CVE-2026-10118
- EPSS 0.25%
- Veröffentlicht 01.06.2026 17:16:39
- Zuletzt bearbeitet 02.10.2026 03:16:39
A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatternFill` function. This overflow leads to an undersi...
CVE-2026-42013
- EPSS 0.42%
- Veröffentlicht 26.05.2026 21:29:32
- Zuletzt bearbeitet 02.10.2026 03:16:45
A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectly fall back to checking the Common Name (CN) field. This could allow a remote attacker to bypass pro...
CVE-2026-42015
- EPSS 0.73%
- Veröffentlicht 26.05.2026 21:29:32
- Zuletzt bearbeitet 02.10.2026 03:16:46
A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allows an remote attacker to write past the internal array of a PKCS#12 bag when appending to a bag that already contains 32 elements. ...
CVE-2026-42012
- EPSS 0.35%
- Veröffentlicht 26.05.2026 21:29:26
- Zuletzt bearbeitet 02.10.2026 03:16:45
A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certi...
CVE-2026-5260
- EPSS 0.73%
- Veröffentlicht 26.05.2026 21:29:20
- Zuletzt bearbeitet 02.10.2026 03:16:50
A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerabil...
CVE-2026-48864
- EPSS 0.23%
- Veröffentlicht 26.05.2026 16:16:07
- Zuletzt bearbeitet 02.10.2026 03:16:46
A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, ...
CVE-2026-9256
- EPSS 9.96%
- Veröffentlicht 22.05.2026 14:11:41
- Zuletzt bearbeitet 25.08.2026 13:19:33
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for ex...
CVE-2026-9149
- EPSS 0.31%
- Veröffentlicht 20.05.2026 23:34:56
- Zuletzt bearbeitet 01.09.2026 12:17:49
A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a ...
CVE-2026-9150
- EPSS 0.41%
- Veröffentlicht 20.05.2026 23:16:36
- Zuletzt bearbeitet 01.09.2026 12:17:50
A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA51...
CVE-2026-42009
- EPSS 1.34%
- Veröffentlicht 18.05.2026 12:44:45
- Zuletzt bearbeitet 02.10.2026 03:16:43
A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle...