Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
Oracle Linux 9 has issued two important advisories addressing critical vulnerabilities in the Apache HTTP Server. The first advisory (ELSA-2026-21391) details multiple CVEs, including CVE-2026-28780, which allows arbitrary code execution via a heap-based buffer overflow. Other vulnerabilities includ...
Mageia 10 has released security updates addressing critical Denial of Service vulnerabilities in libxml2 and libtiff. CVE-2026-6732 affects systems processing crafted xsd-validated documents, while CVE-2026-36849 targets large SamplesPerPixel tags in libtiff. Both vulnerabilities were disclosed on J...
Four vulnerabilities affecting the Apache HTTP Server have been disclosed, including source code disclosures and denial-of-service (DoS) issues. The vulnerabilities, identified as CVE-2024-39884, CVE-2024-40725, CVE-2024-27316, and CVE-2024-36387, impact configurations using AddType and HTTP/2 featu...
Oracle has released advisories for multiple denial-of-service (DoS) vulnerabilities affecting mod_http2 in Oracle Linux 10. The vulnerabilities include CVE-2026-43951, CVE-2026-48913, and CVE-2026-49975, all published on 2026-06-08. CVE-2026-49975 specifically allows for remote DoS attacks via compr...