CVE-2026-0075
published 2026-06-01CVE-2026-0075: In multiple functions, there is a possible way to access the contacts database due to a SQL injection. This could lead to local escalation of privilege with no…
PriorityP429medium5.9CVSS 3.1
AVLACLPRNUINSUCLILAL
EPSS
0.09%
0.7th percentile
In multiple functions, there is a possible way to access the contacts database due to a SQL injection. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
In multiple functions, there is a possible way to access the contacts database due to a SQL injection.
ghsa_unreviewed·2026-06-02
CVE-2026-0075 [MEDIUM] CWE-89 In multiple functions, there is a possible way to access the contacts database due to a SQL injection.
In multiple functions, there is a possible way to access the contacts database due to a SQL injection. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Red Hat
vim: Vim: Information disclosure and denial of service via malformed tags file
vendor_redhat·2026-02-27·CVSS 5.3
CVE-2026-28419 [MEDIUM] CWE-124 vim: Vim: Information disclosure and denial of service via malformed tags file
vim: Vim: Information disclosure and denial of service via malformed tags file
Vim is an open source, command line text editor. Prior to version 9.2.0075, a heap-based buffer underflow exists in Vim's Emacs-style tags file parsing logic. When processing a malformed tags file where a delimiter appears at the start of a line, Vim attempts to read memory immediately preceding the allocated buffer. Version 9.2.0075 fixes the issue.
A flaw was found in Vim, an open-source command-line text editor. This vulnerability, a heap-based buffer underflow, occurs when Vim processes a specially crafted Emacs-style tags file. If a malicious file with a delimiter at the start of a line is opened, Vim attempts to read memory outside its designated area. This could lead to the disclosure of sensitive infor
No detection rules found.
No public exploits indexed.
2026-06-01
Published