CVE-2026-107161
- EPSS -
- Veröffentlicht 07.10.2026 19:29:28
- Zuletzt bearbeitet 07.10.2026 20:17:10
A heap-based buffer overflow flaw was found in Cyrus SASL. The add_to_challenge() function in the DIGEST-MD5 plugin computes the size of the buffer needed for a challenge/response field before DIGEST-MD5 quoting is applied, but does not recompute tha...
CVE-2026-105326
- EPSS 0.22%
- Veröffentlicht 05.10.2026 18:58:56
- Zuletzt bearbeitet 07.10.2026 18:17:15
An argument injection flaw was found in CUPS. When email notification is configured, the CUPS scheduler accepts printer subscription requests that supply a mailto notify-recipient-uri. The mailto notifier passes the recipient address to the configure...
CVE-2026-103242
- EPSS 0.12%
- Veröffentlicht 30.09.2026 11:50:32
- Zuletzt bearbeitet 30.09.2026 17:16:42
A heap-based buffer overflow flaw was found in rpm. RPMTAG_FILESIGNATURES in a crafted, unsigned RPM package's main header is declared with the wrong header type, causing hex2binv() to allocate a one-byte buffer and then write the tag's attacker-cont...
CVE-2026-95520
- EPSS 0.12%
- Veröffentlicht 29.09.2026 12:17:12
- Zuletzt bearbeitet 29.09.2026 21:29:07
A heap-based buffer overflow flaw was found in rpm. Parsing a symlink entry in an untrusted RPM package whose declared RPMTAG_LONGFILESIZES value is 0xFFFFFFFFFFFFFFFF causes an integer overflow in iterReadArchiveNext() that shrinks a buffer allocati...
CVE-2026-95521
- EPSS 0.58%
- Veröffentlicht 24.09.2026 13:26:56
- Zuletzt bearbeitet 24.09.2026 21:00:46
A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames contain a %() macro construct causes rpm to execute an attacker-controlled shell command via popen() while relocating the source file...
CVE-2026-95519
- EPSS 0.14%
- Veröffentlicht 24.09.2026 13:26:54
- Zuletzt bearbeitet 25.09.2026 13:17:23
A flaw was found in rpm. An attacker can supply a crafted manifest file that, when processed by a user or automation using `rpm -q -p` or similar manifest-processing flows, leads to arbitrary code execution. This occurs because manifest entries are u...
CVE-2026-88831
- EPSS 0.21%
- Veröffentlicht 23.09.2026 17:45:23
- Zuletzt bearbeitet 25.09.2026 23:16:54
BusyBox httpd IP deny rules with invalid CIDR prefix lengths fail open, leaving a parsed IP with a zeroed mask so the rule matches no clients.
CVE-2026-88832
- EPSS 0.12%
- Veröffentlicht 23.09.2026 17:05:00
- Zuletzt bearbeitet 25.09.2026 23:16:54
BusyBox romfs volume ID parsing uses unbounded strlen on attacker-controlled metadata, causing a heap buffer overflow when processing crafted filesystem images.
CVE-2026-88830
- EPSS 0.35%
- Veröffentlicht 23.09.2026 17:04:57
- Zuletzt bearbeitet 23.09.2026 20:17:20
A unit confusion in BusyBox TLS Montgomery reduction buffer allocation causes a pre-authentication heap buffer overflow when processing a crafted ClientKeyExchange message.
CVE-2026-96512
- EPSS 0.13%
- Veröffentlicht 23.09.2026 13:22:33
- Zuletzt bearbeitet 05.10.2026 11:17:01
A flaw was found in sudo. When sudoers rules use NOTBEFORE or NOTAFTER time-based access restrictions with timestamps that omit the trailing 'Z' timezone indicator, the time evaluation relies on the TZ environment variable inherited from the calling ...