{"cves":[{"id":"CVE-2026-14789","published":"2026-07-06T00:00:00","updated_at":"2026-07-06T18:03:49.776682+00:00","description":"\nA vulnerability was detected in radareorg radare2 up to 6.1.6. Affected by\nthis issue is some unknown functionality of the file\nlibr/bin/format/mdmp/mdmp.c of the component Memory64ListStream Parser.\nPerforming a manipulation results in stack-based buffer overflow. The\nattack requires a local approach. The exploit is now public and may be\nused. The patch is named 175d4addb68981331c85b10681c2161c38fb5762. It is\nsuggested to install a patch to address this issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":3.3,"baseSeverity":"LOW"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":1.9,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-14789","https://github.com/radareorg/radare2/issues/26051","https://github.com/radareorg/radare2/commit/175d4addb68981331c85b10681c2161c38fb5762 (6.1.8)","https://github.com/mengzhisuoliu/radare2/commit/175d4addb68981331c85b10681c2161c38fb5762","https://github.com/radareorg/radare2/","https://vuldb.com/cve/CVE-2026-14789","https://vuldb.com/submit/850389","https://vuldb.com/vuln/376378","https://vuldb.com/vuln/376378/cti"],"bugs":[""],"patches":{"radare2":[]},"tags":{},"packages":[{"name":"radare2","source":"https://ubuntu.com/security/cve?package=radare2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=radare2","debian":"https://tracker.debian.org/pkg/radare2","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-14788","published":"2026-07-06T00:00:00","updated_at":"2026-07-06T18:03:49.776682+00:00","description":"\nA security vulnerability has been detected in radareorg radare2 up to\n6.1.6. Affected by this vulnerability is the function r_core_bin_load of\nthe file libr/core/cfile.c. Such manipulation leads to use after free. The\nattack needs to be performed locally. The exploit has been disclosed\npublicly and may be used. The name of the patch is\n635ab1eeb30340c26076722a90cb91fb2272130b. Applying a patch is advised to\nresolve this issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":3.3,"baseSeverity":"LOW"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":1.9,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-14788","https://github.com/radareorg/radare2/issues/26049","https://github.com/radareorg/radare2/commit/635ab1eeb30340c26076722a90cb91fb2272130b (6.1.8)","https://github.com/oldzhu/radare2/commit/635ab1eeb30340c26076722a90cb91fb2272130b","https://github.com/radareorg/radare2/","https://vuldb.com/cve/CVE-2026-14788","https://vuldb.com/submit/850388","https://vuldb.com/vuln/376377","https://vuldb.com/vuln/376377/cti"],"bugs":[""],"patches":{"radare2":[]},"tags":{},"packages":[{"name":"radare2","source":"https://ubuntu.com/security/cve?package=radare2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=radare2","debian":"https://tracker.debian.org/pkg/radare2","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-14787","published":"2026-07-06T00:00:00","updated_at":"2026-07-06T18:03:49.776682+00:00","description":"\nA weakness has been identified in radareorg radare2 up to 6.1.6. Affected\nis the function cmd_print in the library libr/core/cmd_print.inc of the\ncomponent pb Print Command Handler. This manipulation causes integer\noverflow. The attack needs to be launched locally. The exploit has been\nmade available to the public and could be used for attacks. Patch name:\n2b6265476c75567006b0fcbb749f4ae7b189c5df. It is recommended to apply a\npatch to fix this issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":3.3,"baseSeverity":"LOW"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":1.9,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-14787","https://github.com/radareorg/radare2/issues/26048","https://github.com/radareorg/radare2/commit/2b6265476c75567006b0fcbb749f4ae7b189c5df (6.1.8)","https://github.com/phix33/radare2/commit/2b6265476c75567006b0fcbb749f4ae7b189c5df","https://github.com/radareorg/radare2/","https://vuldb.com/cve/CVE-2026-14787","https://vuldb.com/submit/850387","https://vuldb.com/vuln/376376","https://vuldb.com/vuln/376376/cti"],"bugs":[""],"patches":{"radare2":[]},"tags":{},"packages":[{"name":"radare2","source":"https://ubuntu.com/security/cve?package=radare2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=radare2","debian":"https://tracker.debian.org/pkg/radare2","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-14786","published":"2026-07-06T00:00:00","updated_at":"2026-07-06T18:03:49.776682+00:00","description":"\nA security flaw has been discovered in radareorg radare2 up to 6.1.6. This\nimpacts the function r_str_word_get0set of the file libr/util/str.c. The\nmanipulation results in integer overflow. The attack must be initiated from\na local position. The exploit has been released to the public and may be\nused for attacks. The patch is identified as\n11ac224c0eb8d57830fccc99e1c1cd8e5d958813. It is best practice to apply a\npatch to resolve this issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":3.3,"baseSeverity":"LOW"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":1.9,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-14786","https://github.com/radareorg/radare2/issues/26047","https://github.com/radareorg/radare2/commit/11ac224c0eb8d57830fccc99e1c1cd8e5d958813 (6.1.8)","https://github.com/radareorg/radare2/","https://github.com/radareorg/radare2/commit/11ac224c0eb8d57830fccc99e1c1cd8e5d958813","https://vuldb.com/cve/CVE-2026-14786","https://vuldb.com/submit/850386","https://vuldb.com/vuln/376375","https://vuldb.com/vuln/376375/cti"],"bugs":[""],"patches":{"radare2":[]},"tags":{},"packages":[{"name":"radare2","source":"https://ubuntu.com/security/cve?package=radare2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=radare2","debian":"https://tracker.debian.org/pkg/radare2","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-13708","published":"2026-07-06T00:00:00","updated_at":"2026-07-09T14:44:41.601638+00:00","description":"\nImager::File::JPEG versions before 1.003 for Perl leak heap memory when\nreading a JPEG with repeated APP13 markers in i_readjpeg_wiol.\ni_readjpeg_wiol walks the marker list libjpeg returns and, for each APP13\nmarker, allocates a new buffer with *iptc_itext = mymalloc(...) and\noverwrites the previous pointer without freeing it. Only the final payload\nis later turned into a Perl scalar and freed, so a JPEG with N such markers\nleaks the first N-1 payloads on every read.\nIn a long-lived process, such as an upload or thumbnailing service,\nrepeated reads accumulate these leaks and exhaust available memory, a\ndenial of service.\nThe same handler ships bundled in the Imager distribution, where versions\nbefore 1.032 are affected and the fix ships in 1.032.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-13708","https://lists.security.metacpan.org/cve-announce/msg/41572486/"],"bugs":[""],"patches":{"libimager-perl":[]},"tags":{},"packages":[{"name":"libimager-perl","source":"https://ubuntu.com/security/cve?package=libimager-perl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libimager-perl","debian":"https://tracker.debian.org/pkg/libimager-perl","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-13705","published":"2026-07-06T00:00:00","updated_at":"2026-07-09T14:44:17.158544+00:00","description":"\nImager versions before 1.032 for Perl have a heap out-of-bounds read in the\nbundled Imager::File::SGI reader via a 16-bit RLE literal run in\nread_rgb_16_rle.\nread_rgb_16_rle guards each literal run with if (count > data_left), but\ncount is a pixel count while every 16-bit sample consumes two bytes. The\ncopy loop reads inp[0] * 256 + inp[1] and advances two bytes per pixel, so\na run with data_left / 2 < count <= data_left passes the guard yet consumes\n2 * count bytes and reads past the end of the buffer. The 8-bit path is\nunaffected because there one pixel is one byte.\nReading a crafted SGI image through Imager->read triggers the over-read\nbefore the parser rejects the malformed image, which can crash the process.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-13705","https://lists.security.metacpan.org/cve-announce/msg/41572386/"],"bugs":[""],"patches":{"libimager-perl":[]},"tags":{},"packages":[{"name":"libimager-perl","source":"https://ubuntu.com/security/cve?package=libimager-perl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libimager-perl","debian":"https://tracker.debian.org/pkg/libimager-perl","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-12893","published":"2026-07-06T00:00:00","updated_at":"2026-07-06T18:03:49.776682+00:00","description":"\n[gstreamer1-libav: gstreamer1-libav: NULL pointer dereference in\ngstavdemux.c error handler]","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-12893","https://bugzilla.redhat.com/show_bug.cgi?id=2491322 (not yet public)","https://gitlab.freedesktop.org/gstreamer/gstreamer-security/-/merge_requests/78"],"bugs":[""],"patches":{"gst-libav1.0":[]},"tags":{},"packages":[{"name":"gst-libav1.0","source":"https://ubuntu.com/security/cve?package=gst-libav1.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gst-libav1.0","debian":"https://tracker.debian.org/pkg/gst-libav1.0","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-14761","published":"2026-07-05T16:19:00","updated_at":"2026-07-09T14:45:11.045637+00:00","description":"\nA security vulnerability has been detected in radareorg radare2 up to\n6.1.6. The affected element is the function r_str_ndup/r_str_append of the\nfile libr/util/str.c. The manipulation leads to integer overflow. An attack\nhas to be approached locally. The exploit has been disclosed publicly and\nmay be used. The identifier of the patch is\na20a56917ae85d732e683f8d9078bdcfee92446c. Applying a patch is the\nrecommended action to fix this issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":3.3,"baseSeverity":"LOW"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":1.9,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-14761","https://github.com/radareorg/radare2/issues/26045","https://github.com/radareorg/radare2/commit/a20a56917ae85d732e683f8d9078bdcfee92446c (6.1.8)","https://github.com/radareorg/radare2/","https://github.com/radareorg/radare2/commit/a20a56917ae85d732e683f8d9078bdcfee92446c","https://vuldb.com/cve/CVE-2026-14761","https://vuldb.com/submit/850385","https://vuldb.com/vuln/376350","https://vuldb.com/vuln/376350/cti"],"bugs":[""],"patches":{"radare2":[]},"tags":{},"packages":[{"name":"radare2","source":"https://ubuntu.com/security/cve?package=radare2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=radare2","debian":"https://tracker.debian.org/pkg/radare2","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-14760","published":"2026-07-05T16:19:00","updated_at":"2026-07-09T14:45:11.045637+00:00","description":"\nA weakness has been identified in radareorg radare2 up to 6.1.6. Impacted\nis the function r_core_seek_arch_bits of the file libr/core/disasm.c of the\ncomponent regprofile Handler. Executing a manipulation can lead to use\nafter free. The attack requires local access. The exploit has been made\navailable to the public and could be used for attacks. This patch is called\n8b25c773785d85cb0103410a0905089d286921c2. It is advisable to implement a\npatch to correct this issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":3.3,"baseSeverity":"LOW"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":1.9,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-14760","https://github.com/radareorg/radare2/issues/26044","https://github.com/radareorg/radare2/commit/8b25c773785d85cb0103410a0905089d286921c2 (6.1.8)","https://github.com/radareorg/radare2/","https://github.com/radareorg/radare2/commit/8b25c773785d85cb0103410a0905089d286921c2","https://vuldb.com/cve/CVE-2026-14760","https://vuldb.com/submit/850384","https://vuldb.com/vuln/376349","https://vuldb.com/vuln/376349/cti"],"bugs":[""],"patches":{"radare2":[]},"tags":{},"packages":[{"name":"radare2","source":"https://ubuntu.com/security/cve?package=radare2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=radare2","debian":"https://tracker.debian.org/pkg/radare2","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-14759","published":"2026-07-05T16:19:00","updated_at":"2026-07-09T14:45:11.045637+00:00","description":"\nA security flaw has been discovered in radareorg radare2 up to 6.1.6. This\nissue affects the function r_bin_java_inner_classes_attr_calc_size of the\nfile shlr/java/class.c of the component RBinJava Line Number Table Parser.\nPerforming a manipulation results in heap-based buffer overflow. The attack\nrequires a local approach. The exploit has been released to the public and\nmay be used for attacks. The patch is named\ncd62d15a6cbecdc67fd03f3ebdbbbeb741d18f87. To fix this issue, it is\nrecommended to deploy a patch.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":3.3,"baseSeverity":"LOW"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":1.9,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-14759","https://github.com/radareorg/radare2/issues/26043","https://github.com/radareorg/radare2/commit/cd62d15a6cbecdc67fd03f3ebdbbbeb741d18f87 (6.1.8)","https://github.com/radareorg/radare2/","https://github.com/radareorg/radare2/commit/cd62d15a6cbecdc67fd03f3ebdbbbeb741d18f87","https://vuldb.com/cve/CVE-2026-14759","https://vuldb.com/submit/850383","https://vuldb.com/vuln/376348","https://vuldb.com/vuln/376348/cti"],"bugs":[""],"patches":{"radare2":[]},"tags":{},"packages":[{"name":"radare2","source":"https://ubuntu.com/security/cve?package=radare2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=radare2","debian":"https://tracker.debian.org/pkg/radare2","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-14758","published":"2026-07-05T15:16:00","updated_at":"2026-07-09T14:44:17.158544+00:00","description":"\nA vulnerability was identified in radareorg radare2 up to 6.1.6. This\nvulnerability affects the function cmd_anal_opcode of the file\nlibr/core/cmd_anal.inc.c of the component hexpairs Parser. Such\nmanipulation leads to integer overflow. The attack needs to be performed\nlocally. The exploit is publicly available and might be used. The name of\nthe patch is 84e773986e7e5bb30453a9384f498ec0ccc9d0a9. A patch should be\napplied to remediate this issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":3.3,"baseSeverity":"LOW"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":1.9,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-14758","https://github.com/radareorg/radare2/issues/26042","https://github.com/radareorg/radare2/commit/84e773986e7e5bb30453a9384f498ec0ccc9d0a9 (6.1.8)","https://github.com/radareorg/radare2/","https://github.com/radareorg/radare2/commit/84e773986e7e5bb30453a9384f498ec0ccc9d0a9","https://vuldb.com/cve/CVE-2026-14758","https://vuldb.com/submit/850382","https://vuldb.com/vuln/376347","https://vuldb.com/vuln/376347/cti"],"bugs":[""],"patches":{"radare2":[]},"tags":{},"packages":[{"name":"radare2","source":"https://ubuntu.com/security/cve?package=radare2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=radare2","debian":"https://tracker.debian.org/pkg/radare2","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-14757","published":"2026-07-05T15:16:00","updated_at":"2026-07-09T14:44:41.601638+00:00","description":"\nA vulnerability was determined in radareorg radare2 up to 6.1.6. This\naffects the function core_anal_bytes of the file libr/core/cmd_anal.inc.\nThis manipulation causes integer overflow. The attack needs to be launched\nlocally. The exploit has been publicly disclosed and may be utilized. It is\nsuggested to install a patch to address this issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":1.9,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-14757","https://github.com/radareorg/radare2/issues/26041"],"bugs":[""],"patches":{"radare2":[]},"tags":{},"packages":[{"name":"radare2","source":"https://ubuntu.com/security/cve?package=radare2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=radare2","debian":"https://tracker.debian.org/pkg/radare2","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-14570","published":"2026-07-05T02:17:00","updated_at":"2026-07-09T14:45:11.045637+00:00","description":"\nCrypt::DSA versions before 1.22 for Perl draw the DSA signing nonce and\nprivate key from a biased random generator, leading to private-key\nrecovery.\n\"Crypt::DSA::Util::makerandom forces the high bit of every value it returns\nto obtain an exactly N-bit integer for prime search. The signing nonce and\nthe private key are drawn from makerandom. Because the high bit is always\nset, the result is not uniform: its top bit is fixed, producing insecure\nvalues.\"\nAn attacker who collects a modest number of signatures under an affected\nkey, together with the public key, can recover the private key with a\nlattice attack.\nKeys used to sign with an affected version should be considered compromised\nand new keys should be generated.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-14570","https://lists.security.metacpan.org/cve-announce/msg/41542402/","https://metacpan.org/release/TIMLEGGE/Crypt-DSA-1.21/source/lib/Crypt/DSA/Util.pm#L56","https://metacpan.org/release/TIMLEGGE/Crypt-DSA-1.22/changes","https://metacpan.org/release/TIMLEGGE/Crypt-DSA-1.22/diff/TIMLEGGE/Crypt-DSA-1.21#lib/Crypt/DSA/Util.pm","http://www.openwall.com/lists/oss-security/2026/07/05/1"],"bugs":[""],"patches":{"libcrypt-dsa-perl":[]},"tags":{},"packages":[{"name":"libcrypt-dsa-perl","source":"https://ubuntu.com/security/cve?package=libcrypt-dsa-perl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libcrypt-dsa-perl","debian":"https://tracker.debian.org/pkg/libcrypt-dsa-perl","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-14686","published":"2026-07-05T01:21:00","updated_at":"2026-08-07T13:59:01.659303+00:00","description":"\nA vulnerability was found in HdrHistogram up to 2.2.2. This issue affects\nthe function org.HdrHistogram.DoubleHistogram.recordValue of the file\nsrc/main/java/org/HdrHistogram/DoubleHistogram.java of the component Range\nCheck. Performing a manipulation results in incorrect comparison. The\nattack is only possible with local access. The exploit has been made public\nand could be used. The presence of this vulnerability remains uncertain at\nthis time. This issue is disputed due to the potential lack of crossing of\nsecurity boundaries and the pre-requisites for a successful attack.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":3.3,"baseSeverity":"LOW"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":1.9,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-14686","https://github.com/HdrHistogram/HdrHistogram/issues/222","https://github.com/HdrHistogram/HdrHistogram/","https://vuldb.com/cve/CVE-2026-14686","https://vuldb.com/submit/846762","https://vuldb.com/vuln/376282","https://vuldb.com/vuln/376282/cti"],"bugs":[""],"patches":{"hdrhistogram":[]},"tags":{},"packages":[{"name":"hdrhistogram","source":"https://ubuntu.com/security/cve?package=hdrhistogram","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=hdrhistogram","debian":"https://tracker.debian.org/pkg/hdrhistogram","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-14685","published":"2026-07-05T00:17:00","updated_at":"2026-08-07T13:59:06.663895+00:00","description":"\nA vulnerability has been found in HdrHistogram up to 2.2.2. This\nvulnerability affects the function recordValueWithCount of the file\nsrc/main/java/org/HdrHistogram/AbstractHistogram.java of the component\nAbstractHistogram. Such manipulation of the argument Count leads to state\nissue. The attack can only be performed from a local environment. The\nexploit has been disclosed to the public and may be used. The existence of\nthis vulnerability is still disputed at present. This issue is disputed due\nto the potential lack of crossing of security boundaries and the\npre-requisites for a successful attack.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":3.3,"baseSeverity":"LOW"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":1.9,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-14685","https://github.com/HdrHistogram/HdrHistogram/issues/221","https://github.com/HdrHistogram/HdrHistogram/","https://vuldb.com/cve/CVE-2026-14685","https://vuldb.com/submit/846761","https://vuldb.com/vuln/376281","https://vuldb.com/vuln/376281/cti"],"bugs":[""],"patches":{"hdrhistogram":[]},"tags":{},"packages":[{"name":"hdrhistogram","source":"https://ubuntu.com/security/cve?package=hdrhistogram","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=hdrhistogram","debian":"https://tracker.debian.org/pkg/hdrhistogram","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-14684","published":"2026-07-05T00:17:00","updated_at":"2026-08-07T13:58:56.941283+00:00","description":"\nA flaw has been found in HdrHistogram up to 2.2.2. This affects the\nfunction org.HdrHistogram.AbstractHistogram.decodeFromByteBuffer of the\nfile src/main/java/org/HdrHistogram/AbstractHistogram.java. This\nmanipulation of the argument numberOfSignificantValueDigits causes\nuncontrolled memory allocation. The attack can only be executed locally.\nThe exploit has been published and may be used. The actual existence of\nthis vulnerability is currently in question. This issue is disputed due to\nthe potential lack of crossing of security boundaries and the\npre-requisites for a successful attack.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":3.3,"baseSeverity":"LOW"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":1.9,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-14684","https://github.com/HdrHistogram/HdrHistogram/issues/220","https://github.com/HdrHistogram/HdrHistogram/","https://vuldb.com/cve/CVE-2026-14684","https://vuldb.com/submit/846754","https://vuldb.com/vuln/376280","https://vuldb.com/vuln/376280/cti"],"bugs":[""],"patches":{"hdrhistogram":[]},"tags":{},"packages":[{"name":"hdrhistogram","source":"https://ubuntu.com/security/cve?package=hdrhistogram","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=hdrhistogram","debian":"https://tracker.debian.org/pkg/hdrhistogram","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-14683","published":"2026-07-04T23:16:00","updated_at":"2026-08-07T13:59:06.663895+00:00","description":"\nA vulnerability was detected in HdrHistogram up to 2.2.2. Affected by this\nissue is the function\norg.HdrHistogram.AbstractHistogram.decodeFromCompressedByteBuffer of the\nfile src/main/java/org/HdrHistogram/AbstractHistogram.java. The\nmanipulation of the argument lengthOfCompressedContents results in\nuncontrolled memory allocation. The attack needs to be approached locally.\nThe exploit is now public and may be used. It is still unclear if this\nvulnerability genuinely exists. This issue is disputed due to the potential\nlack of crossing of security boundaries and the pre-requisites for a\nsuccessful attack.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":3.3,"baseSeverity":"LOW"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":1.9,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-14683","https://github.com/HdrHistogram/HdrHistogram/issues/219","https://github.com/HdrHistogram/HdrHistogram/","https://vuldb.com/cve/CVE-2026-14683","https://vuldb.com/submit/846750","https://vuldb.com/submit/846752","https://vuldb.com/vuln/376279","https://vuldb.com/vuln/376279/cti"],"bugs":[""],"patches":{"hdrhistogram":[]},"tags":{},"packages":[{"name":"hdrhistogram","source":"https://ubuntu.com/security/cve?package=hdrhistogram","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=hdrhistogram","debian":"https://tracker.debian.org/pkg/hdrhistogram","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-14651","published":"2026-07-04T21:17:00","updated_at":"2026-07-16T10:53:55.672417+00:00","description":"\nA vulnerability has been found in connorskees grass up to 0.13.4. The\nimpacted element is the function\ngrass_compiler::selector::extend/grass_compiler::evaluate::visitor. The\nmanipulation leads to denial of service. The attack must be carried out\nlocally. The exploit has been disclosed to the public and may be used. The\nproject maintainer explains: \"DoS vulnerabilities are generally fine in\nSass compilers -- they are trivially possible with recursive functions,\ninfinite loops, nested mixins, etc. The description here is wrong. Compile\ntime is not expected to be linear relative to the input, and the @extend\nalgorithm is definitionally exponential.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":3.3,"baseSeverity":"LOW"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":1.9,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-14651","https://github.com/connorskees/grass/issues/117"],"bugs":[""],"patches":{"sass-grass":[]},"tags":{},"packages":[{"name":"sass-grass","source":"https://ubuntu.com/security/cve?package=sass-grass","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sass-grass","debian":"https://tracker.debian.org/pkg/sass-grass","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-14650","published":"2026-07-04T20:16:00","updated_at":"2026-07-16T10:55:01.493164+00:00","description":"\nA flaw has been found in connorskees grass up to 0.13.4. The affected\nelement is the function grass_compiler::raw_to_parse_error of the component\nUTF-8 Character Handler. Executing a manipulation can lead to denial of\nservice. The attack is restricted to local execution. The exploit has been\npublished and may be used. In Issue #117 with similar structure the project\nmaintainer explains: \"DoS vulnerabilities are generally fine in Sass\ncompilers -- they are trivially possible with recursive functions, infinite\nloops, nested mixins, etc. The description here is wrong. Compile time is\nnot expected to be linear relative to the input, and the @extend algorithm\nis definitionally exponential.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":3.3,"baseSeverity":"LOW"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":1.9,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-14650","https://github.com/connorskees/grass/issues/116"],"bugs":[""],"patches":{"rust-grass-compiler":[],"sass-grass":[]},"tags":{},"packages":[{"name":"rust-grass-compiler","source":"https://ubuntu.com/security/cve?package=rust-grass-compiler","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rust-grass-compiler","debian":"https://tracker.debian.org/pkg/rust-grass-compiler","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"sass-grass","source":"https://ubuntu.com/security/cve?package=sass-grass","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sass-grass","debian":"https://tracker.debian.org/pkg/sass-grass","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-14647","published":"2026-07-04T19:16:00","updated_at":"2026-07-09T14:43:57.116024+00:00","description":"\nA weakness has been identified in onnx up to 1.21.x. This vulnerability\naffects the function convPoolShapeInference_opset19 of the file\nonnx/defs/nn/old.cc of the component onnxruntime. This manipulation causes\nout-of-bounds read. It is possible to initiate the attack remotely. The\nexploit has been made available to the public and could be used for\nattacks. Patch name: a7bf3a0f1d18bb62575236ef6e4944980c40e045. It is\nrecommended to apply a patch to fix this issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":2.1,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-14647","https://github.com/onnx/onnx/issues/8036","https://github.com/onnx/onnx/pull/8051"],"bugs":[""],"patches":{"onnx":[]},"tags":{},"packages":[{"name":"onnx","source":"https://ubuntu.com/security/cve?package=onnx","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=onnx","debian":"https://tracker.debian.org/pkg/onnx","statuses":[{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":8020,"limit":20,"total_results":79316}