Tag
A heap buffer overflow vulnerability in Dnsmasq (CVE-2026-2291) allows remote code execution via a malicious upstream DNS server. The issue was introduced in version 2.73 and fixed in 2.92rel2 and 2.93.
A heap buffer overflow vulnerability in the Linux kernel's iSCSI target authentication code (BASE64 CHAP decoding) allows unauthenticated remote attackers to overflow fixed-size buffers, potentially leading to code execution. The vulnerability was introduced in a 2022 commit and affects systems with iSCSI target support.
A critical heap buffer overflow vulnerability in Nginx's rewrite module (CVE-2026-42945) allows unauthenticated remote code execution, with a proof-of-concept exploit released. The bug affects Nginx versions from 0.6.27 to 1.30.0 and various Nginx Plus releases.