CVE-2026-59849
- EPSS 0.24%
- Veröffentlicht 21.07.2026 14:08:15
- Zuletzt bearbeitet 22.09.2026 19:48:05
A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are missing or repeatedly rejected by a server, leading to denial of service.
CVE-2026-59842
- EPSS 0.42%
- Veröffentlicht 21.07.2026 11:08:30
- Zuletzt bearbeitet 22.09.2026 19:47:55
A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. This could allow a remote ...
CVE-2026-15370
- EPSS 0.16%
- Veröffentlicht 21.07.2026 09:16:53
- Zuletzt bearbeitet 22.09.2026 19:47:33
A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes the server to list attacker-controlled filenames, sufficiently long nam...
CVE-2026-42009
- EPSS 1.34%
- Veröffentlicht 18.05.2026 12:44:45
- Zuletzt bearbeitet 02.10.2026 03:16:43
A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle...
CVE-2026-1709
- EPSS 5.43%
- Veröffentlicht 06.02.2026 19:13:27
- Zuletzt bearbeitet 15.07.2026 02:18:19
A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authentication bypass vulnerability allows unauthenticated clients with network access to perfo...
CVE-2025-13601
- EPSS 0.33%
- Veröffentlicht 26.11.2025 14:44:22
- Zuletzt bearbeitet 31.08.2026 18:17:09
A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping),...
CVE-2025-6021
- EPSS 1.17%
- Veröffentlicht 12.06.2025 12:49:16
- Zuletzt bearbeitet 18.09.2026 18:17:04
A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.
CVE-2025-3155
- EPSS 12.59%
- Veröffentlicht 03.04.2025 14:15:46
- Zuletzt bearbeitet 29.06.2026 21:16:36
A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.
CVE-2025-2784
- EPSS 0.79%
- Veröffentlicht 03.04.2025 03:15:18
- Zuletzt bearbeitet 30.06.2026 01:16:24
A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_insight_whitespace() function. Libsoup clients may read one byte out-of-bounds in response to a crafted HTTP response by an HTTP serv...
CVE-2025-1755
- EPSS 0.14%
- Veröffentlicht 27.02.2025 16:15:39
- Zuletzt bearbeitet 09.04.2025 14:07:43
MongoDB Compass may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privileges, when a crafted file is stored in C:\node_modules\. This issue affects Mon...