CWE-908
- 11
- vulnerabilities tracked
- 1
- critical
- 24 July 2026
- latest publication
cve
Vulnerability watch
idvulnerabilityseveritypublished
CVE-2026-66034libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. In libssh2_publickey_list_fetch(), the version 1 response parser reads a server-controlled comment_len value and advances the parse pointer without verifying sufficient bytes remain in the buffer, causing the out-of-bounds read to leak heap pointers from adjacent allocations defeating ASLR, followed by heap allocator state corruption when the error cleanup path frees an uninitialized pointer from a non-zeroed realloc() region.NVD analysis in progress High CVSS 7.5 CVE-2026-16384Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.Mozilla Firefox High CVSS 7.5 CVE-2026-16385Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.Mozilla Firefox High CVSS 7.5 CVE-2026-16386Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.Mozilla Firefox High CVSS 7.5 CVE-2026-60005NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart.
Impact:
This vulnerability may allow remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only.
Note: The ngx_http_slice_module module is not enabled by default; it's enabled with the --with-http_slice_module configuration parameter.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.NVD analysis in progress High CVSS 8.2 CVE-2026-49165Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.Microsoft Windows 10 1607 High CVSS 7.1 CVE-2026-50497Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.Microsoft Windows 10 1607 High CVSS 7.5 CVE-2026-55949Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 CVE-2026-56190Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 Critical CVSS 9.8 CVE-2026-58533Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.Microsoft Windows 10 1607 High CVSS 7.5 CVE-2026-58535Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.Microsoft Windows 10 1607 High CVSS 7.5