CVE-2026-42616
- EPSS 0.16%
- Veröffentlicht 07.10.2026 00:00:00
- Zuletzt bearbeitet 08.10.2026 19:09:18
In NTFS-3G before 2026.7.7, a heap buffer overflow exists in cat() in ntfscat.c that allows an attacker to corrupt heap memory in the ntfscat binary by crafting a malicious NTFS image. The overflow is triggered by reading a file.
CVE-2026-42617
- EPSS 0.15%
- Veröffentlicht 07.10.2026 00:00:00
- Zuletzt bearbeitet 08.10.2026 19:09:12
In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ir_to_ib() in index.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by extending a direct...
CVE-2026-42618
- EPSS 0.15%
- Veröffentlicht 07.10.2026 00:00:00
- Zuletzt bearbeitet 08.10.2026 19:09:07
In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_decompress() in compress.c that allows an attacker to corrupt one byte of heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by r...
CVE-2026-46569
- EPSS 0.16%
- Veröffentlicht 07.10.2026 00:00:00
- Zuletzt bearbeitet 09.10.2026 14:17:21
In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ib_copy_tail(), in libntfs-3g/index.c, that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by e...
CVE-2026-46571
- EPSS 0.13%
- Veröffentlicht 07.10.2026 00:00:00
- Zuletzt bearbeitet 08.10.2026 19:08:32
In NTFS-3G before 2026.7.7, a out-of-bounds read exists in ntfs_fix_file_name() in libntfs-3g/reparse.c that allows an attacker to read possibly confidential information in ntfs-3g process memory by crafting a malicious NTFS image. The out-of-bounds ...
CVE-2026-46572
- EPSS 0.15%
- Veröffentlicht 07.10.2026 00:00:00
- Zuletzt bearbeitet 08.10.2026 19:08:27
In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ib_cut_tail() in libntfs-3g/index.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by crea...
CVE-2026-46570
- EPSS 0.15%
- Veröffentlicht 07.10.2026 00:00:00
- Zuletzt bearbeitet 08.10.2026 19:08:16
In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_index_walk_down() in libntfs-3g/index.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by ...
CVE-2026-56135
- EPSS 0.14%
- Veröffentlicht 24.08.2026 00:00:00
- Zuletzt bearbeitet 09.09.2026 16:03:22
In NTFS-3G through 2026.2.25, a heap-based buffer overflow exists in the function build_inherited_id() in libntfs-3g/security.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The ove...
CVE-2026-56136
- EPSS 0.14%
- Veröffentlicht 24.08.2026 00:00:00
- Zuletzt bearbeitet 09.09.2026 16:03:22
In NTFS-3G through 2026.2.25, an out-of-bounds read exists in ntfs_ir_nill() in libntfs-3g/index.c that allows an attacker to read possibly confidential information in an ntfs-3g process by crafting a malicious NTFS image. This read operation is trig...
CVE-2023-52890
- EPSS 0.16%
- Veröffentlicht 13.06.2024 04:15:15
- Zuletzt bearbeitet 15.04.2026 00:35:42
NTFS-3G before 75dcdc2 has a use-after-free in ntfs_uppercase_mbs in libntfs-3g/unistr.c. NOTE: discussion suggests that exploitation would be challenging.