CVE-2026-52755
- EPSS 0.22%
- Veröffentlicht 10.06.2026 12:41:11
- Zuletzt bearbeitet 14.07.2026 22:17:14
Ghidra before 12.0.4 contains a path traversal vulnerability in the theme import functionality that allows attackers to write files outside the intended theme directory. Attackers can craft malicious theme ZIP files with traversal sequences in filena...
CVE-2026-52754
- EPSS 0.25%
- Veröffentlicht 10.06.2026 12:40:46
- Zuletzt bearbeitet 14.07.2026 22:17:13
Ghidra before 12.1 contains an authentication bypass vulnerability in PKIAuthenticationModule.authenticate() that allows any user with a valid CA-signed certificate to impersonate other users by presenting their public certificate with a null signatu...
CVE-2026-52753
- EPSS 0.15%
- Veröffentlicht 10.06.2026 12:40:22
- Zuletzt bearbeitet 14.07.2026 22:17:13
Ghidra before 12.0.3 contains an out-of-memory vulnerability in the rust_demangle function that allocates unbounded output buffers without size limits. Attackers can craft malicious Rust symbol names in binaries to trigger exponential memory allocati...
CVE-2026-52752
- EPSS 0.22%
- Veröffentlicht 10.06.2026 12:39:59
- Zuletzt bearbeitet 14.07.2026 22:17:13
Ghidra before 12.0.2 contains a path traversal vulnerability in the extension installer that fails to validate ZIP entry names during extraction. Attackers can craft malicious extensions with traversal sequences like ../ in filenames to write arbitra...
CVE-2026-52751
- EPSS 0.71%
- Veröffentlicht 10.06.2026 12:39:34
- Zuletzt bearbeitet 14.07.2026 22:17:13
Ghidra before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RMI connection code that allows unauthenticated remote code execution. Attackers can craft a malicious project file with a ghidra:// URL that, when open...
CVE-2026-52750
- EPSS 0.5%
- Veröffentlicht 10.06.2026 12:39:03
- Zuletzt bearbeitet 14.07.2026 22:17:13
Ghidra before 12.1 contains a command injection vulnerability in URL annotation handling on Windows where cmd.exe metacharacters are not properly escaped. Attackers can execute arbitrary commands under the Ghidra user's privileges by embedding malici...
CVE-2026-49498
- EPSS 0.26%
- Veröffentlicht 10.06.2026 12:38:34
- Zuletzt bearbeitet 14.07.2026 22:17:11
Ghidra 11.0 before 12.1 contains a SQL injection vulnerability in the changePassword() method of PostgresFunctionDatabase that fails to escape double quotes in usernames interpolated into ALTER ROLE statements. Authenticated attackers can inject SQL ...
CVE-2026-49497
- EPSS 0.19%
- Veröffentlicht 10.06.2026 12:37:59
- Zuletzt bearbeitet 14.07.2026 22:17:11
Ghidra before 12.1 contains a path traversal vulnerability in SameDirDebugInfoProvider that fails to validate filenames from ELF binary .gnu_debuglink sections before constructing file paths. Attackers can craft malicious ELF binaries with traversal ...
CVE-2026-49496
- EPSS 0.17%
- Veröffentlicht 10.06.2026 12:37:30
- Zuletzt bearbeitet 14.07.2026 22:17:11
Ghidra before 12.1 contains a heap-use-after-free vulnerability in SleighBuilder::generatePointerAdd caused by iterator invalidation when PcodeCacher::allocateInstruction reallocates the issued vector. Attackers can trigger memory corruption by decom...
CVE-2026-49495
- EPSS 0.15%
- Veröffentlicht 10.06.2026 12:36:43
- Zuletzt bearbeitet 14.07.2026 22:17:10
Ghidra 10.2 before 12.1 contains an uncontrolled resource consumption vulnerability in ExportTrie.parseTrie() that lacks cycle detection when traversing Mach-O binary export tries. A crafted Mach-O binary with circular references in the export trie c...