CVE-2007-2026
published 2007-04-13CVE-2007-2026: The gnu regular expression code in file 4.20 allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted document with a…
PriorityP425high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
2.09%
79.6th percentile
The gnu regular expression code in file 4.20 allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted document with a large number of line feed characters, which is not well handled by OS/2 REXX regular expressions that use wildcards, as originally reported for AMaViS.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | file | < file 4.20-6 (bookworm) | file 4.20-6 (bookworm) |
| file_project | file | >= 0 < 4.20-6 | 4.20-6 |
| file_project | file | >= 0 < 4.20-6 | 4.20-6 |
| file_project | file | >= 0 < 4.20-6 | 4.20-6 |
| file_project | file | >= 0 < 4.20-6 | 4.20-6 |
| gentoo | file | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.8HIGH
vendor_redhat8.2HIGH
vendor_debian7.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q6xr-rq9m-h889: The gnu regular expression code in file 4
ghsa_unreviewed·2022-05-01
CVE-2007-2026 [HIGH] GHSA-q6xr-rq9m-h889: The gnu regular expression code in file 4
The gnu regular expression code in file 4.20 allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted document with a large number of line feed characters, which is not well handled by OS/2 REXX regular expressions that use wildcards, as originally reported for AMaViS.
OSV
CVE-2007-2026: The gnu regular expression code in file 4
osv·2007-04-13·CVSS 7.8
CVE-2007-2026 [HIGH] CVE-2007-2026: The gnu regular expression code in file 4
The gnu regular expression code in file 4.20 allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted document with a large number of line feed characters, which is not well handled by OS/2 REXX regular expressions that use wildcards, as originally reported for AMaViS.
Red Hat
postgresql: PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory
vendor_redhat·2026-02-12·CVSS 8.2
CVE-2026-2007 [HIGH] CWE-120 postgresql: PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory
postgresql: PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory
Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string. The attacker has limited control over the byte patterns to be written, but we have not ruled out the viability of attacks that lead to privilege escalation. PostgreSQL 18.1 and 18.0 are affected.
A heap based buffer overflow has been discovered in postgresql. This heap buffer overflow is in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string. The attacker has limited control over the byte patterns to be written, but we have not ruled out the viability of attacks that lead to privilege escalation.
Mitigation: Mitigation for this issue is eit
Debian
CVE-2007-2026: file - The gnu regular expression code in file 4.20 allows context-dependent attackers ...
vendor_debian·2007·CVSS 7.8
CVE-2007-2026 [HIGH] CVE-2007-2026: file - The gnu regular expression code in file 4.20 allows context-dependent attackers ...
The gnu regular expression code in file 4.20 allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted document with a large number of line feed characters, which is not well handled by OS/2 REXX regular expressions that use wildcards, as originally reported for AMaViS.
Scope: local
bookworm: resolved (fixed in 4.20-6)
bullseye: resolved (fixed in 4.20-6)
forky: resolved (fixed in 4.20-6)
sid: resolved (fixed in 4.20-6)
trixie: resolved (fixed in 4.20-6)
Red Hat
CVE-2007-2026: The gnu regular expression code in file 4
vendor_redhat·CVSS 7.8
CVE-2007-2026 [HIGH] CVE-2007-2026: The gnu regular expression code in file 4
The gnu regular expression code in file 4.20 allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted document with a large number of line feed characters, which is not well handled by OS/2 REXX regular expressions that use wildcards, as originally reported for AMaViS.
Statement: Not vulnerable. These issues did not affect the versions of file as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5.
Citrix
Citrix Security Bulletin CTX112964
vendor_citrix·CVSS 10.0
CVE-2007-2850 [CRITICAL] Citrix Security Bulletin CTX112964
Citrix Security Bulletin CTX112964
CVE References: CVE-2007-2850, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX113543
vendor_citrix·CVSS 5.0
CVE-2007-3625 [MEDIUM] Citrix Security Bulletin CTX113543
Citrix Security Bulletin CTX113543
CVE References: CVE-2007-3625, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX113817
vendor_citrix·CVSS 7.6
CVE-2007-4017 [HIGH] Citrix Security Bulletin CTX113817
Citrix Security Bulletin CTX113817
CVE References: CVE-2007-4017, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX115281
vendor_citrix·CVSS 2.1
CVE-2007-6267 [LOW] Citrix Security Bulletin CTX115281
Citrix Security Bulletin CTX115281
CVE References: CVE-2007-6267, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX113814
vendor_citrix·CVSS 5.0
CVE-2007-0011 [MEDIUM] Citrix Security Bulletin CTX113814
Citrix Security Bulletin CTX113814
CVE References: CVE-2007-0011, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX113816
vendor_citrix·CVSS 6.8
CVE-2007-4018 [MEDIUM] Citrix Security Bulletin CTX113816
Citrix Security Bulletin CTX113816
CVE References: CVE-2007-4018, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX113815
vendor_citrix·CVSS 4.3
CVE-2007-3679 [MEDIUM] Citrix Security Bulletin CTX113815
Citrix Security Bulletin CTX113815
CVE References: CVE-2007-3679, CVE-2007-4013, CVE-2007-4016, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX112803
vendor_citrix·CVSS 5.0
CVE-2007-0011 [MEDIUM] Citrix Security Bulletin CTX112803
Citrix Security Bulletin CTX112803
CVE References: CVE-2007-0011, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX115283
vendor_citrix·CVSS 4.3
CVE-2007-6477 [MEDIUM] Citrix Security Bulletin CTX115283
Citrix Security Bulletin CTX115283
CVE References: CVE-2007-6477, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX114028
vendor_citrix·CVSS 4.3
CVE-2007-3679 [MEDIUM] Citrix Security Bulletin CTX114028
Citrix Security Bulletin CTX114028
CVE References: CVE-2007-3679, CVE-2007-4013, CVE-2007-4016, CVE-2007-4017, CVE-2007-4018, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX112589
vendor_citrix·CVSS 9.3
CVE-2007-1196 [CRITICAL] Citrix Security Bulletin CTX112589
Citrix Security Bulletin CTX112589
CVE References: CVE-2007-1196, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX111686
vendor_citrix·CVSS 7.2
CVE-2007-0444 [HIGH] Citrix Security Bulletin CTX111686
Citrix Security Bulletin CTX111686
CVE References: CVE-2007-0444, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
No detection rules found.
No public exploits indexed.
Trendmicro
Do Online Mainframes Compomise Business Processes?
blogs_trendmicro·2017-07-13
Do Online Mainframes Compomise Business Processes?
# Do Online Mainframes Compomise Business Processes?
Exposing a mainframe online, even unintentionally, can be detrimental to the security not only of the company’s crown jewels, but also their customers. This is what we found using data from Shodan, a search engine for internet-connected devices.
By: Roel Reyes, Philippe Lin, David Sancho, Morton Swimmer
2017/07/13
Read time: ( words)
Save to Folio
Legacy mainframes are still used by enterprises to handle big data transactions across a range of industries, from financial institutions, telecoms, and internet service providers (ISPs) to airlines and government agencies.
Why are they still in use? As the saying goes: “if it ain’t broke, don’t fix it”. But what if they’re not necessarily “broken”—but unsecure? Exposing a mainframe onlin
Bugzilla
CVE-2026-2007 postgresql: PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory
bugzilla·2026-02-12·CVSS 8.2
CVE-2026-2007 [HIGH] CVE-2026-2007 postgresql: PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory
CVE-2026-2007 postgresql: PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory
Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string. The attacker has limited control over the byte patterns to be written, but we have not ruled out the viability of attacks that lead to privilege escalation. PostgreSQL 18.1 and 18.0 are affected.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2026:19009 https://access.redhat.com/errata/RHSA-2026:19009
http://secunia.com/advisories/24918http://secunia.com/advisories/25394http://secunia.com/advisories/25544http://secunia.com/advisories/25578http://sourceforge.net/mailarchive/forum.php?thread_name=755AF709E5B77E6EA58479D5%40foxx.lsit.ucsb.edu&forum_name=amavis-userhttp://www.amavis.org/security/asa-2007-3.txthttp://www.gentoo.org/security/en/glsa/glsa-200704-13.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2007:114http://www.securityfocus.com/archive/1/469520/30/6420/threadedhttp://www.securityfocus.com/bid/24146http://www.vupen.com/english/advisories/2007/2071https://bugs.gentoo.org/show_bug.cgi?id=174217https://issues.rpath.com/browse/RPL-1311http://secunia.com/advisories/24918http://secunia.com/advisories/25394http://secunia.com/advisories/25544http://secunia.com/advisories/25578http://sourceforge.net/mailarchive/forum.php?thread_name=755AF709E5B77E6EA58479D5%40foxx.lsit.ucsb.edu&forum_name=amavis-userhttp://www.amavis.org/security/asa-2007-3.txthttp://www.gentoo.org/security/en/glsa/glsa-200704-13.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2007:114http://www.securityfocus.com/archive/1/469520/30/6420/threadedhttp://www.securityfocus.com/bid/24146http://www.vupen.com/english/advisories/2007/2071https://bugs.gentoo.org/show_bug.cgi?id=174217https://issues.rpath.com/browse/RPL-1311
2007-04-13
Published