NVD CVEs — 本日公開 (70 件)
CVE-2026-3245 7.5 HIGH
A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.
CVE-2026-12185
In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before integrity check. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
CVE-2026-15055
In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series)
CVE-2026-18581 3.3 LOW
A vulnerability was determined in ggml-org llama.cpp e15efe0. Affected by this issue is some unknown functionality of the file common/jinja/parser.cpp of the component Jinja Minja Template Parser. Executing a manipulation with the input {{9|9|{ can lead to reachable assertion. The attack requires lo
CVE-2026-59638
In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bctls-fips 1.0.24 (1.0.X series), 2.0.24 (2.0.X series) and 2.1.2
CVE-2026-59639
In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X ser
CVE-2026-59640
In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check oracle active on symmetric/session-key paths. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X ser
CVE-2026-59641
In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcmail-fips and bcjmail-fips 1.0.7 (1.0.X series), 2.0.7 (2.0.X series) a
CVE-2026-59642
In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs present. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X
CVE-2026-59643
In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored. This issue also affects Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 2.0.13.
GitHub Security Advisories — 本日公開 (20 件)
GHSA-3q78-fqj5-g3mc
HIGH
In Bouncy Castle for Java before 1.85, HSS public-key level count unbounded, enabling huge...
GHSA-vmmw-77gq-c2hq
UNKNOWN
In Audio HAL, there is a possible system becoming unresponsive due to a race condition. This...
GHSA-854r-9p65-g453
UNKNOWN
In Bluetooth driver, there is a possible permission bypass due to a missing permission check....
GHSA-85vg-gq3h-4v5x
UNKNOWN
In display, there is a possible information disclosure due to a missing bounds check. This could...
GHSA-76m9-f2pj-7mwp
UNKNOWN
In geniezone, there is a possible out of bounds write due to a missing bounds check. This could...
GHSA-777x-vvpp-fv9v
UNKNOWN
In geniezone, there is a possible escalation of privilege due to a missing permission check. This...
GHSA-r43r-m9g7-qp49
UNKNOWN
In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to...
GHSA-639g-9ffj-23fc
UNKNOWN
In med, there is a possible out of bounds write due to an incorrect bounds check. This could lead...
GHSA-g7m9-j98f-r923
UNKNOWN
In imgsensor, there is a possible application crash due to incorrect error handling. This could...
GHSA-36p8-6qw9-45qf
UNKNOWN
In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could...