SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

30 results for “kev-cve-2008-2992” · 0.79 s · cached

Facets · 1 entity types

30 CVE
CVE-2008-4250CVE

Microsoft Windows Buffer Overflow Vulnerability

Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow dur…

EPSS 98.8%KEVMicrosoft
Match for kev-cve-2008-2992
CVE-2026-0029CVE

CVE-2026-0029

In __pkvm_init_vm of pkvm.c, there is a possible memory corruption due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. U…

CVSS 8.4EPSS 0.1%
Match for kev-cve-2008-2992
CVE-2025-6292CVE

CVE-2025-6292

A vulnerability has been found in D-Link DIR-825 2.03 and classified as critical. This vulnerability affects the function sub_4091AC of the component HTTP POST Request Handler. The manipulation leads…

CVSS 8.8EPSS 1.3%
Match for kev-cve-2008-2992
CVE-2008-2992CVE

Adobe Reader and Acrobat Input Validation Vulnerability

Adobe Acrobat and Reader contain an input validation issue in a JavaScript method that could potentially lead to remote code execution.

EPSS 98.5%KEVAdobe
Match for kev-cve-2008-2992
CVE-2026-42770CVE

CVE-2026-42770

Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly checked for the subgroup membership. Impact summary: A malicious peer which present…

CVSS 3.7EPSS 0.3%openssl
Match for kev-cve-2008-2992
CVE-2026-6209CVE

CVE-2026-6209

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Match for kev-cve-2008-2992
CVE-2025-59088CVE

CVE-2025-59088

If kdcproxy receives a request for a realm which does not have server addresses defined in its configuration, by default, it will query SRV records in the DNS zone matching the requested realm name. …

CVSS 8.6EPSS 0.5%
Match for kev-cve-2008-2992
CVE-2025-34069CVE

CVE-2025-34069

An authentication bypass vulnerability exists in GFI Kerio Control 9.4.5 due to insecure default proxy configuration and weak access control in the GFIAgent service. The non-transparent proxy on TCP …

CVSS 9.8EPSS 0.7%
Match for kev-cve-2008-2992
CVE-2025-60228CVE

CVE-2025-60228

Deserialization of Untrusted Data vulnerability in designthemes Knowledge Base kbase allows Object Injection.This issue affects Knowledge Base: from n/a through <= 2.9.

CVSS 8.8EPSS 0.5%
Match for kev-cve-2008-2992
CVE-2025-49091CVE

CVE-2025-49091

KDE Konsole before 25.04.2 allows remote code execution in a certain scenario. It supports loading URLs from the scheme handlers such as a ssh:// or telnet:// or rlogin:// URL. This can be executed r…

CVSS 8.2EPSS 0.7%
Match for kev-cve-2008-2992
CVE-2026-11792CVE

CVE-2026-11792

A heap buffer overflow flaw was found in 389 Directory Server. When audit logging is enabled, the create_masked_entry_string() function in auditlog.c copies a fixed-length password mask into a precis…

CVSS 3.3EPSS 0.3%
Match for kev-cve-2008-2992
CVE-2025-33071CVE

CVE-2025-33071

Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network.

CVSS 8.1EPSS 23.2%
Match for kev-cve-2008-2992
CVE-2026-4395CVE

CVE-2026-4395

Heap-based buffer overflow in the KCAPI ECC code path of wc_ecc_import_x963_ex() in wolfSSL wolfcrypt allows a remote attacker to write attacker-controlled data past the bounds of the pubkey_raw buff…

CVSS 9.8EPSS 0.6%
Match for kev-cve-2008-2992
CVE-2025-49735CVE

CVE-2025-49735

Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network.

CVSS 8.1EPSS 1.1%
Match for kev-cve-2008-2992
CVE-2026-8829CVE

CVE-2026-8829

HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities. The XS routine backing HTML::Entities::_decode_entities cached a pointer (repl) into the entity-value SV retu…

CVSS 7.5EPSS 0.5%oalders
Match for kev-cve-2008-2992
CVE-2026-42992CVE

CVE-2026-42992

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVSS 7.5EPSS 0.6%microsoft
Match for kev-cve-2008-2992
CVE-2026-11793CVE

CVE-2026-11793

A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c copies an attacker-controlled algorithm ID into a 256-byte stack buffer without bounds checking when…

CVSS 4.9EPSS 0.3%redhat
Match for kev-cve-2008-2992
CVE-2026-11787CVE

CVE-2026-11787

A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a heap buffer over-read in string filter parsing that …

CVSS 5.0EPSS 0.2%redhat
Match for kev-cve-2008-2992
CVE-2026-48829CVE

CVE-2026-48829

In GNU SASL before 2.2.3, DIGEST-MD5 has a NULL pointer dereference affecting both clients and servers, via a known token with no accompanying = character. This occurs in lib/digest-md5/getsubopt.c.

CVSS 7.5EPSS 0.6%
Match for kev-cve-2008-2992
CVE-2026-42029CVE

CVE-2026-42029

Rejected reason: This CVE is a duplicate of another CVE.

Match for kev-cve-2008-2992
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.