SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

43 results for “kev-cve-2026-3909” · 0.59 s · cached

Facets · 1 entity types

43 CVE
CVE-2026-52907CVE

CVE-2026-52907

In the Linux kernel, the following vulnerability has been resolved: media: rockchip: rkcif: fix off by one bugs Change these comparisons from > vs >= to avoid accessing one element beyond the end o…

CVSS 7.8EPSS 0.2%linux
Match for kev-cve-2026-3909
CVE-2026-43039CVE

CVE-2026-43039

In the Linux kernel, the following vulnerability has been resolved: net: ti: icssg-prueth: fix missing data copy and wrong recycle in ZC RX dispatch emac_dispatch_skb_zc() allocates a new skb via n…

CVSS 9.8EPSS 0.6%
Match for kev-cve-2026-3909
CVE-2026-5433CVE

CVE-2026-5433

Honeywell Control Network Module (CNM) contains command injection vulnerability in the web interface. An attacker could exploit this vulnerability via command delimiters, potentially resulting in Rem…

CVSS 9.1EPSS 1.6%
Match for kev-cve-2026-3909
CVE-2026-5909CVE

CVE-2026-5909

Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: Low)

CVSS 8.8EPSS 0.3%google
Match for kev-cve-2026-3909
CVE-2026-9076CVE

CVE-2026-9076

Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap) processes attacker-supplied CMS data, an attacker-chosen stream-mode KEK cipher can trigger a heap out-of-bounds read in…

CVSS 7.5EPSS 1.0%openssl
Match for kev-cve-2026-3909
CVE-2026-3921CVE

CVE-2026-3921

Use after free in TextEncoding in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS 8.8EPSS 0.4%
Match for kev-cve-2026-3909
CVE-2026-3809CVE

CVE-2026-3809

A flaw has been found in Tenda FH1202 1.2.0.14(408). The impacted element is the function fromNatStaticSetting of the file /goform/NatSaticSetting. Executing a manipulation of the argument page can l…

CVSS 8.8EPSS 1.0%
Match for kev-cve-2026-3909
CVE-2026-45760CVE

CVE-2026-45760

(Externally Controlled Reference to a Resource in Another Sphere), (Authorization Bypass Through User-Controlled Key) vulnerability in Apache Camel K. Authorized users in a Kubernetes namespace can c…

CVSS 8.1EPSS 0.4%
Match for kev-cve-2026-3909
CVE-2026-44009CVE

CVE-2026-44009

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, This vulnerability is fixed in 3.11.2.

CVSS 9.8EPSS 0.7%vm2_project
Match for kev-cve-2026-3909
CVE-2026-41109CVE

CVE-2026-41109

Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature ove…

CVSS 8.8EPSS 0.9%microsoft
Match for kev-cve-2026-3909
CVE-2026-46264CVE

CVE-2026-46264

In the Linux kernel, the following vulnerability has been resolved: drm/xe/pf: Fix sysfs initialization In case of devm_add_action_or_reset() failure the provided cleanup action will be run immedia…

CVSS 8.8EPSS 0.2%linux
Match for kev-cve-2026-3909
CVE-2026-31590CVE

CVE-2026-31590

In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Drop WARN on large size for KVM_MEMORY_ENCRYPT_REG_REGION Drop the WARN in sev_pin_memory() on npages overflowing an in…

CVSS 5.5EPSS 0.2%linux
Match for kev-cve-2026-3909
CVE-2026-41092CVE

CVE-2026-41092

Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally.

CVSS 7.8EPSS 0.3%microsoft
Match for kev-cve-2026-3909
CVE-2026-52906CVE

CVE-2026-52906

In the Linux kernel, the following vulnerability has been resolved: 9p: fix access mode flags being ORed instead of replaced Since commit 1f3e4142c0eb ("9p: convert to the new mount API"), v9fs_app…

CVSS 7.7EPSS 0.2%linux
Match for kev-cve-2026-3909
CVE-2026-43139CVE

CVE-2026-43139

In the Linux kernel, the following vulnerability has been resolved: xfrm6: fix uninitialized saddr in xfrm6_get_saddr() xfrm6_get_saddr() does not check the return value of ipv6_dev_get_saddr(). Wh…

CVSS 8.6EPSS 0.5%
Match for kev-cve-2026-3909
CVE-2026-10993CVE

CVE-2026-10993

Heap buffer overflow in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium secur…

CVSS 6.5EPSS 0.3%google
Match for kev-cve-2026-3909
CVE-2026-4039CVE

CVE-2026-4039

A vulnerability was determined in OpenClaw 2026.2.19-2. This vulnerability affects the function applySkillConfigenvOverrides of the component Skill Env Handler. Executing a manipulation can lead to c…

CVSS 8.8EPSS 0.6%
Match for kev-cve-2026-3909
CVE-2026-0028CVE

CVE-2026-0028

In __pkvm_host_share_guest of mem_protect.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileg…

CVSS 8.4EPSS 0.2%
Match for kev-cve-2026-3909
CVE-2026-11039CVE

CVE-2026-11039

Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVSS 6.5EPSS 0.3%google
Match for kev-cve-2026-3909
CVE-2025-53928CVE

CVE-2025-53928

MaxKB is an open-source AI assistant for enterprise. Prior to versions 1.10.9-lts and 2.0.0, a Remote Command Execution vulnerability exists in the MCP call. Versions 1.10.9-lts and 2.0.0 fix the iss…

CVSS 9.8EPSS 0.4%
Match for kev-cve-2026-3909
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.