CVE-2026-58012
- EPSS 0.39%
- Veröffentlicht 30.06.2026 13:19:17
- Zuletzt bearbeitet 06.10.2026 03:17:07
A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 funct...
CVE-2026-58013
- EPSS 0.4%
- Veröffentlicht 30.06.2026 13:19:17
- Zuletzt bearbeitet 06.10.2026 03:17:08
A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerabilit...
CVE-2026-58014
- EPSS 0.33%
- Veröffentlicht 30.06.2026 13:19:17
- Zuletzt bearbeitet 09.10.2026 04:18:10
A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service...
CVE-2026-58015
- EPSS 0.52%
- Veröffentlicht 30.06.2026 13:19:17
- Zuletzt bearbeitet 09.10.2026 04:18:11
A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context contain...
CVE-2026-58016
- EPSS 0.55%
- Veröffentlicht 30.06.2026 13:19:17
- Zuletzt bearbeitet 02.10.2026 03:16:49
A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `m...
CVE-2026-12610
- EPSS 0.12%
- Veröffentlicht 30.06.2026 08:27:01
- Zuletzt bearbeitet 31.08.2026 19:16:45
A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory pointer is incorrectly handled. A local attacker could exploit this flaw by manipulating smartcard or...
CVE-2026-13757
- EPSS 0.15%
- Veröffentlicht 29.06.2026 18:44:24
- Zuletzt bearbeitet 29.09.2026 01:16:45
A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRA...
CVE-2026-13601
- EPSS 0.13%
- Veröffentlicht 29.06.2026 10:16:30
- Zuletzt bearbeitet 20.08.2026 13:16:55
A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet...
CVE-2026-13595
- EPSS 0.11%
- Veröffentlicht 29.06.2026 08:06:09
- Zuletzt bearbeitet 31.08.2026 18:17:13
A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent par...
CVE-2026-57966
- EPSS 0.13%
- Veröffentlicht 29.06.2026 07:53:45
- Zuletzt bearbeitet 08.07.2026 03:36:29
A path traversal vulnerability was found in spice-vdagent. This flaw allows a malicious or compromised SPICE host to write arbitrary files to any location on the guest operating system. This occurs because the filename provided by the SPICE host duri...