PULSE
EN VIVO50señales / 24h
FEED
ransomstorm reclama a NCA Alarms · US · Otherransomstorm reclama a Nelson Manufacturing · US · Manufacturingransomstorm reclama a Southern Indiana Radiological Associates · US · Healthcareransomstorm reclama a Liberty Healthcare Corporation · US · Healthcareransomstorm reclama a EvansPetree · US · Otherransomhelix reclama a Venture Logistics · Transportationransomhelix reclama a Uber · US · Transportationransomhelix reclama a Highwoods Properties · US · Otherransomhelix reclama a Morguard · US · Not Foundransomhelix reclama a Westland Insurance · CA · Financial Servicesransomkrybit reclama a reflet2000.fr · FR · Otherransomkrybit reclama a www.actini.com · FR · Technologyransomkrybit reclama a www.ernat-bureau-etudes.fr · FR · Professional Servicesransomkrybit reclama a www.serengetiestates.co.za · ZA · Not Foundransomstorm reclama a NCA Alarms · US · Otherransomstorm reclama a Nelson Manufacturing · US · Manufacturingransomstorm reclama a Southern Indiana Radiological Associates · US · Healthcareransomstorm reclama a Liberty Healthcare Corporation · US · Healthcareransomstorm reclama a EvansPetree · US · Otherransomhelix reclama a Venture Logistics · Transportationransomhelix reclama a Uber · US · Transportationransomhelix reclama a Highwoods Properties · US · Otherransomhelix reclama a Morguard · US · Not Foundransomhelix reclama a Westland Insurance · CA · Financial Servicesransomkrybit reclama a reflet2000.fr · FR · Otherransomkrybit reclama a www.actini.com · FR · Technologyransomkrybit reclama a www.ernat-bureau-etudes.fr · FR · Professional Servicesransomkrybit reclama a www.serengetiestates.co.za · ZA · Not Found
← Todos los CVEs
CVE Watch5 ago 2026

CVE-2026-67858

Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery Server (LDS) is built with multicast discovery enabled thro

CVSS

7.5

Alto

EPSS

0.5%

p39

KEV

Exploit Today

12

0-100

Publicado: 4 ago 2026 · Última mod.: 5 ago 2026 · CWE-120

EPSS · 30d

Sin historial EPSS suficiente todavía.

Descripción técnica

Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery Server (LDS) is built with multicast discovery enabled through the MDNSD backend. An unauthenticated remote attacker can send a RegisterServer or RegisterServer2 request containing many unique discoveryUrls. This allows remote attackers to cause a denial of service.

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-678717.5 ALT
0Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the AddNodes, address_space_bs.c, sopc_node_mgt_helper_internal.c, and toolkit_test_server19h
CVE-2026-678697.5 ALT
0Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Service_Call validates input arguments against runtime-resolved InputArguments metadata19h
CVE-2026-181034.9 MED
32.8%
10A flaw was found in dhcp-server. A remote attacker with network access to the OMAPI (Open Management Application Programming Interface) port, especially if not secured with TSIG (Transaction Signature) key authentication, could send a specially crafted lease creation request. This request, containing an overly long InfiniBand MAC address, triggers a buffer overflow in the `print_hw_addr()` function. Successful exploitation leads to a persistent denial of service (DoS), causing the `dhcpd` service to crash and preventing it from restarting without manual intervention.17h
CVE-2026-455379.1 CRÍ
28.5%
9OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the construct_uri() function concatenates multiple URI components (protocol, username, domain, port, params) into a fixed 1024-byte global BSS buffer without any bounds checking. When a routing script calls construct_uri() with an attacker-controlled username, a combined component length exceeding 1024 bytes overflows the buffer, corrupting adjacent global data with attacker-controlled content. The overflow reaches disable_503_translation, a global flag controlling SIP 503 response handling, allowing an attacker to deterministically set the flag via the URI username and alter the server's routing behavior for subsequent messages. Because the same buffer is shared with contact_builder(), the overflow also corrupts that function's data, and without a memory sanitizer the adjacent globals are silently overwritten on every request containing a long username. This issue has been fixed in versions 3.6.6 and 4.0.0-rc1.2d
CVE-2026-678597.5 ALT
38.0%
11Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Discovery/LDS handling.2d
CVE-2026-451009.1 CRÍ
44.8%
13OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions 3.4.0-beta through 3.6.5 and 4.0.0-beta contain a buffer overflow in the {s.b64encode} string transformation. The size check for {s.b64encode} only verifies that the input fits within the 64 KB transformation buffer, but base64 encoding expands the data by roughly a third, so an input between about 49,153 and 65,535 bytes produces more output than the buffer can hold and overflows it by up to 21,844 bytes. Because these transformation buffers sit next to each other in memory and are reused for chained transformations, the overflow writes attacker-controlled data into the adjacent buffer and corrupts values used by later transformations processing the same SIP message. A remote attacker can trigger this by sending a SIP message with a large header value (roughly 50,000 bytes or more) when the routing script applies  {s.b64encode}  to attacker-controlled input, making exploitability dependent on the deployment's routing configuration. This issue has been fixed in versions 3.6.6 and 4.0.0-rc1.2d