CVE-2025-9784
- EPSS 0.22%
- Veröffentlicht 02.09.2025 13:37:59
- Zuletzt bearbeitet 24.09.2025 14:15:52
A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload b...
CVE-2025-8283
- EPSS 0.04%
- Veröffentlicht 28.07.2025 18:16:07
- Zuletzt bearbeitet 11.08.2025 19:03:36
A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When creating a co...
CVE-2025-7519
- EPSS 0.02%
- Veröffentlicht 14.07.2025 13:35:21
- Zuletzt bearbeitet 11.08.2025 19:20:21
A flaw was found in polkit. When processing an XML policy with 32 or more nested elements in depth, an out-of-bounds write can be triggered. This issue can lead to a crash or other unexpected behavior, and arbitrary code execution is not discarded. T...
CVE-2025-7424
- EPSS 0.06%
- Veröffentlicht 10.07.2025 14:05:41
- Zuletzt bearbeitet 27.08.2025 18:00:52
A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which can lead to type confusion during XML transformations. This vulnerability allows an attacker to crash the application or corrupt m...
CVE-2025-32990
- EPSS 0.1%
- Veröffentlicht 10.07.2025 09:41:46
- Zuletzt bearbeitet 06.10.2025 12:15:33
A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL point...
CVE-2025-32989
- EPSS 0.03%
- Veröffentlicht 10.07.2025 08:05:26
- Zuletzt bearbeitet 06.10.2025 12:15:33
A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transparency (CT) Signed Certificate Timestamp (SCT) extension during X.509 certificate parsing. This flaw allows a malicious user to create a certificate cont...
CVE-2025-32988
- EPSS 0.1%
- Veröffentlicht 10.07.2025 08:04:57
- Zuletzt bearbeitet 06.10.2025 12:15:33
A flaw was found in GnuTLS. A double-free vulnerability exists in GnuTLS due to incorrect ownership handling in the export logic of Subject Alternative Name (SAN) entries containing an otherName. If the type-id OID is invalid or malformed, GnuTLS wil...
CVE-2025-5351
- EPSS 0.04%
- Veröffentlicht 04.07.2025 08:16:47
- Zuletzt bearbeitet 22.08.2025 13:50:58
A flaw was found in the key export functionality of libssh. The issue occurs in the internal function responsible for converting cryptographic keys into serialized formats. During error handling, a memory structure is freed but not cleared, leading t...
CVE-2025-5372
- EPSS 0.06%
- Veröffentlicht 04.07.2025 06:01:27
- Zuletzt bearbeitet 22.08.2025 14:01:21
A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL uses 0 to indicate failure and li...
CVE-2025-32463
- EPSS 23.61%
- Veröffentlicht 30.06.2025 00:00:00
- Zuletzt bearbeitet 30.09.2025 13:30:30
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.