Retour à la veille
CVE-2026-88839
Score CVSS
6.7
MEDIUM
Description détaillée
BusyBox passwd/group tokenize() references a stale endpoint pointer after trimming, causing an out-of-bounds write of heap pointers.
Vecteur d'attaque (CVSS)
Vecteur brut :CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Dernières Vulnérabilités
CVE-2026-91775
LimeSurvey fails to safely encode attacker-controlled content from a crafted .lss survey file when displaying import warnings, resulting in XSS in the administrative interface.
VOIR DÉTAILS
CVE-2026-88840
BusyBox TLS get_client_hello() reads past the end of the input buffer when parsing a truncated ClientHello message.
VOIR DÉTAILS
CVE-2026-88837
BusyBox httpd treats yescrypt ($y$) password hashes as plaintext during Basic Authentication, inverting the authentication check.
VOIR DÉTAILS
