CVE-2026-42010
- EPSS 0.16%
- Veröffentlicht 07.05.2026 12:16:17
- Zuletzt bearbeitet 14.05.2026 23:16:36
A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted...
CVE-2026-33845
- EPSS 0.05%
- Veröffentlicht 30.04.2026 17:41:34
- Zuletzt bearbeitet 05.05.2026 03:03:19
A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause inform...
CVE-2026-3832
- EPSS 0.04%
- Veröffentlicht 30.04.2026 17:41:28
- Zuletzt bearbeitet 11.05.2026 19:15:57
A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP...
CVE-2026-3833
- EPSS 0.09%
- Veröffentlicht 30.04.2026 17:37:05
- Zuletzt bearbeitet 07.05.2026 02:09:04
A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees...
CVE-2026-7309
- EPSS 0.03%
- Veröffentlicht 28.04.2026 12:33:55
- Zuletzt bearbeitet 07.05.2026 02:16:00
A flaw was found in the OpenShift Container Platform build system. A user with the `edit` ClusterRole can inject arbitrary environment variables, such as `LD_PRELOAD` or `http_proxy`, into `docker-build` containers through the `buildconfigs/instantia...
CVE-2026-6732
- EPSS 0.06%
- Veröffentlicht 23.04.2026 22:19:34
- Zuletzt bearbeitet 15.05.2026 14:36:35
A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a malicious d...
CVE-2026-31431
- EPSS 2.57%
- Veröffentlicht 22.04.2026 08:15:10
- Zuletzt bearbeitet 12.05.2026 16:15:00
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-pl...
- EPSS 0.01%
- Veröffentlicht 09.04.2026 14:49:02
- Zuletzt bearbeitet 07.05.2026 22:16:36
A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability upd...
CVE-2026-5745
- EPSS 0.02%
- Veröffentlicht 07.04.2026 14:57:31
- Zuletzt bearbeitet 03.05.2026 15:15:58
A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string (such as a bare "d" or "default" tag without...
CVE-2026-5121
- EPSS 0.09%
- Veröffentlicht 30.03.2026 08:16:18
- Zuletzt bearbeitet 14.05.2026 23:16:37
A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buff...