CVE-2024-36032
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: qca: fix info leak when fetching fw build id Add the missin
CVSS
8.1
Alto
EPSS
0.4%
p28
KEV
—
Exploit Today
9
0-100
Publicado: 30 may 2024 · Última mod.: 4 ago 2026 · CWE-668
0.4%EPSS · 30 días0.4%
2026-08-182026-09-15
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: qca: fix info leak when fetching fw build id Add the missing sanity checks and move the 255-byte build-id buffer off the stack to avoid leaking stack data through debugfs in case the build-info reply is malformed.
- git.kernel.orghttps://git.kernel.org/stable/c/57062aa13e87b1a78a4a8f6cb5fab6ba24f5f488
- git.kernel.orghttps://git.kernel.org/stable/c/62d5550ab62042dcceaf18844d0feadbb962cffe
- git.kernel.orghttps://git.kernel.org/stable/c/6b63e0ef4d3ce0080395e5091fba2023f246c45a
- git.kernel.orghttps://git.kernel.org/stable/c/a571044cc0a0c944e7c12237b6768aeedd7480e1
- git.kernel.orghttps://git.kernel.org/stable/c/cda0d6a198e2a7ec6f176c36173a57bdd8af7af2
- git.kernel.orghttps://git.kernel.org/stable/c/57062aa13e87b1a78a4a8f6cb5fab6ba24f5f488
- git.kernel.orghttps://git.kernel.org/stable/c/62d5550ab62042dcceaf18844d0feadbb962cffe
- git.kernel.orghttps://git.kernel.org/stable/c/6b63e0ef4d3ce0080395e5091fba2023f246c45a
- git.kernel.orghttps://git.kernel.org/stable/c/a571044cc0a0c944e7c12237b6768aeedd7480e1
- git.kernel.orghttps://git.kernel.org/stable/c/cda0d6a198e2a7ec6f176c36173a57bdd8af7af2
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-615907.4 ALT—
———djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, djust's observability endpoints expose live view/session state and a remote method-invocation surface (`eval_handler`). The localhost restriction was an opt-in middleware that the documented setup omits; the views themselves enforced only `DEBUG`. In the misconfigured-but-documented scenario (DEBUG on, middleware not installed) a non-localhost client could read live application state and invoke handlers remotely. This issue is fixed in djust 1.0.7. The localhost restriction is enforced in-view on every observability endpoint (no longer dependent on a separately-installed middleware), and `eval_handler` is restricted; gated requests receive a non-disclosing response. As a workaround, ensure `DEBUG=False` in production, and do not expose the observability endpoints to untrusted networks.6hCVE-2026-850538.8 ALT22.0%
——7Improper resource exposure in CacheStorage in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)8dCVE-2026-826525.3 MED10.7%
——3SiYuan before v3.8.1 fails to filter invisible-tier content from SQL embed blocks, attribute-view keys, and attribute-view backlinks in publish mode. Anonymous readers can enumerate invisible content through these three listing mechanisms despite admin configuration marking content unlisted.16dCVE-2026-826504.4 MED12.5%
——4SiYuan 3.8.0 contains a path traversal / sensitive file exposure vulnerability in the RenderTemplate function (kernel/model/template.go), reachable via the POST /api/template/render endpoint (kernel/api/template.go). The endpoint restricts the supplied path only to the workspace directory (util.IsAbsPathInWorkspace) but, unlike the file API's refuseToAccess() blocklist, applies no sensitive-path exclusion. This allows an authenticated attacker to read sensitive workspace files, including conf/conf.json, which contains the API token and cookie signing key. The issue is fixed in v3.8.1.16dCVE-2026-790684.3 MED11.1%
——3Improper resource exposure in StreamsAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Medium)16dCVE-2026-790313.1 BAJ26.4%
——8Improper resource exposure in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)19d