CVE-2026-4647
- EPSS 0.17%
- Veröffentlicht 23.03.2026 13:37:44
- Zuletzt bearbeitet 21.08.2026 13:18:10
A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not prop...
CVE-2026-4426
- EPSS 0.31%
- Veröffentlicht 19.03.2026 13:53:39
- Zuletzt bearbeitet 21.08.2026 13:18:10
A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by suppl...
CVE-2026-4424
- EPSS 0.88%
- Veröffentlicht 19.03.2026 13:50:27
- Zuletzt bearbeitet 15.07.2026 02:22:40
A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote attacker can expl...
CVE-2026-3441
- EPSS 0.18%
- Veröffentlicht 15.03.2026 00:19:07
- Zuletzt bearbeitet 21.08.2026 12:16:26
A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCO...
CVE-2026-3442
- EPSS 0.26%
- Veröffentlicht 15.03.2026 00:19:02
- Zuletzt bearbeitet 21.08.2026 23:16:24
A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious X...
CVE-2025-12801
- EPSS 0.46%
- Veröffentlicht 04.03.2026 15:25:53
- Zuletzt bearbeitet 30.06.2026 00:16:51
A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to a...
CVE-2026-0992
- EPSS 0.43%
- Veröffentlicht 15.01.2026 14:20:24
- Zuletzt bearbeitet 21.08.2026 13:16:47
A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated <nextCatalog> elements pointing to the same downstream catalog. A remote attacker can exploit this...
CVE-2026-0989
- EPSS 0.46%
- Veröffentlicht 15.01.2026 14:20:23
- Zuletzt bearbeitet 21.08.2026 13:16:47
A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially crafted or overly complex schem...
CVE-2026-0990
- EPSS 0.82%
- Veröffentlicht 15.01.2026 14:20:06
- Zuletzt bearbeitet 21.08.2026 12:16:21
A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker could exploit th...
CVE-2025-14443
- EPSS 0.34%
- Veröffentlicht 16.12.2025 12:14:47
- Zuletzt bearbeitet 15.04.2026 00:35:42
A flaw was found in ose-openshift-apiserver. This vulnerability allows internal network enumeration, service discovery, limited information disclosure, and potential denial-of-service (DoS) through Server-Side Request Forgery (SSRF) due to missing IP...