CVE-2025-59609
Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length.
CVSS
5.5
Medio
EPSS
0.1%
p1
KEV
—
Exploit Today
0
0-100
Publicado: 1 jun 2026 · Última mod.: 22 jul 2026 · CWE-126
0.1%EPSS · 30 días0.1%
2026-08-022026-08-31
Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-70652—1.6%
——0libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built with libultrahdr support can incorrectly size an output buffer in libvips/foreign/uhdrsave.c within vips_foreign_save_uhdr_set_raw_hdr when a pipeline enlarges an incoming JPEG to a very large output before encoding a gain map through VipsForeignSaveUhdr. The undersized allocation can cause a heap buffer over-read that may disclose adjacent data or crash the process. This issue is fixed in version 8.18.3.10dCVE-2026-535877.5 ALT32.2%
——10libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 performs a fixed-size strncmp in set_data in src/libgit2/transports/smart_pkt.c without first verifying that the smart-protocol pkt-line capability buffer contains 14 bytes. A malicious Git server can make bytes after the pkt-line complete object-format=, causing format_str to advance beyond the pkt-line and the following memchr length calculation to underflow. The resulting heap out-of-bounds walk can crash a client during the first refs-advertisement packet over HTTP, HTTPS, SSH, or the Git protocol. This issue is fixed in versions 1.8.6 and 1.9.5.11dCVE-2026-768853.1 BAJ7.0%
——2Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service3dCVE-2026-768843.1 BAJ7.0%
——2ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service3dCVE-2026-695506.5 MED48.7%
——15Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.4dCVE-2026-65933—7.4%
——2A malformed Bluetooth connection request message can cause the BT122 to leak potentially sensitive information. See vulnerability B-E4 in the related paper below.18d