CVE-2026-42055
- EPSS 4.02%
- Veröffentlicht 17.06.2026 14:04:32
- Zuletzt bearbeitet 11.08.2026 15:12:52
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_in...
CVE-2026-4367
- EPSS 0.13%
- Veröffentlicht 16.06.2026 16:50:15
- Zuletzt bearbeitet 28.07.2026 10:16:48
A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `xpmNextWord()` function by processing a specially crafted or very small XPM (X PixMap) image file. This improper validation of file...
CVE-2026-42014
- EPSS 0.15%
- Veröffentlicht 16.06.2026 00:49:15
- Zuletzt bearbeitet 22.07.2026 16:17:20
A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when an attacker attempts to change the PIN with a NULL old PIN for a token th...
- EPSS 0.26%
- Veröffentlicht 11.06.2026 09:49:07
- Zuletzt bearbeitet 12.06.2026 15:16:24
An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or ...
CVE-2026-6893
- EPSS 1.09%
- Veröffentlicht 10.06.2026 19:49:27
- Zuletzt bearbeitet 20.08.2026 22:18:01
A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DH...
CVE-2026-5419
- EPSS 0.38%
- Veröffentlicht 01.06.2026 19:26:56
- Zuletzt bearbeitet 22.07.2026 08:10:00
A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timi...
CVE-2026-10118
- EPSS 0.25%
- Veröffentlicht 01.06.2026 17:16:39
- Zuletzt bearbeitet 21.07.2026 19:10:00
A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatternFill` function. This overflow leads to an undersi...
CVE-2026-42013
- EPSS 0.42%
- Veröffentlicht 26.05.2026 21:29:32
- Zuletzt bearbeitet 24.07.2026 11:10:00
A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectly fall back to checking the Common Name (CN) field. This could allow a remote attacker to bypass pro...
CVE-2026-42015
- EPSS 0.73%
- Veröffentlicht 26.05.2026 21:29:32
- Zuletzt bearbeitet 21.08.2026 12:16:28
A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allows an remote attacker to write past the internal array of a PKCS#12 bag when appending to a bag that already contains 32 elements. ...
CVE-2026-42012
- EPSS 0.35%
- Veröffentlicht 26.05.2026 21:29:26
- Zuletzt bearbeitet 24.07.2026 11:10:00
A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certi...