Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · netapp

netapp

· 184 Critical

Total CVEs

2,509

Critical

184

Products

371

Search All CVEs →

2,509

Products (371)

oncommand insight971 CVEsactive iq unified manager848 CVEsoncommand workflow automation743 CVEssnapcenter575 CVEscloud backup349 CVEsh500s316 CVEsh700s316 CVEsh410s315 CVEsh300s314 CVEsh700s firmware290 CVEsh300s firmware289 CVEsh500s firmware289 CVEsh410s firmware289 CVEsh410c250 CVEse-series santricity os controller242 CVEsh410c firmware237 CVEssteelstore cloud integrated storage211 CVEssolidfire194 CVEsclustered data ontap190 CVEshci management node182 CVEssnapmanager180 CVEsontap select deploy administration utility179 CVEsoncommand unified manager169 CVEshci compute node157 CVEsh700e151 CVEsh300e150 CVEsh500e150 CVEsh700e firmware149 CVEsh500e firmware148 CVEsh300e firmware148 CVEse-series santricity storage manager140 CVEsstorage automation store113 CVEssolidfire \& hci management node103 CVEselement software100 CVEse-series santricity web services99 CVEssolidfire baseboard management controller88 CVEsoncommand balance83 CVEssantricity unified manager77 CVEs7-mode transition tool75 CVEsoncommand performance manager73 CVEsstoragegrid72 CVEssolidfire baseboard management controller firmware71 CVEsvirtual storage console70 CVEsvasa provider for clustered data ontap69 CVEsplug-in for symantec netbackup69 CVEsoncommand shift64 CVEsstorage replication adapter for clustered data ontap63 CVEsh610s63 CVEsh610s firmware62 CVEsdata availability services61 CVEse-series performance analyzer61 CVEscloud secure agent57 CVEsbootstrap os55 CVEscloud insights acquisition unit53 CVEssolidfire\, enterprise sds \& hci storage node43 CVEsdata ontap42 CVEssnap creator framework42 CVEsh610c39 CVEshci storage node39 CVEsh610c firmware38 CVEsh615c37 CVEsh615c firmware36 CVEse-series santricity web services proxy35 CVEshci compute node firmware34 CVEshci baseboard management controller34 CVEsa700s32 CVEsa700s firmware32 CVEse-series santricity unified manager30 CVEsservice level manager29 CVEsontap tools29 CVEse-series santricity management plug-ins28 CVEsmanagement services for element software27 CVEsoncommand system manager27 CVEssantricity cloud connector27 CVEshci bootstrap os27 CVEssolidfire \& hci storage node26 CVEsontap24 CVEssantricity storage plugin23 CVEsdata ontap edge23 CVEsclustered data ontap antivirus connector23 CVEscloud insights storage workload security agent23 CVEssnapcenter server23 CVEscn161022 CVEsa25022 CVEsfas\/aff bios22 CVEscn1610 firmware22 CVEshci compute node bios21 CVEsa250 firmware21 CVEsaff a400 firmware21 CVEsaff a40021 CVEscloud manager19 CVEssmi-s provider19 CVEsoncommand api services19 CVEsaff a700s19 CVEsaff a700s firmware18 CVEssnapdrive18 CVEssnapprotect18 CVEsa40017 CVEsmanagement services for netapp hci17 CVEsaff baseboard management controller17 CVEsa400 firmware17 CVEs830016 CVEs8700 firmware16 CVEsmanagement services for element software and netapp hci16 CVEs870016 CVEssolidfire bios16 CVEs8300 firmware16 CVEshci16 CVEsmanageability software development kit15 CVEsactive iq performance analytics services15 CVEssantricity smi-s provider14 CVEsaff 500f firmware14 CVEsaff 500f14 CVEsdata infrastructure insights storage workload security agent14 CVEs500f14 CVEsfas\/aff baseboard management controller14 CVEshci storage node bios14 CVEsservice processor13 CVEs500f firmware13 CVEsaff 830012 CVEsbluexp12 CVEsfas 870012 CVEsfas 830012 CVEsaff 8700 firmware12 CVEsaff 870012 CVEsaff 8300 firmware12 CVEsaff a25011 CVEsfas bios11 CVEsbrocade san navigator11 CVEsvasa provider11 CVEstrident11 CVEsoncommand unified manager core package11 CVEsfas 500f11 CVEsaff a250 firmware11 CVEsfas 500f firmware11 CVEse-series santricity management11 CVEsfas 8300 firmware11 CVEsfas 8700 firmware11 CVEscloud volumes ontap mediator10 CVEsaff bios10 CVEsfas275010 CVEsfas2750 firmware10 CVEsfas2720 firmware10 CVEsfas272010 CVEscloud insights telegraf agent10 CVEsfas8300 firmware9 CVEsa2209 CVEsa220 firmware9 CVEsa8009 CVEsa800 firmware9 CVEsc1909 CVEsc190 firmware9 CVEsdata infrastructure insights acquisition unit9 CVEselement plug-in for vcenter server9 CVEselement software management node9 CVEsfas83009 CVEsfas87009 CVEsfas8700 firmware9 CVEsfabric-attached storage a4008 CVEsfabric-attached storage a400 firmware8 CVEsontap select deploy8 CVEshci h410c firmware7 CVEshci h410c7 CVEsontap 97 CVEssantricity web services proxy7 CVEsmax data7 CVEsstorage replication adapter6 CVEsstoragegrid webscale6 CVEssteelstore6 CVEsa3206 CVEsa320 firmware6 CVEse-series bios6 CVEsc400 firmware6 CVEsc4006 CVEshci storage node firmware5 CVEshyper converged infrastructure5 CVEshci storage nodes5 CVEsactive iq unified manager for vmware vsphere5 CVEsfas28205 CVEscloud insights telegraf5 CVEscloud insights5 CVEsc2505 CVEsontap antivirus connector5 CVEsfas2820 firmware5 CVEssnapcenter plug-in5 CVEselement software management5 CVEsc250 firmware5 CVEsa150 firmware4 CVEsc800 firmware4 CVEskubernetes monitoring operator4 CVEsc8004 CVEsa9004 CVEsa900 firmware4 CVEsactive iq4 CVEsvirtual storage console for vmware vsphere4 CVEsbeegfs csi driver4 CVEsoncommand unified manager for clustered data ontap4 CVEsnextgen api4 CVEselement4 CVEsconverged systems advisor agent4 CVEselement os4 CVEsfas a4004 CVEsa1504 CVEssolidfire element os3 CVEsfabric-attached storage 83003 CVEsfabric-attached storage 8300 firmware3 CVEsfabric-attached storage 87003 CVEsfabric-attached storage 8700 firmware3 CVEsfas95003 CVEsfas9500 firmware3 CVEscluster data ontap3 CVEsfas a400 firmware3 CVEsfas baseboard management controller3 CVEsbrocade network advisor3 CVEsbrocade fabric operating system3 CVEsastra trident3 CVEsastra control center3 CVEsaltavault3 CVEsall flash fabric-attached storage a4003 CVEsall flash fabric-attached storage 87003 CVEshci h610s3 CVEshci h610s firmware3 CVEsall flash fabric-attached storage 83003 CVEsaff c190 firmware3 CVEsaff c1903 CVEsmetrocluster tiebreaker3 CVEsaff a220 firmware3 CVEsaff a2203 CVEsa90 firmware3 CVEsa903 CVEsa70 firmware3 CVEsa703 CVEsa1k firmware3 CVEsa1k3 CVEssolidfire element os management node3 CVEssolidfire enterprise sds3 CVEsstorage replication adapter for clustered data ontap for vmware vsphere3 CVEsstorage services connector3 CVEshci h610c2 CVEsaff a3202 CVEsaff a300 firmware2 CVEshci h610c firmware2 CVEswindows host utilities2 CVEsontap mediator2 CVEsfas baseboard management controller a2202 CVEsaff a3002 CVEs9500 firmware2 CVEsontap system manager2 CVEsstoragegrid webscale nas bridge2 CVEssymantec netbackup2 CVEsfas baseboard management controller a3202 CVEsaff a200 firmware2 CVEsaff a2002 CVEshost agent2 CVEsfas baseboard management controller c1902 CVEshci h615c2 CVEsfas8200 firmware2 CVEsfas baseboard management controller a8002 CVEsfas82002 CVEsfas500f firmware2 CVEsbrocade fabric operating system firmware2 CVEssra plugin2 CVEshci h615c firmware2 CVEsaff baseboard management controller firmware2 CVEsinventory collect tool2 CVEsbaseboard management controller firmware2 CVEsoncommand cloud manager2 CVEsall flash fabric-attached storage 8300 firmware2 CVEsbaseboard management controller2 CVEsstorage encryption2 CVEsall flash fabric-attached storage 8700 firmware2 CVEs95002 CVEsaff a700 firmware2 CVEsaff a7002 CVEssystem manager2 CVEsfas500f2 CVEsaff a320 firmware2 CVEsall flash fabric-attached storage a400 firmware2 CVEsfas9001 CVEsxcp nfs1 CVEsdata ontap operating in 7-mode1 CVEsontap select deploy utility1 CVEssan host utilities1 CVEssantricity smi-s provider firmware1 CVEssantricity storage manager1 CVEsa9500 firmware1 CVEsa95001 CVEssg1101 CVEssg11001 CVEssg1100 firmware1 CVEssg110 firmware1 CVEssg61601 CVEssg6160 firmware1 CVEssgf61121 CVEssgf6112 firmware1 CVEsfas27x0 firmware1 CVEsfas27x01 CVEssystem setup1 CVEs9000 firmware1 CVEssnapdriver1 CVEssnapgathers1 CVEsa700 firmware1 CVEsa7001 CVEs90001 CVEse-series santricity storage1 CVEsef600a1 CVEsa300 firmware1 CVEsa3001 CVEs8200 firmware1 CVEselement healthtools1 CVEsef600a firmware1 CVEsfas26001 CVEsfas baseboard management controller a800 firmware1 CVEsfas baseboard management controller c190 firmware1 CVEsfas baseboard management controller firmware1 CVEsfas baseboard management controller a400 firmware1 CVEselement plug-in1 CVEsblue xp connector1 CVEsbh500s firmware1 CVEsfas baseboard management controller a4001 CVEsbaseboard management controller a250 firmware1 CVEsbaseboard management controller 500f firmware1 CVEsastra trident autosupport1 CVEsfas2700 firmware1 CVEsfas27001 CVEsaltavault ost plug-in1 CVEsfas26x0 firmware1 CVEsall flash fabric-attached storage c8001 CVEsall flash fabric-attached storage c4001 CVEsall flash fabric-attached storage c2501 CVEsall flash fabric-attached storage a8001 CVEsall flash fabric-attached storage a9001 CVEsall flash fabric-attached storage a2501 CVEsall flash fabric-attached storage 95001 CVEsfas26x01 CVEshci h300s1 CVEshci h300s firmware1 CVEsfas baseboard management controller a320 firmware1 CVEshci h410s1 CVEshci h410s firmware1 CVEshci h500s1 CVEshci h500s firmware1 CVEsvirtual desktop service1 CVEshci h700s1 CVEshci h700s firmware1 CVEs82001 CVEsall flash fabric-attached storage 500f1 CVEsall flash fabric-attached storage 28201 CVEsfas baseboard management controller a220 firmware1 CVEshcl compute node1 CVEshcl compute node bios1 CVEsfas a250 firmware1 CVEshyper converged infrastructure compute node1 CVEsfas a2501 CVEsaffa900 firmware1 CVEsaffa9001 CVEsstoragegrid firmware1 CVEsfas9000 firmware1 CVEsfas2600 firmware1 CVEsnetapp manageability sdk1 CVEsnetapp plug-in1 CVEsnetapp xcp smb1 CVEsnext generation application programming interface1 CVEsfas90001 CVEsnfs plug-in1 CVEsaff a900 firmware1 CVEsaff a9001 CVEsaff a800 firmware1 CVEsoncommand report1 CVEsaff a8001 CVEsoncommand unified manager for 7-mode1 CVEs

Recent Vulnerabilities

View all 2,509
CVE-2026-22052MEDIUM 4.3

ONTAP versions 9.12.1 and higher with S3 NAS buckets are susceptible to an information disclosure vulnerability. Successful exploit could allow an authenticated attacker to view a listing of the contents in a directory for which they lack permission.

CVE-2026-22050MEDIUM 4.3

ONTAP versions 9.16.1 prior to 9.16.1P9 and 9.17.1 prior to 9.17.1P2 with snapshot locking enabled are susceptible to a vulnerability which could allow a privileged remote attacker to set the snapshot expiry time to none.

CVE-2025-26517MEDIUM 5.4

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are susceptible to a privilege escalation vulnerability. Successful exploit could allow an unauthorized authenticated attacker to discover Grid node names and IP addresses or modify Storage Grades.

CVE-2025-26516MEDIUM 5.3

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are susceptible to a Denial of Service vulnerability. Successful exploit could allow an unauthenticated attacker to cause a Denial of Service on the Admin node.

CVE-2025-26515HIGH 7.5

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 without Single Sign-on enabled are susceptible to a Server-Side Request Forgery (SSRF) vulnerability. Successful exploit could allow an unauthenticated attacker to change the password of any Grid Manager or Tenant Manager non-federated user.

CVE-2025-26514MEDIUM 6.4

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are susceptible to a Reflected Cross-Site Scripting vulnerability. Successful exploit could allow an attacker to view or modify configuration settings or add or modify user accounts but requires the attacker to know specific information about the target instance and then trick a privileged user into clicking a specially crafted link.

CVE-2025-26513HIGH 7.0

The installer for SAN Host Utilities for Windows versions prior to 8.0 is susceptible to a vulnerability which when successfully exploited could allow a local user to escalate their privileges.

CVE-2025-27820HIGH 7.5

A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release

CVE-2025-30722MEDIUM 5.3

Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Client accessible data as well as unauthorized update, insert or delete access to some of MySQL Client accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N).

CVE-2025-30691MEDIUM 4.8

Vulnerability in Oracle Java SE (component: Compiler). Supported versions that are affected are Oracle Java SE: 21.0.6, 24; Oracle GraalVM for JDK: 21.0.6 and 24. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE accessible data as well as unauthorized read access to a subset of Oracle Java SE accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).

CVE-2025-21583MEDIUM 4.9

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.4.0 and 9.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVE-2025-31672MEDIUM 5.3

Improper Input Validation vulnerability in Apache POI. The issue affects the parsing of OOXML format files like xlsx, docx and pptx. These file formats are basically zip files and it is possible for malicious users to add zip entries with duplicate names (including the path) in the zip. In this case, products reading the affected file could read different data because 1 of the zip entries with the duplicate name is selected over another but different products may choose a different zip entry. This issue affects Apache POI poi-ooxml before 5.4.0. poi-ooxml 5.4.0 has a check that throws an exception if zip entries with duplicate file names are found in the input file. Users are recommended to upgrade to version poi-ooxml 5.4.0, which fixes the issue. Please read https://poi.apache.org/security.html for recommendations about how to use the POI libraries securely.

CVE-2025-1861CRITICAL 9.8

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when parsing HTTP redirect in the response to an HTTP request, there is currently limit on the location value size caused by limited size of the location buffer to 1024. However as per RFC9110, the limit is recommended to be 8000. This may lead to incorrect URL truncation and redirecting to a wrong location.

CVE-2025-1736HIGH 7.3

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when user-supplied headers are sent, the insufficient validation of the end-of-line characters may prevent certain headers from being sent or lead to certain headers be misinterpreted.

CVE-2025-1734MEDIUM 5.3

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when receiving headers from HTTP server, the headers missing a colon (:) are treated as valid headers even though they are not. This may confuse applications into accepting invalid headers.

CVE-2025-26512CRITICAL 9.9

SnapCenter versions prior to 6.0.1P1 and 6.1P1 are susceptible to a vulnerability which may allow an authenticated SnapCenter Server user to become an admin user on a remote system where a SnapCenter plug-in has been installed.

CVE-2025-29768MEDIUM 4.4

Vim, a text editor, is vulnerable to potential data loss with zip.vim and special crafted zip files in versions prior to 9.1.1198. The impact is medium because a user must be made to view such an archive with Vim and then press 'x' on such a strange filename. The issue has been fixed as of Vim patch v9.1.1198.

CVE-2025-25292CRITICAL 9.8

ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential. ReXML and Nokogiri parse XML differently, the parsers can generate entirely different document structures from the same XML input. That allows an attacker to be able to execute a Signature Wrapping attack. This issue may lead to authentication bypass. Versions 1.12.4 and 1.18.0 contain a patch for the issue.

CVE-2025-25291CRITICAL 9.8

ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential. ReXML and Nokogiri parse XML differently; the parsers can generate entirely different document structures from the same XML input. That allows an attacker to be able to execute a Signature Wrapping attack. This issue may lead to authentication bypass. Versions 1.12.4 and 1.18.0 fix the issue.

CVE-2024-54085CRITICAL 9.8KEV

AMI’s SPx contains a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.

CVE-2025-24813CRITICAL 9.8KEV

Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.2, from 10.1.0-M1 through 10.1.34, from 9.0.0.M1 through 9.0.98. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. If all of the following were true, a malicious user was able to view security sensitive files and/or inject content into those files: - writes enabled for the default servlet (disabled by default) - support for partial PUT (enabled by default) - a target URL for security sensitive uploads that was a sub-directory of a target URL for public uploads - attacker knowledge of the names of security sensitive files being uploaded - the security sensitive files also being uploaded via partial PUT If all of the following were true, a malicious user was able to perform remote code execution: - writes enabled for the default servlet (disabled by default) - support for partial PUT (enabled by default) - application was using Tomcat's file based session persistence with the default storage location - application included a library that may be leveraged in a deserialization attack Users are recommended to upgrade to version 11.0.3, 10.1.35 or 9.0.99, which fixes the issue.

CVE-2025-27423HIGH 7.1

Vim is an open source, command line text editor. Vim is distributed with the tar.vim plugin, that allows easy editing and viewing of (compressed or uncompressed) tar files. Starting with 9.1.0858, the tar.vim plugin uses the ":read" ex command line to append below the cursor position, however the is not sanitized and is taken literally from the tar archive. This allows to execute shell commands via special crafted tar archives. Whether this really happens, depends on the shell being used ('shell' option, which is set using $SHELL). The issue has been fixed as of Vim patch v9.1.1164

CVE-2025-24928HIGH 7.8

libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted DTD. NOTE: this is similar to CVE-2017-9047.

CVE-2024-56171HIGH 7.8

libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used.

CVE-2025-26603MEDIUM 4.2

Vim is a greatly improved version of the good old UNIX editor Vi. Vim allows to redirect screen messages using the `:redir` ex command to register, variables and files. It also allows to show the contents of registers using the `:registers` or `:display` ex command. When redirecting the output of `:display` to a register, Vim will free the register content before storing the new content in the register. Now when redirecting the `:display` command to a register that is being displayed, Vim will free the content while shortly afterwards trying to access it, which leads to a use-after-free. Vim pre 9.1.1115 checks in the ex_display() function, that it does not try to redirect to a register while displaying this register at the same time. However this check is not complete, and so Vim does not check the `+` and `*` registers (which typically donate the X11/clipboard registers, and when a clipboard connection is not possible will fall back to use register 0 instead. In Patch 9.1.1115 Vim will therefore skip outputting to register zero when trying to redirect to the clipboard registers `*` or `+`. Users are advised to upgrade. There are no known workarounds for this vulnerability.