CVE-2026-1584
- EPSS 1.32%
- Veröffentlicht 09.04.2026 18:16:44
- Zuletzt bearbeitet 01.09.2026 13:18:14
A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted ClientHello message with an invalid Pre-Shared Key (PSK) binder value during the TLS handshake. This can lead to a NULL point...
- EPSS 0.13%
- Veröffentlicht 07.04.2026 16:34:10
- Zuletzt bearbeitet 31.08.2026 12:17:52
A flaw was found in libssh. This vulnerability allows local man-in-the-middle attacks, security downgrades of SSH (Secure Shell) connections, and manipulation of trusted host information, posing a significant risk to the confidentiality, integrity, a...
CVE-2026-5745
- EPSS 0.16%
- Veröffentlicht 07.04.2026 14:57:31
- Zuletzt bearbeitet 01.09.2026 12:17:43
A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string (such as a bare "d" or "default" tag without...
CVE-2026-5704
- EPSS 0.37%
- Veröffentlicht 06.04.2026 15:17:27
- Zuletzt bearbeitet 22.09.2026 22:17:11
A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allo...
CVE-2026-3184
- EPSS 0.44%
- Veröffentlicht 03.04.2026 18:43:45
- Zuletzt bearbeitet 31.08.2026 12:17:55
A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a s...
CVE-2026-2625
- EPSS 0.09%
- Veröffentlicht 03.04.2026 18:38:09
- Zuletzt bearbeitet 24.07.2026 22:10:00
A flaw was found in rust-rpm-sequoia. An attacker can exploit this vulnerability by providing a specially crafted Red Hat Package Manager (RPM) file. During the RPM signature verification process, this crafted file can trigger an error in the OpenPGP...
CVE-2026-5121
- EPSS 1.07%
- Veröffentlicht 30.03.2026 08:16:18
- Zuletzt bearbeitet 29.09.2026 01:16:55
A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buff...
CVE-2026-0964
- EPSS 0.41%
- Veröffentlicht 26.03.2026 20:06:28
- Zuletzt bearbeitet 01.09.2026 12:17:33
A malicious SCP server can send unexpected paths that could make the client application override local files outside of working directory. This could be misused to create malicious executable or configuration files and make the user execute them unde...
CVE-2026-0966
- EPSS 0.58%
- Veröffentlicht 26.03.2026 20:06:28
- Zuletzt bearbeitet 01.09.2026 12:17:33
A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited remotely by an attacker during GSSAPI (Generic Security Service Application Program Interface)...
CVE-2026-2100
- EPSS 1.16%
- Veröffentlicht 26.03.2026 20:01:46
- Zuletzt bearbeitet 29.09.2026 01:16:46
A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters set to NULL. This could lead to the RPC-client attemp...