Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Zhangph

#18400of 56,326
15.6Total CVSS
Vulnerabilities · 2
High
2
PT-2026-52211
8.1
2026-06-25
Nsd · Nsd · CVE-2026-12246
**Name of the Vulnerable Software and Affected Versions** NSD version 4.14.0 **Description** A memory corruption flaw exists when handling APL (Address Prefix List) resource records during the process of serializing or writing a zone to disk. The issue stems from improper input validation and bounds checking of the `adflength` field. An attacker can trigger a stack-based buffer overflow by introducing a specially crafted APL record with an `adflength` larger than permitted for the address family into a zone. This can result in the overwrite of up to 111 attacker-controlled bytes on the stack, potentially leading to a denial of service or arbitrary code execution. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2026-42903
7.5
2026-05-24
Gnu · Gnu Sasl · CVE-2026-48829
**Name of the Vulnerable Software and Affected Versions** GNU SASL versions prior to 2.2.3 **Description** DIGEST-MD5 contains a NULL pointer dereference affecting both clients and servers. This issue occurs in the file lib/digest-md5/getsubopt.c when a known token is provided without an accompanying = character. **Recommendations** Update to version 2.2.3 or later.