Export limit exceeded: 402866 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (402866 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-87676 2026-10-08 N/A
A stack-based buffer overflow vulnerability exists in the security library component of Brocade Fabric OS versions before 10.0.1. When parsing uploaded X.509 PEM certificates for management display, the system improperly validates the length of the Authority Key Identifier (AKI) extension before copying string tokens into an internal memory buffer. An authenticated user with administrative privileges to import custom certificates can supply a certificate containing an intentionally oversized AKI extension. When the system processes or renders the certificate attributes, this can trigger a stack memory corruption leading to a denial-of-service (DoS) condition by crashing the management daemon.
CVE-2026-87686 2026-10-08 N/A
An authentication and access control bypass vulnerability exists in the web server management interface of Brocade Fabric OS versions before 10.0.1. The web dispatcher routine evaluates internal management VLAN trust decisions using the client-supplied HTTP host header instead of the actual socket transport layer source IP address. Successful exploitation allows the attacker to bypass IP-filtering access control lists (ACLs) and obtain sensitive device metadata (such as model, serial number, hardware revision, and firmware version) without authentication.
CVE-2026-87679 2026-10-08 N/A
When Brocade Fabric OS versions before 10.0.1 processes trunk configuration operations, the application parses user-supplied list strings into dynamically allocated heap arrays without enforcing boundary checks on the maximum allowable number of elements. An authenticated administrator can exploit this vulnerability via crafted REST API requests containing an excessive number of list delimiters, causing heap corruption that can result in service crash or arbitrary code execution.
CVE-2026-87682 1 Brocade 1 Fabric Os 2026-10-08 N/A
Multiple OS Command Injection vulnerabilities exist in the management interface and session processing routines of Brocade Fabric OS versions before 10.0.1. Input processing flaws during remote management connection validation and session verification for directory-based user accounts allow untrusted input containing shell metacharacters to reach internal system execution wrappers. An authenticated user or a compromised directory service account can exploit these vulnerabilities to execute arbitrary operating system commands with elevated privileges on the target device.
CVE-2026-87683 1 Brocade 1 Fabric Os 2026-10-08 N/A
Multiple stack-based buffer overflow vulnerabilities exist in the REST API management component of Brocade Fabric OS versions prior to 10.0.1. When processing API request payloads (such as device configuration attributes or port mapping requests) the REST API service fails to properly validate incoming array counts and string lengths against internal buffer capacities. An authenticated attacker with REST API access can transmit crafted, oversized request parameters to induce memory corruption on the execution stack. This may result in a denial-of-service condition (daemon crash) or potential arbitrary code execution within the management process context.
CVE-2026-102488 2026-10-08 N/A
In affected versions, Octopus Server incorrectly evaluates multiple scoped permission assignments, allowing a highly privileged user to obtain deployment permissions beyond those actually granted to them.
CVE-2026-87680 1 Brocade 1 Fabric Os 2026-10-08 N/A
A command injection vulnerability in the REST API management interface of Brocade Fabric OS versions before 10.0.1 allows an authenticated user to execute arbitrary system commands via crafted input parameters.
CVE-2026-94578 2026-10-08 N/A
Brocade Fabric OS versions before 10.0.1 contain an authorization logic vulnerability in the AAA (Authentication, Authorization, and Accounting) integration framework allows remote authenticated users to gain root-equivalent chassis access controls. By returning specific, crafted Vendor-Specific Attributes (VSAs) or directory claims from an external identity provider (such as RADIUS, LDAP, TACACS+, or Federated IDP), an account can bypass administrative role restriction checks during session establishment.
CVE-2026-87659 2026-10-08 N/A
A critical authorization bypass vulnerability exists in the Management Server handling of Brocade Fabric OS versions before 10.0.1. A compromised switch connected to the fabric can transmit crafted inband Fibre Channel vendor-unique CT (Common Transport) management requests to bypass administrative authentication. Successful exploitation allows an unauthorized peer switch to execute administrative actions on the target device, including resetting administrative passwords, initiating system reboots, and triggering firmware downloads.
CVE-2026-87671 2026-10-08 N/A
An out-of-bounds memory read vulnerability exists in the web management daemon of Brocade Fabric OS versions before 10.0.1. Unauthenticated HTTP endpoints process specific URL query parameters without validating array index boundaries or performing numerical range checks. An unauthenticated remote attacker can exploit this issue by sending a single, crafted HTTP request containing extreme numerical values in the query string. This causes an invalid memory dereference, resulting in a crash of the web management process (Denial of Service) and potential temporary management-plane disruption.
CVE-2026-87684 2026-10-08 N/A
A stack-based buffer overflow vulnerability exists in the SNMP daemon request handling of Brocade Fabric versions before 10.0.1. When processing an incoming SNMPv3 packet, an internal statistics gathering handler copies user-supplied context name data into a fixed-size buffer without properly validating the length of the string. A remote, unauthenticated attacker (under default configuration) can exploit this vulnerability by sending a specially crafted SNMPv3 packet, leading to memory corruption, daemon crash (Denial of Service), or potential arbitrary code execution.
CVE-2017-20283 1 Nxp 1 Mqx 2026-10-08 6.5 Medium
NXP MQX Classic before 5.0 contains an out-of-bounds write vulnerability in the RTCS UDP recvfrom() implementation. Improper enforcement of the application-supplied receive buffer length may allow a crafted UDP packet to overflow the destination buffer, resulting in memory corruption, or denial of service.
CVE-2026-87726 2026-10-08 3.9 Low
Insufficient API bounds checking in phalFelica in NXP NXPNfcRdLib RC663 through 07.14.00_Pub may allow an attacker with privileges or an untrusted third party to access unintended memory regions, potentially leading to limited loss of confidentiality, integrity, and availability. All software versions from 07.18.00 onwards have fixed this problem.
CVE-2025-70516 2026-10-08 9.1 Critical
The websocket handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce proper authentication restrictions against sessionless users. The lack of restrictions grants anyone the ability to view any device resources such as operational logs or perform diagnostic requests.
CVE-2026-95386 1 Wireshark 1 Wireshark 2026-10-08 5.5 Medium
TTL file parser infinite loop in 4.6.0 to 4.6.8 allows denial of service
CVE-2026-95387 1 Wireshark 1 Wireshark 2026-10-08 8.1 High
SPDY protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-95388 1 Wireshark 1 Wireshark 2026-10-08 5.5 Medium
Sharkd utility crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-95389 1 Wireshark 1 Wireshark 2026-10-08 8.1 High
SCTP protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-95390 1 Wireshark 1 Wireshark 2026-10-08 5.5 Medium
PEAK CAN TRC file parser crash in 4.6.0 to 4.6.8 allows denial of service
CVE-2026-95391 1 Wireshark 1 Wireshark 2026-10-08 5.5 Medium
ZigBee ZCL protocol dissector crash in 4.6.0 to 4.6.8 allows denial of service