[
News
|
Newsletters
|
Blogs
|
Lists
|
Media
|
Jobs
]
HoneyDB
[
vulnerabilities
|
tools
]
CISA Advisories
US-CERT
FullDisclosure
[NotCVE-2026-0019] game-music-emu through 0.6.5 VGM Command Interpreter Missing Operand Length Check Allows Heap Out-of-Bounds Read
[NotCVE-2026-0018] game-music-emu (libgme) through 0.6.5 Unbounded GYM Command Loop Allows Heap Out-of-Bounds Read
[NotCVE-2026-0017] game-music-emu (libgme) 0.6.5 and Earlier AY Loader NULL Pointer Dereference Allows Denial of Service
[NotCVE-2026-0016] game-music-emu VGM Command Interpreter Unvalidated 0xE0 PCM Seek Offset Allows Out-of-Bounds Read and Denial of Service
APPLE-SA-09-28-2026-3 macOS Sequoia 15.8.1
APPLE-SA-09-28-2026-2 macOS Tahoe 26.7.1
APPLE-SA-09-28-2026-1 iOS 26.7.1 and iPadOS 26.7.1
SEC Consult SA-20260923-0 :: Local Privilege Escalation in Honeywell IQ MultiAccess Update Service #CVE-2026-13742
[SYSS-2026-071]: GDCM (Grassroots DICOM) - Format String (CWE-134)
[SYSS-2026-070]: GDCM (Grassroots DICOM) - Integer Overflow (CWE-190)
US CERT Weekly
Open Source Security
CVE-2026-104380: Punk versions from 0.48 before 0.55 for Perl route Extended CONNECT requests to any GET route without an Origin check in ps_serve_one
Fwd: [Freeipmi-announce] FreeIPMI 1.6.20 Released
libexpat 2.9.0 fixes two vulnerabilities
Re: cloud computing provider disclosures
Re: cloud computing provider disclosures
CVE-2026-104714: Apache Struts: Shared message formatter exposes date and time values across concurrent requests
CVE-2026-104713: Apache Struts: Unbounded request body read in the REST plugin
CVE-2026-104712: Apache Struts: Disproportionate response size when rendering BigDecimal request parameters
CVE-2026-104711: Apache Struts: OGNL injection in the legacy RESTful action mapper
CVE-2026-19954: Net::Whois::Raw versions before 2.99044 for Perl ship a pwhois command-line tool that queries WHOIS for the wrong domain for unicode domain names
© 2026 RiskDiscovery | Sponsored by:
Deception Logic