CVE-2026-0989
- EPSS 0.46%
- Veröffentlicht 15.01.2026 14:20:23
- Zuletzt bearbeitet 01.09.2026 13:18:07
A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially crafted or overly complex schem...
CVE-2026-0990
- EPSS 0.82%
- Veröffentlicht 15.01.2026 14:20:06
- Zuletzt bearbeitet 01.09.2026 12:17:34
A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker could exploit th...
CVE-2025-14443
- EPSS 0.34%
- Veröffentlicht 16.12.2025 12:14:47
- Zuletzt bearbeitet 15.04.2026 00:35:42
A flaw was found in ose-openshift-apiserver. This vulnerability allows internal network enumeration, service discovery, limited information disclosure, and potential denial-of-service (DoS) through Server-Side Request Forgery (SSRF) due to missing IP...
CVE-2025-13601
- EPSS 0.33%
- Veröffentlicht 26.11.2025 14:44:22
- Zuletzt bearbeitet 31.08.2026 18:17:09
A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping),...
CVE-2025-8283
- EPSS 0.29%
- Veröffentlicht 28.07.2025 18:16:07
- Zuletzt bearbeitet 01.09.2026 13:18:05
A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When creating a co...
CVE-2025-7519
- EPSS 0.18%
- Veröffentlicht 14.07.2025 13:35:21
- Zuletzt bearbeitet 01.09.2026 12:17:32
A flaw was found in polkit. When processing an XML policy with 32 or more nested elements in depth, an out-of-bounds write can be triggered. This issue can lead to a crash or other unexpected behavior, and arbitrary code execution is not discarded. T...
CVE-2025-7424
- EPSS 1.2%
- Veröffentlicht 10.07.2025 14:05:41
- Zuletzt bearbeitet 01.09.2026 12:17:31
A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which can lead to type confusion during XML transformations. This vulnerability allows an attacker to crash the application or corrupt m...
CVE-2025-32990
- EPSS 0.72%
- Veröffentlicht 10.07.2025 09:41:46
- Zuletzt bearbeitet 01.09.2026 12:17:19
A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL point...
CVE-2025-32989
- EPSS 1.18%
- Veröffentlicht 10.07.2025 08:05:26
- Zuletzt bearbeitet 01.09.2026 12:17:18
A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transparency (CT) Signed Certificate Timestamp (SCT) extension during X.509 certificate parsing. This flaw allows a malicious user to create a certificate cont...
CVE-2025-32988
- EPSS 1.19%
- Veröffentlicht 10.07.2025 08:04:57
- Zuletzt bearbeitet 01.09.2026 12:17:18
A flaw was found in GnuTLS. A double-free vulnerability exists in GnuTLS due to incorrect ownership handling in the export logic of Subject Alternative Name (SAN) entries containing an otherName. If the type-id OID is invalid or malformed, GnuTLS wil...