{"cves":[{"id":"CVE-2025-60495","published":"2026-06-01T15:16:00","updated_at":"2026-06-06T09:47:33.461404+00:00","description":"\nA segmentation violation in the gf_media_get_color_info function\n(/media_tools/isom_tools.c) of GPAC Project/MP4Box before 26.02.0 allows\nattackers to cause a Denial of Service (DoS) via supplying a crafted data\nfile.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-60495","https://github.com/gpac/gpac/issues/3335","https://github.com/gpac/gpac/commit/9beed3c0a2f38505c745e5376234e7ed66e8e0b1","https://github.com/sigdevel/pocs/blob/main/res/gpac/MP4Box/66/README.md","https://infosec.exchange/@sigdevel/116659058320692913","http://www.openwall.com/lists/oss-security/2026/06/01/13"],"bugs":[""],"patches":{"gpac":[]},"tags":{},"packages":[{"name":"gpac","source":"https://ubuntu.com/security/cve?package=gpac","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gpac","debian":"https://tracker.debian.org/pkg/gpac","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-60486","published":"2026-06-01T15:16:00","updated_at":"2026-06-06T09:47:33.461404+00:00","description":"\nA heap use-after-free in the dasher_process function (/filters/dasher.c) of\nGPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of\nService (DoS) via supplying a crafted MPEG-2 file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-60486","https://github.com/gpac/gpac/issues/3314","https://github.com/gpac/gpac/commit/e6d01820d7bf3967d931fedb379ee5f209bc133b","https://github.com/sigdevel/pocs/blob/main/res/gpac/MP4Box/53/README.md","https://infosec.exchange/@sigdevel/116662544397024289","http://www.openwall.com/lists/oss-security/2026/06/01/12"],"bugs":[""],"patches":{"gpac":[]},"tags":{},"packages":[{"name":"gpac","source":"https://ubuntu.com/security/cve?package=gpac","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gpac","debian":"https://tracker.debian.org/pkg/gpac","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-60485","published":"2026-06-01T15:16:00","updated_at":"2026-06-06T09:47:33.461404+00:00","description":"\nA segmentation violation in the gf_isom_apple_set_tag_ex function\n(/isomedia/isom_write.c) of GPAC Project/MP4Box before 26.02.0 allows\nattackers to cause a Denial of Service (DoS) via supplying a crafted MP4\nfile.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-60485","https://github.com/gpac/gpac/issues/3323","https://github.com/gpac/gpac/commit/4860a1a6f128ccc9ae37b4b738d22029f9672457","https://github.com/sigdevel/pocs/blob/main/res/gpac/MP4Box/52/README.md","https://infosec.exchange/@sigdevel/116662498332150083","http://www.openwall.com/lists/oss-security/2026/06/01/11"],"bugs":[""],"patches":{"gpac":[]},"tags":{},"packages":[{"name":"gpac","source":"https://ubuntu.com/security/cve?package=gpac","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gpac","debian":"https://tracker.debian.org/pkg/gpac","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-60483","published":"2026-06-01T15:16:00","updated_at":"2026-06-06T09:47:33.461404+00:00","description":"\nA NULL pointer dereference in the gf_ac4_pres_b_4_back_channels_present\nfunction (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0\nallows attackers to cause a Denial of Service (DoS) via supplying a crafted\nAC4 file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-60483","https://github.com/gpac/gpac/issues/3302","https://github.com/gpac/gpac/commit/13eb5b76560aaf7813b865a2ad433258478e2695","https://github.com/sigdevel/pocs/blob/main/res/gpac/MP4Box/49/README.md","https://infosec.exchange/@sigdevel/116659111520602254","http://www.openwall.com/lists/oss-security/2026/06/01/9"],"bugs":[""],"patches":{"gpac":[]},"tags":{},"packages":[{"name":"gpac","source":"https://ubuntu.com/security/cve?package=gpac","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gpac","debian":"https://tracker.debian.org/pkg/gpac","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-60481","published":"2026-06-01T15:16:00","updated_at":"2026-06-06T09:47:33.461404+00:00","description":"\nA NULL pointer dereference in the gf_odf_ac4_cfg_dsi_v1 function\n(/odf/descriptors.c) of GPAC Project/MP4Box before 26.02.0 allows attackers\nto cause a Denial of Service (DoS) via supplying a crafted AC4 file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-60481","https://github.com/gpac/gpac/issues/3296","https://github.com/gpac/gpac/commit/e02d1fd24cdc26acb1b236ab38b3832cffcae21b","https://github.com/sigdevel/pocs/blob/main/res/gpac/MP4Box/45/README.md","https://infosec.exchange/@sigdevel/116659159345966316","http://www.openwall.com/lists/oss-security/2026/06/01/8"],"bugs":[""],"patches":{"gpac":[]},"tags":{},"packages":[{"name":"gpac","source":"https://ubuntu.com/security/cve?package=gpac","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gpac","debian":"https://tracker.debian.org/pkg/gpac","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-55664","published":"2026-06-01T15:16:00","updated_at":"2026-06-06T09:47:33.461404+00:00","description":"\nA heap buffer overflow in the m2tsdmx_send_packet function\n(filters/dmx_m2ts.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial\nof Service (DoS) via supplying a crafted MP4 file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-55664","https://github.com/gpac/gpac/issues/3310","https://github.com/gpac/gpac/commit/9bd6a72c9efc0513dfd33b87498afc7658dabd26","https://infosec.exchange/@sigdevel/116659245751279377","http://www.openwall.com/lists/oss-security/2026/06/01/10"],"bugs":[""],"patches":{"gpac":[]},"tags":{},"packages":[{"name":"gpac","source":"https://ubuntu.com/security/cve?package=gpac","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gpac","debian":"https://tracker.debian.org/pkg/gpac","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-10532","published":"2026-06-01T13:16:00","updated_at":"2026-06-06T09:47:52.519306+00:00","description":"\nDeserialization of untrusted data vulnerability in QOS.CH Sarl logback\nlogback-core (HardenedObjectInputStream (logback-core) modules) allows\nObject Injection, albeit heavily restricted.\nMore precisely, an attacker able to influence serialized data sent to\nSimpleSocketServer or SimpleSSLSocketServer can instantiate Proxy objects.\nAlthough deserialization is heavily restricted by HardenedObjectInputStream\nand no\npractical way to achieve remote code execution or significant privilege\nescalation has been identified, this issue constitutes a bypass of the\nintended security restrictions.\nThis issue affects logback: through 1.5.33 inclusive.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:P/RE:M/U:Green","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"}},"baseScore":2.9,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-10532","https://logback.qos.ch/news.html#1.5.34"],"bugs":[""],"patches":{"logback":[]},"tags":{},"packages":[{"name":"logback","source":"https://ubuntu.com/security/cve?package=logback","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=logback","debian":"https://tracker.debian.org/pkg/logback","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-49270","published":"2026-06-01T09:16:00","updated_at":"2026-06-06T09:48:14.041747+00:00","description":"\nExposure of Sensitive Information Through Metadata vulnerability in Apache\nActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All.\nBrokers that are configured with a network connector with syncDurableSubs\nset to true, are vulnerable to an unauthenticated attacker who can receive\na list of all durable topic subscriptions in the broker, including client\nidentifiers, subscription names, topic destinations, and JMS selector\nexpressions, by sending a BrokerInfo command. The broker incorrectly\nresponds without first ensuring the connection is authenticated.\nThis issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before\n6.2.6; Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6; Apache\nActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6.\nUsers are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes\nthe issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-49270","https://www.openwall.com/lists/oss-security/2026/05/31/22","https://lists.apache.org/thread/k3233c1x506z3w7x4z0dqvd86d4v2fr2","http://www.openwall.com/lists/oss-security/2026/05/31/22"],"bugs":[""],"patches":{"activemq":[]},"tags":{},"packages":[{"name":"activemq","source":"https://ubuntu.com/security/cve?package=activemq","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=activemq","debian":"https://tracker.debian.org/pkg/activemq","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-49157","published":"2026-06-01T09:16:00","updated_at":"2026-06-06T09:48:14.041747+00:00","description":"\nIncorrect Default Permissions vulnerability in Apache ActiveMQ.\nThis issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6.\nThe default Jolokia authorization settings granted non-admin\n(low-privilege) web-login accounts access to Jolokia operations which\nallowed executing broker management operations meant for admins such as\naddQueue and removeQueue.\nUsers are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes\nthe issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-49157","https://www.openwall.com/lists/oss-security/2026/05/31/21","https://lists.apache.org/thread/rrcsf6s90hj4tdh89nvkko75q5505rj8","http://www.openwall.com/lists/oss-security/2026/05/31/21"],"bugs":[""],"patches":{"activemq":[]},"tags":{},"packages":[{"name":"activemq","source":"https://ubuntu.com/security/cve?package=activemq","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=activemq","debian":"https://tracker.debian.org/pkg/activemq","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-48827","published":"2026-06-01T09:16:00","updated_at":"2026-06-06T05:13:43.541481+00:00","description":"\nPath traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of\npath validation in git-upload-pack, git-receive-pack, and other git\noperations allows users authenticated over SSH access to git repositories\noutside the configured git server root directory.\nApplications are affected if they use org.apache.sshd:sshd-git.\nApplications not using sshd-git are not affected.\nUsers are advised to upgrade affected applications to Apche MINA SSHD\n2.18.0, which fixes the issue.\nThe issue also is present in the pre-release milestones 3.0.0-M1 to\n3.0.0-M3 for a new upcoming new major version 3.0.0. Again, applications\nare affected only if they use sshd-git. Upgrade affected applications to\n3.0.0-M4.\nWe would like to point out that a professional git server should not rely\nsolely on file system layout and permissions, but should implement\nadditional security controls to govern access to git repositories and\noperations allowed on particular git repositories.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":7.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-48827","https://www.openwall.com/lists/oss-security/2026/05/30/1"],"bugs":[""],"patches":{"mina":[],"mina2":[]},"tags":{},"packages":[{"name":"mina","source":"https://ubuntu.com/security/cve?package=mina","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mina","debian":"https://tracker.debian.org/pkg/mina","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mina2","source":"https://ubuntu.com/security/cve?package=mina2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mina2","debian":"https://tracker.debian.org/pkg/mina2","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-46605","published":"2026-06-01T09:16:00","updated_at":"2026-06-06T09:48:04.391188+00:00","description":"\nIncomplete authorization by Apache ActiveMQ server before versions v6.2.6\nand v5.19.7 allows authenticated connections to remove existing\ndestinations with proper permissions.\nThis issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before\n6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6; Apache\nActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6.\nUsers are recommended to upgrade to version v6.2.6 or v5.19.7, which fixes\nthe issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-46605","https://www.openwall.com/lists/oss-security/2026/05/31/20","https://lists.apache.org/thread/l4lxgr2s73g9pb218f180psfyskf8ldm","http://www.openwall.com/lists/oss-security/2026/05/31/20"],"bugs":[""],"patches":{"activemq":[]},"tags":{},"packages":[{"name":"activemq","source":"https://ubuntu.com/security/cve?package=activemq","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=activemq","debian":"https://tracker.debian.org/pkg/activemq","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45505","published":"2026-06-01T09:16:00","updated_at":"2026-06-06T09:48:04.391188+00:00","description":"\nImproper Input Validation, Improper Control of Generation of Code ('Code\nInjection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All,\nApache ActiveMQ.\nNon-parenthesized discovery wrappers such as `masterslave:vm://...,...`\nand `static:vm://...` incorrectly pass validation allowing bypass of fix\nin CVE-2026-34197.\nOriginal description from CVE-2026-34197.\nApache ActiveMQ exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the\nweb console. The default Jolokia access policy permits exec operations on\nall ActiveMQ MBeans (org.apache.activemq:*), including\nBrokerService.addNetworkConnector(String) and\nBrokerService.addConnector(String). An authenticated attacker can invoke\nthese operations with a crafted discovery UR that triggers the VM\ntransport's brokerConfig parameter to load a remote Spring XML application\ncontext using ResourceXmlApplicationContext. Because Spring's\nResourceXmlApplicationContext instantiates all singleton beans before the\nBrokerService validates the configuration, arbitrary code execution occurs\non the broker's JVM through bean factory methods such as Runtime.exec().\nThis issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before\n6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6; Apache\nActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6.\nUsers are recommended to upgrade to version 5.19.7 or 6.2.6, which fixes\nthe issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45505","https://www.openwall.com/lists/oss-security/2026/05/31/19","https://lists.apache.org/thread/7n97nddyw96w6ykldjv1h40jx86xdo0w","https://nvd.nist.gov/vuln/detail/CVE-2026-34197"],"bugs":[""],"patches":{"activemq":[]},"tags":{},"packages":[{"name":"activemq","source":"https://ubuntu.com/security/cve?package=activemq","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=activemq","debian":"https://tracker.debian.org/pkg/activemq","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-44825","published":"2026-06-01T09:16:00","updated_at":"2026-06-06T05:13:22.152920+00:00","description":"\nHardcoded credentials in the Basic Authentication setup tool (bin/solr auth\nenable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a\nremote attacker to gain full administrative access to the cluster via\npublicly known default credentials installed silently alongside the\nuser-specified account.\nAs an immediate workaround without upgrading, delete the template users\n(superadmin, admin, search, index) from security.json or change their\npasswords.\nThe future, not yet released, versions 9.11.0 and 10.1.0 will not be\nvulnerable, and it will be enough to upgrade to solve the issue.\nNot affected:\n * Clusters where bin/solr auth enable was not used to bootstrap\nBasicAuth\n * Clusters where template users have been assigned strong passwords\nafter bootstrap","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-44825","https://issues.apache.org/jira/browse/SOLR-18233"],"bugs":[""],"patches":{"lucene-solr":[]},"tags":{},"packages":[{"name":"lucene-solr","source":"https://ubuntu.com/security/cve?package=lucene-solr","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lucene-solr","debian":"https://tracker.debian.org/pkg/lucene-solr","statuses":[{"release_codename":"bionic","status":"not-affected","description":"3.6.2+dfsg-18~18.04.1~esm2","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.6.2+dfsg-22","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.6.2+dfsg-24","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"3.6.2+dfsg-26","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"3.6.2+dfsg-26","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"3.6.2+dfsg-27","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"3.6.2+dfsg-2ubuntu0.1~esm4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"3.6.2+dfsg-8ubuntu0.1+esm1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"debian: Only affects 9.4.0 and later","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-42588","published":"2026-06-01T09:16:00","updated_at":"2026-06-06T09:48:04.391188+00:00","description":"\nImproper Input Validation, Improper Control of Generation of Code ('Code\nInjection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All,\nApache ActiveMQ.\nApache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at\n/api/jolokia/ on the web console. The default Jolokia access policy permits\nexec operations on all ActiveMQ MBeans (org.apache.activemq:*), including\nBrokerService.addNetworkConnector(String).\nAn authenticated attacker can invoke these operations with a crafted\ndiscovery URI that triggers the VM transport's brokerConfig parameter using\nthe \"masterslave:// \" URL which can allow loading a Spring XML application\ncontext using ResourceXmlApplicationContext.\nBecause Spring's ResourceXmlApplicationContext instantiates all singleton\nbeans before the BrokerService validates the configuration, arbitrary code\nexecution occurs on the broker's JVM through bean factory methods such as\nRuntime.exec().\nThis issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before\n6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6; Apache\nActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6.\nUsers are recommended to upgrade to version 5.19.7 or 6.2.6, which fixes\nthe issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":8.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-42588","https://www.openwall.com/lists/oss-security/2026/05/31/18","https://lists.apache.org/thread/ns0zktfo16s9ql2mmtqtlb6p6xcs45xm","http://www.openwall.com/lists/oss-security/2026/05/31/18"],"bugs":[""],"patches":{"activemq":[]},"tags":{},"packages":[{"name":"activemq","source":"https://ubuntu.com/security/cve?package=activemq","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=activemq","debian":"https://tracker.debian.org/pkg/activemq","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-42253","published":"2026-06-01T09:16:00","updated_at":"2026-06-06T09:47:52.519306+00:00","description":"\nImproper Neutralization of Input During Web Page Generation ('Cross-site\nScripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web.\nThe MessageServlet in the ActiveMQ web console API copies every JMS message\nproperty into an HTTP response header without any validation. This can\nallow overwriting and injecting security headers by setting them on JMS\nmessages that are returned by the servlet.\nThis issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6;\nApache ActiveMQ Web: before 5.19.7, from 6.0.0 before 6.2.6.\nUsers are recommended to upgrade to version 5.19.7 or 6.2.6, which fixes\nthe issue. The MessageServlet has now been deprecated and disabled by\ndefault.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-42253","https://www.openwall.com/lists/oss-security/2026/05/31/17","https://lists.apache.org/thread/j9vmlc410ht5f28fc98gx75jcbq62j00","http://www.openwall.com/lists/oss-security/2026/05/31/17"],"bugs":[""],"patches":{"activemq":[]},"tags":{},"packages":[{"name":"activemq","source":"https://ubuntu.com/security/cve?package=activemq","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=activemq","debian":"https://tracker.debian.org/pkg/activemq","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-10233","published":"2026-06-01T08:16:00","updated_at":"2026-06-06T09:47:44.123367+00:00","description":"\nA security vulnerability has been detected in Assimp up to 6.0.4. Affected\nby this issue is the function HL1MDLLoader::read_sequence_infos of the file\nHL1MDLLoader.cpp of the component Half-Life 1 MDL Loader. The manipulation\nof the argument aiString leads to out-of-bounds read. The attack needs to\nbe performed locally. The exploit has been disclosed publicly and may be\nused. The project tagged the reported issue as bug.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":3.3,"baseSeverity":"LOW"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":1.9,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-10233","https://github.com/assimp/assimp/issues/6619","https://github.com/assimp/assimp/","https://github.com/user-attachments/files/27228962/poc.zip","https://vuldb.com/cve/CVE-2026-10233","https://vuldb.com/submit/821196","https://vuldb.com/vuln/367512","https://vuldb.com/vuln/367512/cti"],"bugs":[""],"patches":{"assimp":[]},"tags":{},"packages":[{"name":"assimp","source":"https://ubuntu.com/security/cve?package=assimp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=assimp","debian":"https://tracker.debian.org/pkg/assimp","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-10232","published":"2026-06-01T08:16:00","updated_at":"2026-06-06T09:47:44.123367+00:00","description":"\nA weakness has been identified in Assimp up to 6.0.4. Affected by this\nvulnerability is the function aiNode::~aiNode of the file scene.cpp of the\ncomponent ASE File Parser. Executing a manipulation can lead to use after\nfree. The attack needs to be launched locally. The exploit has been made\navailable to the public and could be used for attacks. The project tagged\nthe reported issue as bug.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":1.9,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-10232","https://github.com/assimp/assimp/issues/6617","https://github.com/assimp/assimp/","https://github.com/user-attachments/files/27200601/poc.zip","https://vuldb.com/cve/CVE-2026-10232","https://vuldb.com/submit/821192","https://vuldb.com/vuln/367511","https://vuldb.com/vuln/367511/cti"],"bugs":[""],"patches":{"assimp":[]},"tags":{},"packages":[{"name":"assimp","source":"https://ubuntu.com/security/cve?package=assimp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=assimp","debian":"https://tracker.debian.org/pkg/assimp","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-10231","published":"2026-06-01T08:16:00","updated_at":"2026-06-06T09:47:44.123367+00:00","description":"\nA security flaw has been discovered in Assimp up to 6.0.4. Affected is the\nfunction HL1MDLLoader::extract_anim_value of the file HL1MDLLoader.cpp of\nthe component Half-Life 1 MDL Loader. Performing a manipulation of the\nargument num.total results in heap-based buffer overflow. The attack must\nbe initiated from a local position. The exploit has been released to the\npublic and may be used for attacks. The project tagged the reported issue\nas bug.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":1.9,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-10231","https://github.com/assimp/assimp/issues/6616","https://github.com/assimp/assimp/","https://github.com/user-attachments/files/27195744/poc.zip","https://vuldb.com/cve/CVE-2026-10231","https://vuldb.com/submit/821191","https://vuldb.com/vuln/367510","https://vuldb.com/vuln/367510/cti"],"bugs":[""],"patches":{"assimp":[]},"tags":{},"packages":[{"name":"assimp","source":"https://ubuntu.com/security/cve?package=assimp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=assimp","debian":"https://tracker.debian.org/pkg/assimp","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-10230","published":"2026-06-01T08:16:00","updated_at":"2026-06-06T09:47:44.123367+00:00","description":"\nA vulnerability was identified in Assimp up to 6.0.4. This impacts the\nfunction Assimp::MDL::HalfLife::HL1MDLLoader::read_animations of the file\nHL1MDLLoader.cpp of the component Half-Life 1 MDL Loader. Such manipulation\nleads to heap-based buffer overflow. The attack must be carried out\nlocally. The exploit is publicly available and might be used. The project\ntagged the reported issue as bug.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":1.9,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-10230","https://github.com/assimp/assimp/issues/6615","https://github.com/assimp/assimp/","https://vuldb.com/cve/CVE-2026-10230","https://vuldb.com/submit/821190","https://vuldb.com/vuln/367509","https://vuldb.com/vuln/367509/cti"],"bugs":[""],"patches":{"assimp":[]},"tags":{},"packages":[{"name":"assimp","source":"https://ubuntu.com/security/cve?package=assimp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=assimp","debian":"https://tracker.debian.org/pkg/assimp","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-10229","published":"2026-06-01T08:16:00","updated_at":"2026-06-06T09:47:44.123367+00:00","description":"\nA vulnerability was determined in Assimp up to 6.0.4. This affects the\nfunction HL1MDLLoader::read_meshes of the file HL1MDLLoader.cpp of the\ncomponent Half-Life 1 MDL Loader. This manipulation causes heap-based\nbuffer overflow. The attack is restricted to local execution. The exploit\nhas been publicly disclosed and may be utilized. The project tagged the\nreported issue as bug.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":1.9,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-10229","https://github.com/assimp/assimp/issues/6614","https://github.com/assimp/assimp/","https://github.com/user-attachments/files/27194364/poc.zip","https://vuldb.com/cve/CVE-2026-10229","https://vuldb.com/submit/821189","https://vuldb.com/vuln/367508","https://vuldb.com/vuln/367508/cti"],"bugs":[""],"patches":{"assimp":[]},"tags":{},"packages":[{"name":"assimp","source":"https://ubuntu.com/security/cve?package=assimp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=assimp","debian":"https://tracker.debian.org/pkg/assimp","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":10660,"limit":20,"total_results":79316}