CVE-2026-42011
- EPSS 0.48%
- Veröffentlicht 07.05.2026 13:51:04
- Zuletzt bearbeitet 06.10.2026 01:16:35
A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when previous Certificate Authorities (CAs) only had excluded name constraints. A remote attacker could exploit this to bypass critical ...
CVE-2026-42010
- EPSS 1.05%
- Veröffentlicht 07.05.2026 12:16:17
- Zuletzt bearbeitet 02.10.2026 03:16:44
A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted...
CVE-2026-33846
- EPSS 1.26%
- Veröffentlicht 04.05.2026 09:08:51
- Zuletzt bearbeitet 02.10.2026 03:16:42
A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without vali...
CVE-2026-33845
- EPSS 0.81%
- Veröffentlicht 30.04.2026 17:41:34
- Zuletzt bearbeitet 02.10.2026 03:16:41
A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause inform...
CVE-2026-3832
- EPSS 0.72%
- Veröffentlicht 30.04.2026 17:41:28
- Zuletzt bearbeitet 29.09.2026 01:16:47
A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP...
CVE-2026-3833
- EPSS 0.57%
- Veröffentlicht 30.04.2026 17:37:05
- Zuletzt bearbeitet 02.10.2026 03:16:43
A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees...
CVE-2026-6732
- EPSS 0.63%
- Veröffentlicht 23.04.2026 22:19:34
- Zuletzt bearbeitet 31.08.2026 12:17:56
A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a malicious d...
CVE-2026-6846
- EPSS 0.17%
- Veröffentlicht 22.04.2026 08:37:14
- Zuletzt bearbeitet 01.09.2026 12:17:45
A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious fi...
CVE-2026-6844
- EPSS 0.1%
- Veröffentlicht 22.04.2026 08:37:09
- Zuletzt bearbeitet 01.09.2026 12:17:44
A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource ex...
- EPSS 0.15%
- Veröffentlicht 22.04.2026 07:54:19
- Zuletzt bearbeitet 01.09.2026 12:17:45
A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. T...