Search

Search Results (402600 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-104034 2 Redhat, Sssd 4 Enterprise Linux, Openshift, Openshift Container Platform and 1 more 2026-10-06 4.7 Medium
A flaw was found in SSSD. A use-after-free vulnerability exists in the Kerberos Credential Manager (KCM) responder during Kerberos ticket-granting ticket (TGT) renewal, where a deferred callback accesses memory that has already been released. An authenticated local user with a renewable Kerberos ticket can trigger this issue on systems configured with KCM renewal, causing the KCM responder service to crash and resulting in a Denial of Service (DoS).
CVE-2026-104035 2 Redhat, Sssd 4 Enterprise Linux, Openshift, Openshift Container Platform and 1 more 2026-10-06 5.5 Medium
A flaw was found in SSSD. An issue in the Kerberos Credential Manager (KCM) responder allows a local user to cause a Denial of Service (DoS) by maintaining a persistent connection and repeatedly storing and destroying credentials. Because the service fails to release cached objects from memory when credentials are removed, memory consumption grows continuously, ultimately exhausting available memory and rendering the service unresponsive.
CVE-2026-104036 2 Redhat, Sssd 4 Enterprise Linux, Openshift, Openshift Container Platform and 1 more 2026-10-06 5.8 Medium
A flaw was found in SSSD's NFS idmap plugin. When retrieving cached user or group names, the plugin detects if an entry exceeds the destination buffer size but fails to abort before copying data. A local attacker can trigger this vulnerability by requesting identity lookups that resolve to oversized cached entries, resulting in an out-of-bounds write. This flaw primarily leads to a Denial of Service (DoS) by crashing the identity mapping service, and may also corrupt adjacent process memory.
CVE-2026-92821 2 Redhat, Sssd 4 Enterprise Linux, Openshift, Openshift Container Platform and 1 more 2026-10-06 6.8 Medium
A flaw was found in SSSD. When configured to evaluate password expiration warnings before restrictive access rules in LDAP (Lightweight Directory Access Protocol) environments, an expired-password warning terminates rule evaluation early and treats the access request as successful. A remote authenticated user with an expired password using an alternative authentication method, such as SSH public key authentication, can exploit this flaw to bypass access control restrictions and gain unauthorized access to protected systems.
CVE-2026-104037 2 Redhat, Sssd 4 Enterprise Linux, Openshift, Openshift Container Platform and 1 more 2026-10-06 5.5 Medium
A flaw was found in SSSD. A local attacker can exploit this issue by sending a specially crafted request with an invalid packet length to the autofs responder UNIX socket. This causes an integer underflow and an out-of-bounds memory read, which can crash the responder process and result in a denial of service (DoS).
CVE-2026-104038 2 Redhat, Sssd 4 Enterprise Linux, Openshift, Openshift Container Platform and 1 more 2026-10-06 5.9 Medium
A flaw was found in sssd. A remote attacker can cause a denial of service (DoS) by submitting a certificate that lacks an expected Security Identifier (SID) extension. In deployments configured with SID-based certificate mapping rules, the service fails to verify the presence of the extension before processing it, causing the process to crash during authentication or lookup operations.
CVE-2026-104039 2 Redhat, Sssd 4 Enterprise Linux, Openshift, Openshift Container Platform and 1 more 2026-10-06 4.7 Medium
A flaw was found in SSSD. A local user can cause a denial of service (DoS) by disrupting system authentication services. When handling Generic Security Services Application Programming Interface (GSSAPI) authentication in the Pluggable Authentication Module (PAM) responder, cached connection state is freed upon completion without clearing the reference pointer. An attacker can exploit this by sending an additional request over the same connection, causing the service to access invalid memory and unexpectedly terminate.
CVE-2026-104040 2 Redhat, Sssd 4 Enterprise Linux, Openshift, Openshift Container Platform and 1 more 2026-10-06 4.4 Medium
A flaw was found in SSSD. When configured with the Entra ID identity provider, input lookup names containing single quotes are not properly escaped before being included in Microsoft Graph Open Data Protocol (OData) queries. A low-privileged local user can exploit this flaw by submitting a crafted search request, altering query filters to broaden user or group searches. This can lead to information disclosure by retrieving unintended directory objects, as well as a Denial of Service (DoS) through excessive processing and cache population.
CVE-2026-104042 2 Redhat, Sssd 4 Enterprise Linux, Openshift, Openshift Container Platform and 1 more 2026-10-06 5.5 Medium
A flaw was found in sssd. A local attacker can cause a Denial of Service (DoS) by sending a crafted Pluggable Authentication Module (PAM) request containing a zero-length authentication token to the responder socket. Due to missing input validation, the service attempts to read beyond buffer boundaries when processing the token, causing the PAM responder to crash.
CVE-2026-104043 2 Redhat, Sssd 4 Enterprise Linux, Openshift, Openshift Container Platform and 1 more 2026-10-06 5.5 Medium
A flaw was found in SSSD. A local attacker with access to the Name Service Switch (NSS) responder UNIX socket can trigger an integer underflow by sending a specially crafted request with an undersized packet header. This issue causes an out-of-bounds memory read during packet parsing, crashing the responder process and resulting in a Denial of Service (DoS).
CVE-2026-104044 2 Redhat, Sssd 4 Enterprise Linux, Openshift, Openshift Container Platform and 1 more 2026-10-06 6.2 Medium
A flaw was found in sssd. A local attacker can trigger a Denial of Service (DoS) by sending a specially crafted Pluggable Authentication Module (PAM) request when passkey authentication is enabled. Due to a missing state validation check in passkey Kerberos handling, the PAM responder dereferences an uninitialized pointer and crashes. This failure disrupts authentication services on the host.
CVE-2026-104380 1 Perl 1 Punk 2026-10-06 5.3 Medium
Punk versions from 0.48 before 0.55 for Perl route Extended CONNECT requests to any GET route without an Origin check in ps_serve_one. On HTTP/2 and HTTP/3 a WebSocket handshake arrives as an Extended CONNECT, which is matched as a GET and so reaches every GET route, API operation and mount. The Origin check runs only when a websocket route matches. On this transport the handler's status is the handshake response, and a 2xx accepts it. A cross-origin page can open a WebSocket to any path and learn from its open or error event whether that path returns 2xx.
CVE-2026-94293 1 Murrelektronik 2 Aas Edge Client, Software Aas Edge Client All Versions 2026-10-06 9.8 Critical
An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read all data exposed by the GET endpoints.
CVE-2026-42414 2 Cridio, Wordpress-extensions 2 Listingpro, Listingpro 2026-10-06 8.5 High
Subscriber SQL Injection in ListingPro <= 2.9.12 versions.
CVE-2026-42415 2 Portotheme, Wordpress-extensions 2 Functionality, Porto Theme 2026-10-06 9.3 Critical
Unauthenticated SQL Injection in Porto Theme - Functionality <= 3.9.3 versions.
CVE-2026-42416 2 Andondesign, Wordpress-extensions 2 Udesign, Udesign Core 2026-10-06 8.5 High
Subscriber SQL Injection in UDesign Core <= 4.15.0 versions.
CVE-2026-42417 2 Reputeinfosystems, Wordpress-extensions 2 Armember, Armember Premium 2026-10-06 9.3 Critical
Unauthenticated SQL Injection in ARMember Premium <= 7.8 versions.
CVE-2026-42418 2 Wordpress-extensions, Wpsocialrocket 2 Social Rocket, Social Rocket 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Social Rocket <= 1.3.5 versions.
CVE-2026-42634 2 Bplugins, Wordpress-extensions 2 Video Background Block – Use Video As Background In The Section., Video Background Block Use Video As Background In The Section 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Video Background Block – Use video as background in the section. <= 2.0.3 versions.
CVE-2026-42635 2 Wordpress-extensions, Wpgenie 2 Woocommerce Simple Auctions, Woocommerce Simple Auctions 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in WooCommerce Simple Auctions <= 3.0.10 versions.