Vulnerabilità ed exploit

Netty: fix per DoS e SMTP command injection

Debian ha rilasciato aggiornamenti per Netty per correggere più vulnerabilità. Le falle includono un bug di logica in HTTP/2 (MadeYouReset) che può agevolare attacchi DoS, vulnerabilità di request smuggling e una SMTP command injection.

1 fonte · 19 mar

CVE-2026-3909

NVD KEV

Sfruttamento noto · CISA KEV

CVSS 8.8 HIGH: out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. EPSS 33% (97º percentile). Patch Microsoft: Release Notes.

Data di correzione federale CISA 27 mar

CVE-2026-3910

NVD KEV

Sfruttamento noto · CISA KEV

CVSS 8.8 HIGH: inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. EPSS 23% (96º percentile). Patch Microsoft: Release Notes.

Data di correzione federale CISA 27 mar

Cronologia

Fonti

Part of the PlainSec briefing for 2026-03-12

Every edition of this story: Netty: fix per DoS e SMTP command injection

Altro da oggi