CVE-2025-14874
- EPSS 0.09%
- Veröffentlicht 18.12.2025 08:40:31
- Zuletzt bearbeitet 08.01.2026 03:15:43
A flaw was found in Nodemailer. This vulnerability allows a denial of service (DoS) via a crafted email address header that triggers infinite recursion in the address parser.
CVE-2025-13601
- EPSS 0.01%
- Veröffentlicht 26.11.2025 14:44:22
- Zuletzt bearbeitet 19.03.2026 06:16:24
A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping),...
CVE-2023-48795
- EPSS 66.91%
- Veröffentlicht 18.12.2023 16:15:10
- Zuletzt bearbeitet 04.11.2025 22:15:55
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client a...
CVE-2023-44487
- EPSS 94.43%
- Veröffentlicht 10.10.2023 14:15:10
- Zuletzt bearbeitet 07.11.2025 19:00:41
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CVE-2023-0056
- EPSS 0.17%
- Veröffentlicht 23.03.2023 21:15:19
- Zuletzt bearbeitet 25.02.2025 20:15:31
An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impac...
CVE-2022-3854
- EPSS 0.07%
- Veröffentlicht 06.03.2023 23:15:11
- Zuletzt bearbeitet 06.03.2025 19:15:25
A flaw was found in Ceph, relating to the URL processing on RGW backends. An attacker can exploit the URL processing by providing a null URL to crash the RGW, causing a denial of service.
CVE-2021-3979
- EPSS 0.28%
- Veröffentlicht 25.08.2022 20:15:09
- Zuletzt bearbeitet 03.11.2025 19:15:40
A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality an...
CVE-2022-0670
- EPSS 0.2%
- Veröffentlicht 25.07.2022 14:15:10
- Zuletzt bearbeitet 21.11.2024 06:39:09
A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volumes" plugin in Ceph Manager. This allows an attacker...
CVE-2022-26148
- EPSS 89.9%
- Veröffentlicht 21.03.2022 20:15:14
- Zuletzt bearbeitet 21.11.2024 06:53:31
An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source code. When the user logs in and allows the user to register, one can right click to view the source cod...
CVE-2021-4048
- EPSS 0.36%
- Veröffentlicht 08.12.2021 22:15:10
- Zuletzt bearbeitet 21.11.2024 06:36:47
An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.0, as also used in OpenBLAS before version 0.3.18. Specially crafted inputs passed to these functions could cause an application u...