CVE-2026-42764 NULL Pointer Dereference in QUIC Server Initial Packet Handling
Information published.
Categories: Microsoft
CVE-2026-45446 Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes
Information published.
Categories: Microsoft
CVE-2026-9076 Out-of-Bounds Read in CMS Password-Based Decryption
Information published.
Categories: Microsoft
CVE-2026-42768 Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt()
Information published.
Categories: Microsoft
CVE-2026-7383 Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversion
Information published.
Categories: Microsoft
CVE-2026-34182 CMS AuthEnvelopedData Processing May Accept Forged Messages
Information published.
Categories: Microsoft
CVE-2026-34183 Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler
Information published.
Categories: Microsoft
CVE-2026-45447 Heap Use-After-Free in the PKCS7_verify() Function
Information published.
Categories: Microsoft
CVE-2026-44705 tmp: Path Traversal via unsanitized prefix/postfix enables directory escape
Information published.
Categories: Microsoft
CVE-2026-52858 Vim: Arbitrary Code Execution via Python Omni-Completion
Information published.
Categories: Microsoft
CVE-2026-47162 Vim: Vimscript Code Injection in netrw NetrwBookHistSave() via crafted directory name
Information published.
Categories: Microsoft
CVE-2026-47167 Vim: Vimscript Code Injection in cucumber filetype plugin via crafted step-definition regex
Information published.
Categories: Microsoft
CVE-2026-52859 Vim: Out-of-bounds Read in Terminal Screen Snapshot
Information published.
Categories: Microsoft
CVE-2026-52860 Vim: Arbitrary Code Execution via Python Omni-Completion
Information published.
Categories: Microsoft
CVE-2026-46683 Snappy: SSRF and local file read via the xsl-style-sheet option
Information published.
Categories: Microsoft
CVE-2026-46643 Snappy: Binary path is never shell-escaped due to an inverted is_executable check
Information published.
Categories: Microsoft
CVE-2026-42012 Gnutls: gnutls: certificate validation bypass due to improper handling of uri and srv sans
Information published.
Categories: Microsoft
CVE-2026-5260 Gnutls: gnutls: information disclosure via heap overread in rsa key exchange
Information published.
Categories: Microsoft
CVE-2026-42015 Gnutls: gnutls: memory corruption due to off-by-one error in pkcs#12 bag handling
Information published.
Categories: Microsoft


