CVE-2026-56968
GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory di
CVSS
3.7
Low
EPSS
0.3%
p21
KEV
—
Exploit Today
6
0-100
Published: Jun 23, 2026 · Last modified: Jul 31, 2026 · CWE-839 · CWE-908
0.3%EPSS · 30 days0.3%
2026-08-032026-08-31
GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.
- ftp.gnu.orghttps://ftp.gnu.org/gnu/gsasl/
- lists.debian.orghttps://lists.debian.org/debian-security-announce/2026/msg00259.html
- lists.gnu.orghttps://lists.gnu.org/archive/html/help-gsasl/2026-06/msg00000.html
- www.gnu.orghttps://www.gnu.org/software/gsasl/
- lists.debian.orghttps://lists.debian.org/debian-lts-announce/2026/07/msg00049.html
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-792856.5 MED29.3%
——9Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)1dCVE-2026-792706.5 MED29.3%
——9Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)1dCVE-2026-792694.3 MED16.9%
——5Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)1dCVE-2026-792296.5 MED29.3%
——9Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)1dCVE-2026-792216.5 MED14.7%
——4Uninitialized resource in Dawn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)1dCVE-2026-791206.5 MED22.2%
——7Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)1d