CVE-2026-56211
- EPSS 0.45%
- Veröffentlicht 19.06.2026 16:28:33
- Zuletzt bearbeitet 06.10.2026 03:17:05
A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. Insufficient bounds validation in the AV1 encoder's SVC (Scalable Video Coding) layer ID control allows an attacker to supply crafted video frame pixel...
CVE-2026-56208
- EPSS 0.35%
- Veröffentlicht 19.06.2026 16:28:26
- Zuletzt bearbeitet 06.10.2026 03:17:03
A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_fram...
CVE-2026-56209
- EPSS 0.33%
- Veröffentlicht 19.06.2026 16:28:26
- Zuletzt bearbeitet 06.10.2026 03:17:04
An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows an attacker to inject an arbitrary pointer into the cycli...
CVE-2026-12515
- EPSS 0.22%
- Veröffentlicht 17.06.2026 15:34:00
- Zuletzt bearbeitet 04.08.2026 22:17:13
A flaw was found in Katello's of Red Hat Satellite. A content upload functionality where insufficient authorization checks in the ContentUploadsController allowed users with the edit_products permission to query content information for repositories o...
CVE-2026-42055
- EPSS 4.02%
- Veröffentlicht 17.06.2026 14:04:32
- Zuletzt bearbeitet 14.09.2026 13:18:34
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_in...
CVE-2026-4367
- EPSS 0.13%
- Veröffentlicht 16.06.2026 16:50:15
- Zuletzt bearbeitet 28.07.2026 10:16:48
A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `xpmNextWord()` function by processing a specially crafted or very small XPM (X PixMap) image file. This improper validation of file...
CVE-2026-42014
- EPSS 0.15%
- Veröffentlicht 16.06.2026 00:49:15
- Zuletzt bearbeitet 02.10.2026 03:16:46
A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when an attacker attempts to change the PIN with a NULL old PIN for a token th...
- EPSS 0.26%
- Veröffentlicht 11.06.2026 09:49:07
- Zuletzt bearbeitet 31.08.2026 18:17:12
An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or ...
CVE-2026-6893
- EPSS 1.09%
- Veröffentlicht 10.06.2026 19:49:27
- Zuletzt bearbeitet 02.10.2026 00:17:03
A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DH...
CVE-2026-5419
- EPSS 0.38%
- Veröffentlicht 01.06.2026 19:26:56
- Zuletzt bearbeitet 02.10.2026 03:16:50
A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timi...