CVE-2026-68766
- EPSS 0.22%
- Veröffentlicht 22.08.2026 15:16:20
- Zuletzt bearbeitet 22.08.2026 15:16:20
hashcat fails to restrict command-line options when parsing restore files, allowing attackers to inject output-redirecting options like --outfile and --potfile-path. Attackers can craft restore files with malicious options to append attacker-controll...
CVE-2026-68767
- EPSS 0.17%
- Veröffentlicht 22.08.2026 15:16:20
- Zuletzt bearbeitet 22.08.2026 15:16:20
hashcat's fgetl() function in src/filehandling.c writes a null terminator one byte past the caller's buffer when an input line is exactly the buffer length. Attackers can trigger this out-of-bounds heap write by providing a hash file, potfile, or wor...
CVE-2026-68768
- EPSS 0.19%
- Veröffentlicht 22.08.2026 15:16:20
- Zuletzt bearbeitet 22.08.2026 15:16:20
hashcat contains a heap-based buffer overflow (out-of-bounds write) in the outfile_write() function in src/outfile.c. When assembling output into a fixed-size buffer (HCBUFSIZ_LARGE, ~16 MB), the function sequentially appends the username, separator,...
CVE-2026-68765
- EPSS 0.13%
- Veröffentlicht 17.08.2026 20:48:17
- Zuletzt bearbeitet 21.08.2026 12:16:31
hashcat master branch builds after v7.1.2 contain a heap buffer overflow vulnerability in the KeePass AESKDF/KDBX v4 module (module 34301) that allows attackers to corrupt adjacent heap memory by supplying an oversized ninth hash field token. The mod...
CVE-2026-42482
- EPSS 0.4%
- Veröffentlicht 01.05.2026 14:16:22
- Zuletzt bearbeitet 01.05.2026 19:16:32
A stack-based buffer overflow in mangle_to_hex_lower() and mangle_to_hex_upper() in src/rp_cpu.c in hashcat v7.1.2 allows an attacker to cause a denial of service or possibly execute arbitrary code via a crafted rule file, or via the -j or -k rule op...
CVE-2026-42483
- EPSS 0.3%
- Veröffentlicht 01.05.2026 14:16:22
- Zuletzt bearbeitet 01.05.2026 18:16:16
A heap-based buffer overflow in the Kerberos hash parser in hashcat v7.1.2 allows an attacker to cause a denial of service or possibly execute arbitrary code via a crafted Kerberos hash file. The issue affects module_hash_decode in multiple Kerberos-...
CVE-2026-42484
- EPSS 0.44%
- Veröffentlicht 01.05.2026 14:16:22
- Zuletzt bearbeitet 01.05.2026 19:16:33
A heap-based buffer overflow in hex_to_binary in the PKZIP hash parser in hashcat v7.1.2 allows an attacker to cause a denial of service or possibly execute arbitrary code via a crafted PKZIP hash file. The issue affects modules 17200, 17210, 17220, ...