Retour à la veille
CVE-2026-88840
Score CVSS
5.3
MEDIUM
Description détaillée
BusyBox TLS get_client_hello() reads past the end of the input buffer when parsing a truncated ClientHello message.
Vecteur d'attaque (CVSS)
Vecteur brut :CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Dernières Vulnérabilités
CVE-2026-91775
LimeSurvey fails to safely encode attacker-controlled content from a crafted .lss survey file when displaying import warnings, resulting in XSS in the administrative interface.
VOIR DÉTAILS
CVE-2026-88839
BusyBox passwd/group tokenize() references a stale endpoint pointer after trimming, causing an out-of-bounds write of heap pointers.
VOIR DÉTAILS
CVE-2026-88837
BusyBox httpd treats yescrypt ($y$) password hashes as plaintext during Basic Authentication, inverting the authentication check.
VOIR DÉTAILS
