CVE-2026-4424
- EPSS 0.88%
- Veröffentlicht 19.03.2026 13:50:27
- Zuletzt bearbeitet 29.09.2026 01:16:51
A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote attacker can expl...
CVE-2026-0992
- EPSS 0.43%
- Veröffentlicht 15.01.2026 14:20:24
- Zuletzt bearbeitet 01.09.2026 13:18:07
A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated <nextCatalog> elements pointing to the same downstream catalog. A remote attacker can exploit this...
CVE-2026-0989
- EPSS 0.46%
- Veröffentlicht 15.01.2026 14:20:23
- Zuletzt bearbeitet 01.09.2026 13:18:07
A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially crafted or overly complex schem...
CVE-2026-0990
- EPSS 0.82%
- Veröffentlicht 15.01.2026 14:20:06
- Zuletzt bearbeitet 01.09.2026 12:17:34
A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker could exploit th...