在 libxml2 中发现了一个漏洞。本地用户或攻击者可以通过提供一份经过特殊构造的 XML 目录(XML catalog)文件,在解析 XML 目录过程中触发空指针解引用(NULL pointer dereference)。具体而言,当 元素缺少其必需的 属性时,会导致应用程序崩溃,从而引发拒绝服务(Denial of Service, DoS)攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Hardened Images | - |
cpe:/a:redhat:hummingbird:1
|
|
| Red Hat | Red Hat Hardened Images | - |
cpe:/a:redhat:hummingbird:1
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86320 | 7.8 HIGH | Flatpak-builder: host code execution via `git am` hook execution in patch source extractio |
| CVE-2026-87742 | 7.5 HIGH | Quarkus-websockets-next: denial of service (oom) in quarkus-websockets-next via unbounded |
| CVE-2026-92925 | 7.1 HIGH | Redis: redis: out-of-bounds read via crafted cluster bus packets |
| CVE-2026-81829 | 5.3 MEDIUM | Smallrye-jwt: quarkus-smallrye-jwt: smallrye-jwt: unauthenticated same-origin ssrf via uns |
| CVE-2026-92904 | 4.3 MEDIUM | Rubygem-foreman_remote_execution: job output readable without object-level view_job_invoca |
| CVE-2026-92893 | 4.3 MEDIUM | Rubygem-foreman_ansible: ansible inventory api ignores view_hosts permission filters, expo |
| CVE-2026-92894 | 4.3 MEDIUM | Rubygem-foreman_ansible: unscoped lookupvalue deletion allows cross-model override value d |
No comments yet