Comparison Overview
Core-Mark International

Core-Mark International
1500 Solana Blvd, Westlake, Texas, 76262, US
Last Update: 05/02/2026
The power of one transforms everything. One idea inspires growth. One individual changes an outcome. Since 1888, Core-Mark has been one of the largest and leading distributors to the convenience retail industry in North America. We offer a full range of products, market...

Sonepar
25 rue d’Astorg, Paris, 75008, FR
Last Update: 02/04/2026
Sonepar is an independent family-owned company standing as the world leader in B-to-B distribution of electrical equipment, solutions, and services. In 2024, Sonepar achieved sales of €32.5 billion. Present in 40 countries with a dense network of brands, the Group is le...
Compliance Ranges Comparison

Core-Mark International







Sonepar






Benchmark & Cyber Underwriting Signals
Incidents vs Wholesale Industry Avg (This Year)
No incidents recorded for Core-Mark International in 2026.
Incidents vs Wholesale Industry Avg (This Year)
No incidents recorded for Sonepar in 2026.
Incident History - Core-Mark International (X = Date, Y = Severity)
Core-Mark International cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Sonepar (X = Date, Y = Severity)
Sonepar cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Core-Mark International

Sonepar
FAQ
Latest Global CVEs
HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server.
Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references. We now reject these as malformed and curb the memory amplification vector as a result.
A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped. We now ensure that valid keyword uses are escaped and non-keyword uses are not escaped.
Improper certificate validation in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.
Authorization bypass through user-controlled key in Microsoft Bookings allows an unauthorized attacker to elevate privileges over a network.