Vulnerabilities

Summary — last 7 days

New vulnerabilities2,831▲ 194 vs. last week
Critical / high1,317▼ 115 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)234▲ 220 vs. last week
–

12 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (5.5)0.20%—XEN LibfsimageAI7/28/20267/28/2026
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver derives several lengths directly from attacker-controlled on-disk fields without validating them:
DeferredMedium (5.5)0.20%—XEN LibfsimageAI7/28/20267/28/2026
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver derives several lengths directly from attacker-controlled on-disk fields without validating them:
DeferredMedium (5.5)0.20%—XEN LibfsimageAI7/28/20267/28/2026
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver derives several lengths directly from attacker-controlled on-disk fields without validating them:
DeferredMedium (5.5)0.20%—XEN LibfsimageAI7/28/20267/28/2026
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver derives several lengths directly from attacker-controlled on-disk fields without validating them:
DeferredMedium (6.1)0.11%—Libfsimage Iso9660 DriverAI7/28/20267/28/2026
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver derives several lengths directly from attacker-controlled on-disk fields without validating them:
ModifiedMedium (6.5)1.5%—Libfsclfs Project Libfsclfs9/1/20186/17/2026
The libfsclfs_block_read function in libfsclfs_block.c in libfsclfs before 2018-07-25 allows remote attackers to cause a heap-based buffer over-read via a crafted clfs file. NOTE: the vendor has disputed this as described in the GitHub issue comments
ModifiedMedium (5.5)1.2%—Libfsntfs Project Libfsntfs6/19/20186/17/2026
The libfsntfs_mft_entry_read_attributes function in libfsntfs_mft_entry.c in libfsntfs through 2018-04-20 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted ntfs file. NOTE: the vendor has disputed this as described in libyal/libfsntfs issue 8 on GitHub
ModifiedMedium (5.5)0.84%—Libfsntfs Project Libfsntfs6/19/20186/17/2026
The libfsntfs_security_descriptor_values_free function in libfsntfs_security_descriptor_values.c in libfsntfs through 2018-04-20 allows remote attackers to cause a denial of service (double-free) via a crafted ntfs file. NOTE: the vendor has disputed this as described in libyal/libfsntfs issue 8 on GitHub
ModifiedMedium (5.5)1.2%—Libfsntfs Project Libfsntfs6/19/20186/17/2026
The libfsntfs_mft_entry_read_header function in libfsntfs_mft_entry.c in libfsntfs through 2018-04-20 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted ntfs file. NOTE: the vendor has disputed this as described in libyal/libfsntfs issue 8 on GitHub
ModifiedMedium (5.5)1.2%—Libfsntfs Project Libfsntfs6/19/20186/17/2026
The libfsntfs_reparse_point_values_read_data function in libfsntfs_reparse_point_values.c in libfsntfs through 2018-04-20 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted ntfs file. NOTE: the vendor has disputed this as described in libyal/libfsntfs issue 8 on…
ModifiedMedium (5.5)1.2%—Libfsntfs Project Libfsntfs6/19/20186/17/2026
The libfsntfs_attribute_read_from_mft function in libfsntfs_attribute.c in libfsntfs through 2018-04-20 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted ntfs file. NOTE: the vendor has disputed this as described in libyal/libfsntfs issue 8 on GitHub
ModifiedMedium (6.8)1.3%—X Libfs6/15/20136/16/2026
X.org libFS 1.0.4 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to an unexpected sign extension in the FSOpenServer function.
Orbitaley — Vulnerabilities