ZeroHour

Vulnerabilities

6 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-40393
In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted p

In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then used for alloca.

NVD description · AI analysis pending
9.8<1%
  • mesa3d mesa
CVE-2023-45931
+3 in the same advisory: …45913 …45919 …45922
Mesa 23.0.4 was discovered to contain a NULL pointer dereference in check_xshm() for the has_error state.

Mesa 23.0.4 was discovered to contain a NULL pointer dereference in check_xshm() for the has_error state. NOTE: this is disputed because there is no scenario in which the vulnerability was demonstrated.

NVD description · AI analysis pending
7.5
group max
1% PoC
  • mesa3d mesa
CVE-2019-5068
An exploitable shared memory permissions vulnerability exists in the functionality of X11 Mesa 3D Graphics Library 19.1.2.

An exploitable shared memory permissions vulnerability exists in the functionality of X11 Mesa 3D Graphics Library 19.1.2. An attacker can access the shared memory without any specific permissions to trigger this vulnerability.

NVD description · AI analysis pending
4.4<1% PoC
  • mesa3d mesa
  • mesa3d leap
  • mesa3d debian linux
  • +1 more