Total
397489 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-76884 | 1 Wireshark | 1 Wireshark | 2026-08-31 | N/A | 3.1 LOW |
| ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service | |||||
| CVE-2026-76883 | 1 Wireshark | 1 Wireshark | 2026-08-31 | N/A | 4.7 MEDIUM |
| Catapult DCT2000 file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service | |||||
| CVE-2026-76882 | 1 Wireshark | 1 Wireshark | 2026-08-31 | N/A | 4.7 MEDIUM |
| Bluetooth Attribute Protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service | |||||
| CVE-2026-76919 | 1 Wireshark | 1 Wireshark | 2026-08-31 | N/A | 5.3 MEDIUM |
| ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service | |||||
| CVE-2026-76918 | 1 Wireshark | 1 Wireshark | 2026-08-31 | N/A | 5.5 MEDIUM |
| SSH protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service | |||||
| CVE-2026-76917 | 1 Wireshark | 1 Wireshark | 2026-08-31 | N/A | 5.5 MEDIUM |
| Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service | |||||
| CVE-2026-76891 | 1 Wireshark | 1 Wireshark | 2026-08-31 | N/A | 3.1 LOW |
| Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service | |||||
| CVE-2026-76890 | 1 Wireshark | 1 Wireshark | 2026-08-31 | N/A | 3.1 LOW |
| Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service | |||||
| CVE-2026-76889 | 1 Wireshark | 1 Wireshark | 2026-08-31 | N/A | 4.7 MEDIUM |
| UMTS FP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service | |||||
| CVE-2026-70626 | 1 Nltk | 1 Nltk | 2026-08-31 | N/A | 6.2 MEDIUM |
| NLTK versions before 3.9.4 contain a symlink escape vulnerability in CorpusReader.open() that allows local attackers to read arbitrary files outside the corpus root. The vulnerability exists because path validation is lexical and does not account for symlink resolution, enabling attackers to place symlinks inside the corpus root to access files outside the intended boundary. | |||||
| CVE-2026-81727 | 1 Nltk | 1 Nltk | 2026-08-31 | N/A | 7.1 HIGH |
| NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloader.incr_download methods that allows attackers to overwrite files outside the install root through pre-existing hardlinks. Attackers with write access to a shared downloader directory can create hardlinks pointing to outside-root files that are then overwritten during normal package extraction, mutating files outside the intended install tree. | |||||
| CVE-2026-81726 | 1 Nltk | 1 Nltk | 2026-08-31 | N/A | 7.0 HIGH |
| NLTK through 3.10.3 contains a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement by using raw file operations on caller-controlled paths. Attackers can read or write files outside allowed sandbox roots through TransitionParser, AveragedPerceptron, PerceptronTagger, and maxent parameter APIs when pathsec is enabled. | |||||
| CVE-2026-81724 | 1 Nltk | 1 Nltk | 2026-08-31 | N/A | 5.3 MEDIUM |
| NLTK before 3.10.3 contains an uncontrolled recursion vulnerability in nltk.featstruct.FeatStructReader that allows unauthenticated attackers to cause a denial of service by supplying deeply nested feature-structure input. Attackers can craft trivial payloads with nested brackets that exceed Python's recursion limit and raise an unhandled RecursionError, crashing applications that parse user-supplied feature structures or feature grammars. | |||||
| CVE-2026-79676 | 1 Nltk | 1 Nltk | 2026-08-31 | N/A | 5.9 MEDIUM |
| NLTK versions before 3.10.3 contain a path traversal vulnerability in corpus readers that reopen root-derived paths using built-in open() instead of nltk.pathsec.open(), allowing symlinks to escape trusted roots. Attackers who stage symlinked corpus files under a trusted data root can disclose outside-root content through normal corpus reader methods like channels(), domains(), and synonyms(). | |||||
| CVE-2026-79674 | 1 Nltk | 1 Nltk | 2026-08-31 | N/A | 8.2 HIGH |
| NLTK versions before 3.10.3 contain a path sandbox bypass vulnerability in corpus-reader constructors that allows attackers to read files outside the intended data root. Attackers can supply arbitrary corpus root paths to LinThesaurusCorpusReader and PanLexLiteCorpusReader constructors to access filesystem content and SQLite databases outside the pathsec sandbox boundary. | |||||
| CVE-2026-79657 | 1 Nltk | 1 Nltk | 2026-08-31 | N/A | 9.8 CRITICAL |
| NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust entire module namespaces instead of specific safe callables. Attackers can craft malicious pickle payloads invoking dangerous in-namespace functions like ReppTokenizer._execute and numpy.f2py.crackfortran.myeval through pickle REDUCE to execute arbitrary commands during model or tokenizer artifact loading. | |||||
| CVE-2026-78682 | 1 Nltk | 1 Nltk | 2026-08-31 | N/A | 7.5 HIGH |
| NLTK before 3.10.3 contains a server-side request forgery vulnerability in nltk.pathsec.urlopen (and callers nltk.data.load, nltk.downloader.Downloader.index/download) when an HTTP proxy is configured. pathsec.urlopen validates the requested hostname locally, but proxy-handler inheritance disables the safe HTTP/HTTPS handlers so the actual fetch is performed by the proxy against a destination that is never re-validated. An attacker can supply a validated public URL that the proxy forwards to an internal loopback-only service, allowing disclosure of internal HTTP resources, loading of forged downloader indexes, and installation of attacker-chosen package content. | |||||
| CVE-2026-78683 | 1 Nltk | 1 Nltk | 2026-08-31 | N/A | 9.6 CRITICAL |
| NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization vulnerability in the TransitionParser.parse() method (nltk/parse/transitionparser.py). The method calls pickle_load() with the default restricted=False, routing deserialization through WarningUnpickler, which does not override find_class() and therefore permits arbitrary class resolution. When an application loads an attacker-crafted model file, embedded pickle gadget chains execute arbitrary Python code with the privileges of the user running the application. NLTK provides a RestrictedUnpickler for safe deserialization, but it is not used by production code paths. Fixed in 3.10.0. | |||||
| CVE-2026-58083 | 1 Freebsd | 1 Freebsd | 2026-08-31 | N/A | 8.4 HIGH |
| While the kernel was copying knotes during fork, a knote with a timer-based filter could fire and be enqueued on the kqueue's active list before the copy was complete. The copy routine did not account for this and could enqueue the new knote a second time, corrupting the active list. In addition, the copy routine did not hold the appropriate locks while reading knote state, allowing further races. An unprivileged local user can trigger a use-after-free in the kernel, potentially leading to privilege escalation. | |||||
| CVE-2026-58082 | 1 Freebsd | 1 Freebsd | 2026-08-31 | N/A | 9.8 CRITICAL |
| The ISO-2022 encoding module used a stack buffer sized to MB_LEN_MAX (6 bytes) for intermediate character output. Some ISO-2022 variants can require up to 10 bytes per character, in which case conversions can trigger a stack buffer overflow of up to four bytes. An application that uses iconv(3) to convert untrusted input to or from one of the affected encodings may be vulnerable to buffer overflows if it uses one of the affected encoding modules. | |||||
