 2026‑02‑20 High
CVE-2024-1552
Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior.*Note:* This issue only affects 32-bit ARM devices. This vulnerability affects Firefox &lt; 123, Firefox ESR &lt; 115.8, and Thunderbird &lt; 115.8.
2026‑02‑20 · CVE-2024-1552
MSRC 2026‑02‑20 High
CVE-2024-21348
Internet Connection Sharing (ICS) Denial of Service Vulnerability
2026‑02‑20 · CVE-2024-21348
MSRC 2026‑02‑20 High
CVE-2024-21412
Internet Shortcut Files Security Feature Bypass Vulnerability
2026‑02‑20 · CVE-2024-21412
MSRC 2026‑02‑20 High
CVE-2024-1312
Kernel: race condition leads to use after free during vma lock in lock_vma_under_rcu
2026‑02‑20 · CVE-2024-1312
MSRC 2026‑02‑20 Medium
CVE-2024-26594
ksmbd: validate mech token in session setup
2026‑02‑20 · CVE-2024-26594
MSRC 2026‑02‑20 High
CVE-2024-24575
libgit2 is vulnerable to a denial of service attack in `git_revparse_single`
2026‑02‑20 · CVE-2024-24575
MSRC 2026‑02‑20 High
CVE-2024-24577
libgit2 is vulnerable to arbitrary code execution due to heap corruption in `git_index_add`
2026‑02‑20 · CVE-2024-24577
MSRC 2026‑02‑20 Critical
CVE-2024-26588
LoongArch: BPF: Prevent out-of-bounds memory access
2026‑02‑20 · CVE-2024-26588
MSRC 2026‑02‑20 High
CVE-2024-21349
Microsoft ActiveX Data Objects Remote Code Execution Vulnerability
2026‑02‑20 · CVE-2024-21349
MSRC 2026‑02‑20 High
CVE-2024-21381
Microsoft Azure Active Directory B2C Spoofing Vulnerability
2026‑02‑20 · CVE-2024-21381
MSRC 2026‑02‑20 Medium
CVE-2024-21397
Microsoft Azure File Sync Elevation of Privilege Vulnerability
2026‑02‑20 · CVE-2024-21397
MSRC 2026‑02‑20 Medium
CVE-2024-21403
Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability
2026‑02‑20 · CVE-2024-21403
MSRC 2026‑02‑20 Critical
CVE-2024-21376
Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability
2026‑02‑20 · CVE-2024-21376
MSRC 2026‑02‑20 Critical
CVE-2024-21364
Microsoft Azure Site Recovery Elevation of Privilege Vulnerability
2026‑02‑20 · CVE-2024-21364
MSRC 2026‑02‑20 Critical
CVE-2024-21315
Microsoft Defender for Endpoint Protection Elevation of Privilege Vulnerability
2026‑02‑20 · CVE-2024-21315
MSRC 2026‑02‑20 High
CVE-2024-21389
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
2026‑02‑20 · CVE-2024-21389
MSRC 2026‑02‑20 High
CVE-2024-21393
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
2026‑02‑20 · CVE-2024-21393
MSRC 2026‑02‑20 High
CVE-2024-21395
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
2026‑02‑20 · CVE-2024-21395
MSRC 2026‑02‑20 High
CVE-2024-21327
Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability
2026‑02‑20 · CVE-2024-21327
MSRC 2026‑02‑20 High
CVE-2024-21380
Microsoft Dynamics Business Central/NAV Information Disclosure Vulnerability
2026‑02‑20 · CVE-2024-21380
MSRC 2026‑02‑20 High
Page 1