CVE-2025-5915
- EPSS 0.04%
- Veröffentlicht 09.06.2025 19:49:02
- Zuletzt bearbeitet 08.01.2026 04:15:55
A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may attempt to r...
CVE-2025-4598
- EPSS 0.04%
- Veröffentlicht 30.05.2025 13:13:26
- Zuletzt bearbeitet 02.02.2026 10:16:05
A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, suc...
CVE-2025-0686
- EPSS 0.03%
- Veröffentlicht 03.03.2025 18:15:30
- Zuletzt bearbeitet 28.07.2025 17:23:26
A flaw was found in grub2. When performing a symlink lookup from a romfs filesystem, grub's romfs filesystem module uses user-controlled parameters from the filesystem geometry to determine the internal buffer size, however, it improperly checks for ...
CVE-2025-0678
- EPSS 0.04%
- Veröffentlicht 03.03.2025 17:15:14
- Zuletzt bearbeitet 25.03.2025 05:15:40
A flaw was found in grub2. When reading data from a squash4 filesystem, grub's squash4 fs module uses user-controlled parameters from the filesystem geometry to determine the internal buffer size, however, it improperly checks for integer overflows. ...
CVE-2024-45778
- EPSS 0.02%
- Veröffentlicht 03.03.2025 17:15:12
- Zuletzt bearbeitet 07.03.2025 19:45:52
A stack overflow flaw was found when reading a BFS file system. A crafted BFS filesystem may lead to an uncontrolled loop, causing grub2 to crash.
CVE-2024-45782
- EPSS 0.04%
- Veröffentlicht 03.03.2025 17:15:12
- Zuletzt bearbeitet 25.03.2025 05:15:39
A flaw was found in the HFS filesystem. When reading an HFS volume's name at grub_fs_mount(), the HFS filesystem driver performs a strcpy() using the user-provided volume name as input without properly validating the volume name's length. This issue ...
CVE-2025-26465
- EPSS 59.97%
- Veröffentlicht 18.02.2025 19:15:29
- Zuletzt bearbeitet 03.11.2025 22:18:41
A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in spec...
CVE-2025-0750
- EPSS 0.05%
- Veröffentlicht 28.01.2025 10:15:09
- Zuletzt bearbeitet 11.02.2025 12:15:34
A vulnerability was found in CRI-O. A path traversal issue in the log management functions (UnMountPodLogs and LinkContainerLogs) may allow an attacker with permissions to create and delete Pods to unmount arbitrary host paths, leading to node-level ...
CVE-2024-12085
- EPSS 19.14%
- Veröffentlicht 14.01.2025 18:15:25
- Zuletzt bearbeitet 20.11.2025 21:15:59
A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of un...
CVE-2024-12086
- EPSS 0.64%
- Veröffentlicht 14.01.2025 18:15:25
- Zuletzt bearbeitet 03.11.2025 22:16:39
A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a client to a server. During this process, the rsync server will send chec...