CVE-2026-42011
- EPSS 0.03%
- Veröffentlicht 07.05.2026 13:51:04
- Zuletzt bearbeitet 14.05.2026 23:16:36
A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when previous Certificate Authorities (CAs) only had excluded name constraints. A remote attacker could exploit this to bypass critical ...
CVE-2026-42010
- EPSS 0.16%
- Veröffentlicht 07.05.2026 12:16:17
- Zuletzt bearbeitet 14.05.2026 23:16:36
A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted...
CVE-2026-33846
- EPSS 0.08%
- Veröffentlicht 04.05.2026 09:08:51
- Zuletzt bearbeitet 04.05.2026 15:22:52
A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without vali...
CVE-2026-33845
- EPSS 0.05%
- Veröffentlicht 30.04.2026 17:41:34
- Zuletzt bearbeitet 05.05.2026 03:03:19
A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause inform...
CVE-2026-3832
- EPSS 0.04%
- Veröffentlicht 30.04.2026 17:41:28
- Zuletzt bearbeitet 11.05.2026 19:15:57
A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP...
CVE-2026-3833
- EPSS 0.09%
- Veröffentlicht 30.04.2026 17:37:05
- Zuletzt bearbeitet 07.05.2026 02:09:04
A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees...
CVE-2026-6732
- EPSS 0.06%
- Veröffentlicht 23.04.2026 22:19:34
- Zuletzt bearbeitet 15.05.2026 14:36:35
A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a malicious d...
CVE-2026-1584
- EPSS 0.11%
- Veröffentlicht 09.04.2026 18:16:44
- Zuletzt bearbeitet 03.05.2026 14:16:26
A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted ClientHello message with an invalid Pre-Shared Key (PSK) binder value during the TLS handshake. This can lead to a NULL point...
- EPSS 0.01%
- Veröffentlicht 07.04.2026 16:34:10
- Zuletzt bearbeitet 29.04.2026 12:11:05
A flaw was found in libssh. This vulnerability allows local man-in-the-middle attacks, security downgrades of SSH (Secure Shell) connections, and manipulation of trusted host information, posing a significant risk to the confidentiality, integrity, a...
CVE-2026-5745
- EPSS 0.02%
- Veröffentlicht 07.04.2026 14:57:31
- Zuletzt bearbeitet 03.05.2026 15:15:58
A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string (such as a bare "d" or "default" tag without...