Vulnerabilities
Summary — last 7 days
New vulnerabilities2,831▲ 194 vs. last week
Critical / high1,317▼ 115 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)234▲ 220 vs. last week
12 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (5.5) | 0.20% | — | XEN LibfsimageAI | 7/28/2026 | 7/28/2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver derives several lengths directly from attacker-controlled on-disk fields without validating them: | |
| Deferred | Medium (5.5) | 0.20% | — | XEN LibfsimageAI | 7/28/2026 | 7/28/2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver derives several lengths directly from attacker-controlled on-disk fields without validating them: | |
| Deferred | Medium (5.5) | 0.20% | — | XEN LibfsimageAI | 7/28/2026 | 7/28/2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver derives several lengths directly from attacker-controlled on-disk fields without validating them: | |
| Deferred | Medium (5.5) | 0.20% | — | XEN LibfsimageAI | 7/28/2026 | 7/28/2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver derives several lengths directly from attacker-controlled on-disk fields without validating them: | |
| Deferred | Medium (6.1) | 0.11% | — | Libfsimage Iso9660 DriverAI | 7/28/2026 | 7/28/2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver derives several lengths directly from attacker-controlled on-disk fields without validating them: | |
| Modified | Medium (6.5) | 1.5% | — | Libfsclfs Project Libfsclfs | 9/1/2018 | 6/17/2026 | The libfsclfs_block_read function in libfsclfs_block.c in libfsclfs before 2018-07-25 allows remote attackers to cause a heap-based buffer over-read via a crafted clfs file. NOTE: the vendor has disputed this as described in the GitHub issue comments | |
| Modified | Medium (5.5) | 1.2% | — | Libfsntfs Project Libfsntfs | 6/19/2018 | 6/17/2026 | The libfsntfs_mft_entry_read_attributes function in libfsntfs_mft_entry.c in libfsntfs through 2018-04-20 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted ntfs file. NOTE: the vendor has disputed this as described in libyal/libfsntfs issue 8 on GitHub | |
| Modified | Medium (5.5) | 0.84% | — | Libfsntfs Project Libfsntfs | 6/19/2018 | 6/17/2026 | The libfsntfs_security_descriptor_values_free function in libfsntfs_security_descriptor_values.c in libfsntfs through 2018-04-20 allows remote attackers to cause a denial of service (double-free) via a crafted ntfs file. NOTE: the vendor has disputed this as described in libyal/libfsntfs issue 8 on GitHub | |
| Modified | Medium (5.5) | 1.2% | — | Libfsntfs Project Libfsntfs | 6/19/2018 | 6/17/2026 | The libfsntfs_mft_entry_read_header function in libfsntfs_mft_entry.c in libfsntfs through 2018-04-20 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted ntfs file. NOTE: the vendor has disputed this as described in libyal/libfsntfs issue 8 on GitHub | |
| Modified | Medium (5.5) | 1.2% | — | Libfsntfs Project Libfsntfs | 6/19/2018 | 6/17/2026 | The libfsntfs_reparse_point_values_read_data function in libfsntfs_reparse_point_values.c in libfsntfs through 2018-04-20 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted ntfs file. NOTE: the vendor has disputed this as described in libyal/libfsntfs issue 8 on… | |
| Modified | Medium (5.5) | 1.2% | — | Libfsntfs Project Libfsntfs | 6/19/2018 | 6/17/2026 | The libfsntfs_attribute_read_from_mft function in libfsntfs_attribute.c in libfsntfs through 2018-04-20 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted ntfs file. NOTE: the vendor has disputed this as described in libyal/libfsntfs issue 8 on GitHub | |
| Modified | Medium (6.8) | 1.3% | — | X Libfs | 6/15/2013 | 6/16/2026 | X.org libFS 1.0.4 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to an unexpected sign extension in the FSOpenServer function. |