DE EN FR
hlukh.ch MàJ : 2026-02-25T09:01:16.562Z · week: 2024-W02

Alertes de sécurité

Sélectionnées à partir d'avis publics. Objectif : visibilité, contexte et export rapide — sans clickbait.

Alertes récentes
CVE-2024-20672
.NET Denial of Service Vulnerability
2026‑02‑20 · CVE-2024-20672
MSRC 2026‑02‑20 Élevée
CVE-2024-21312
.NET Framework Denial of Service Vulnerability
2026‑02‑20 · CVE-2024-21312
MSRC 2026‑02‑20 Élevée
CVE-2023-50711
`serde` deserialization for `FamStructWrapper` lacks bound checks that could potentially lead to out-of-bounds memory access
2026‑02‑20 · CVE-2023-50711
MSRC 2026‑02‑20 Moyenne
CVE-2023-3772
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑20 · CVE-2023-3772
MSRC 2026‑02‑20 Moyenne
CVE-2023-3773
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑20 · CVE-2023-3773
MSRC 2026‑02‑20 Moyenne
CVE-2023-51258
A memory leak issue discovered in YASM v.1.3.0 allows a local attacker to cause a denial of service via the new_Token function in the modules/preprocs/nasm/nasm-pp:1512.
2026‑02‑20 · CVE-2023-51258
MSRC 2026‑02‑20 Moyenne
CVE-2024-0752
A use-after-free crash could have occurred on macOS if a Firefox update were being applied on a very busy system. This could have resulted in an exploitable crash. This vulnerability affects Firefox &lt; 122.
2026‑02‑20 · CVE-2024-0752
MSRC 2026‑02‑20 Moyenne
CVE-2024-23829
aiohttp's HTTP parser (the python one, not llhttp) still overly lenient about separators
2026‑02‑20 · CVE-2024-23829
MSRC 2026‑02‑20 Moyenne
CVE-2023-49558
An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_mmac_params function in the modules/preprocs/nasm/nasm-pp.c component.
2026‑02‑20 · CVE-2023-49558
MSRC 2026‑02‑20 Moyenne
CVE-2023-49555
An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_smacro function in the modules/preprocs/nasm/nasm-pp.c component.
2026‑02‑20 · CVE-2023-49555
MSRC 2026‑02‑20 Moyenne
CVE-2023-49557
An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the yasm_section_bcs_first function in the libyasm/section.c component.
2026‑02‑20 · CVE-2023-49557
MSRC 2026‑02‑20 Moyenne
CVE-2022-48619
An issue was discovered in drivers/input/input.c in the Linux kernel before 5.17.10. An attacker can cause a denial of service (panic) because input_set_capability mishandles the situation in which an event code falls outside of a bitmap.
2026‑02‑20 · CVE-2022-48619
MSRC 2026‑02‑20 Moyenne
CVE-2024-22705
An issue was discovered in ksmbd in the Linux kernel before 6.6.10. smb2_get_data_area_len in fs/smb/server/smb2misc.c can cause an smb_strndup_from_utf16 out-of-bounds access because the relationship between Name data and CreateContexts data is mishandled.
2026‑02‑20 · CVE-2024-22705
MSRC 2026‑02‑20 Élevée
CVE-2024-0741
An out of bounds write in ANGLE could have allowed an attacker to corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox &lt; 122, Firefox ESR &lt; 115.7, and Thunderbird &lt; 115.7.
2026‑02‑20 · CVE-2024-0741
MSRC 2026‑02‑20 Moyenne
CVE-2023-6040
An out-of-bounds access vulnerability involving netfilter was reported and fixed as: f1082dd31fe4 (netfilter: nf_tables: Reject tables of unsupported family)
2026‑02‑20 · CVE-2023-6040
MSRC 2026‑02‑20 Élevée
CVE-2024-20676
Azure Storage Mover Remote Code Execution Vulnerability
2026‑02‑20 · CVE-2024-20676
MSRC 2026‑02‑20 Élevée
CVE-2024-20666
BitLocker Security Feature Bypass Vulnerability
2026‑02‑20 · CVE-2024-20666
MSRC 2026‑02‑20 Moyenne
CVE-2023-49556
Buffer Overflow vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expr_delete_term function in the libyasm/expr.c component.
2026‑02‑20 · CVE-2023-49556
MSRC 2026‑02‑20 Moyenne
CVE-2024-23650
BuildKit possible panic when incorrect parameters sent from frontend
2026‑02‑20 · CVE-2024-23650
MSRC 2026‑02‑20 Moyenne
CVE-2024-23851
copy_params in drivers/md/dm-ioctl.c in the Linux kernel through 6.7.1 can attempt to allocate more than INT_MAX bytes and crash because of a missing param_kernel-&gt;data_size check. This is related to ctl_ioctl.
2026‑02‑20 · CVE-2024-23851
MSRC 2026‑02‑20 Moyenne
CVE-2023-6476
Cri-o: pods are able to break out of resource confinement on cgroupv2
2026‑02‑20 · CVE-2023-6476
MSRC 2026‑02‑20 Moyenne
CVE-2023-7207
Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --no-absolute-filenames.
2026‑02‑20 · CVE-2023-7207
MSRC 2026‑02‑20 Moyenne
CVE-2023-4001
Grub2: bypass the grub password protection feature
2026‑02‑20 · CVE-2023-4001
MSRC 2026‑02‑20 Moyenne
CVE-2024-21305
Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability
2026‑02‑20 · CVE-2024-21305
MSRC 2026‑02‑20 Moyenne
CVE-2024-0208
Improper Handling of Missing Values in Wireshark
2026‑02‑20 · CVE-2024-0208
MSRC 2026‑02‑20 Élevée
CVE-2024-23850
In btrfs_get_root_ref in fs/btrfs/disk-io.c in the Linux kernel through 6.7.1 there can be an assertion failure and crash because a subvolume can be read out too soon after its root item is inserted upon subvolume creation.
2026‑02‑20 · CVE-2024-23850
MSRC 2026‑02‑20 Moyenne
CVE-2024-23849
In rds_recv_track_latency in net/rds/af_rds.c in the Linux kernel through 6.7.1 there is an off-by-one error for an RDS_MSG_RX_DGRAM_TRACE_MAX comparison resulting in out-of-bounds access.
2026‑02‑20 · CVE-2024-23849
MSRC 2026‑02‑20 Moyenne
CVE-2024-0753
In specific HSTS configurations an attacker could have bypassed HSTS on a subdomain. This vulnerability affects Firefox &lt; 122, Firefox ESR &lt; 115.7, and Thunderbird &lt; 115.7.
2026‑02‑20 · CVE-2024-0753
MSRC 2026‑02‑20 Moyenne
CVE-2023-51042
In the Linux kernel before 6.4.12 amdgpu_cs_wait_all_fences in drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c has a fence use-after-free.
2026‑02‑20 · CVE-2023-51042
MSRC 2026‑02‑20 Élevée
CVE-2023-51043
In the Linux kernel before 6.4.5 drivers/gpu/drm/drm_atomic.c has a use-after-free during a race condition between a nonblocking atomic commit and a driver unload.
2026‑02‑20 · CVE-2023-51043
MSRC 2026‑02‑20 Élevée
CVE-2023-46343
In the Linux kernel before 6.5.9 there is a NULL pointer dereference in send_acknowledge in net/nfc/nci/spi.c.
2026‑02‑20 · CVE-2023-46343
MSRC 2026‑02‑20 Moyenne
CVE-2024-23848
In the Linux kernel through 6.7.1, there is a use-after-free in cec_queue_msg_fh, related to drivers/media/cec/core/cec-adap.c and drivers/media/cec/core/cec-api.c.
2026‑02‑20 · CVE-2024-23848
MSRC 2026‑02‑20 Moyenne
CVE-2024-23307
Integer overflow in raid5_cache_count in Linux kernel
2026‑02‑20 · CVE-2024-23307
MSRC 2026‑02‑20 Moyenne
CVE-2022-2602
io_uring UAF Unix SCM garbage collection
2026‑02‑20 · CVE-2022-2602
MSRC 2026‑02‑20 Élevée
CVE-2022-2586
It was discovered that a nft object or expression could reference a nft set on a different nft table leading to a use-after-free once that table was deleted.
2026‑02‑20 · CVE-2022-2586
MSRC 2026‑02‑20 Élevée
CVE-2022-2588
It was discovered that the cls_route filter implementation in the Linux kernel would not remove an old filter from the hashtable before freeing it if its handle had the value 0.
2026‑02‑20 · CVE-2022-2588
MSRC 2026‑02‑20 Élevée
CVE-2022-2585
It was discovered that when exec'ing from a non-leader thread armed POSIX CPU timers would be left on a list but freed leading to a use-after-free.
2026‑02‑20 · CVE-2022-2585
MSRC 2026‑02‑20 Élevée
CVE-2024-22195
Jinja vulnerable to Cross-Site Scripting (XSS)
2026‑02‑20 · CVE-2024-22195
MSRC 2026‑02‑20 Moyenne
CVE-2023-6270
Kernel: aoe: improper reference count leads to use-after-free vulnerability
2026‑02‑20 · CVE-2023-6270
MSRC 2026‑02‑20 Élevée
CVE-2024-0565
Kernel: cifs filesystem decryption improper input validation remote code execution vulnerability in function receive_encrypted_standard of client
2026‑02‑20 · CVE-2024-0565
MSRC 2026‑02‑20 Élevée
CVE-2024-0641
Kernel: deadlock leading to denial of service in tipc_crypto_key_revoke
2026‑02‑20 · CVE-2024-0641
MSRC 2026‑02‑20 Moyenne
CVE-2023-6531
Kernel: gc's deletion of an skb races with unix_stream_read_generic() leading to uaf
2026‑02‑20 · CVE-2023-6531
MSRC 2026‑02‑20 Élevée
CVE-2024-0340
Kernel: information disclosure in vhost/vhost.c:vhost_new_msg()
2026‑02‑20 · CVE-2024-0340
MSRC 2026‑02‑20 Moyenne
CVE-2024-0646
Kernel: ktls overwrites readonly memory pages when using function splice with a ktls socket as destination
2026‑02‑20 · CVE-2024-0646
MSRC 2026‑02‑20 Élevée
CVE-2024-0639
Kernel: potential deadlock on &amp;net-&gt;sctp.addr_wq_lock leading to dos
2026‑02‑20 · CVE-2024-0639
MSRC 2026‑02‑20 Moyenne
CVE-2023-7192
Kernel: refcount leak in ctnetlink_create_conntrack()
2026‑02‑20 · CVE-2023-7192
MSRC 2026‑02‑20 Moyenne
CVE-2024-0562
Kernel: use-after-free after removing device in wb_inode_writeback_end in mm/page-writeback.c
2026‑02‑20 · CVE-2024-0562
MSRC 2026‑02‑20 Élevée
CVE-2024-0775
Kernel: use-after-free while changing the mount option in __ext4_remount leading
2026‑02‑20 · CVE-2024-0775
MSRC 2026‑02‑20 Élevée
CVE-2023-6004
Libssh: proxycommand/proxyjump features allow injection of malicious code through hostname
2026‑02‑20 · CVE-2023-6004
MSRC 2026‑02‑20 Moyenne
CVE-2023-52356
Libtiff: segment fault in libtiff in tiffreadrgbatileext() leading to denial of service
2026‑02‑20 · CVE-2023-52356
MSRC 2026‑02‑20 Élevée
Page 1