CVE-2025-26601
- EPSS 0.03%
- Veröffentlicht 25.02.2025 16:15:39
- Zuletzt bearbeitet 06.04.2026 13:17:17
A use-after-free flaw was found in X.Org and Xwayland. When changing an alarm, the values of the change mask are evaluated one after the other, changing the trigger values as requested, and eventually, SyncInitTrigger() is called. If one of the chang...
CVE-2025-26594
- EPSS 0.03%
- Veröffentlicht 25.02.2025 16:15:38
- Zuletzt bearbeitet 06.04.2026 13:17:13
A use-after-free flaw was found in X.Org and Xwayland. The root cursor is referenced in the X server as a global variable. If a client frees the root cursor, the internal reference points to freed memory and causes a use-after-free.
CVE-2025-26595
- EPSS 0.03%
- Veröffentlicht 25.02.2025 16:15:38
- Zuletzt bearbeitet 06.04.2026 13:17:15
A buffer overflow flaw was found in X.Org and Xwayland. The code in XkbVModMaskText() allocates a fixed-sized buffer on the stack and copies the names of the virtual modifiers to that buffer. The code fails to check the bounds of the buffer and would...
CVE-2025-26596
- EPSS 0.03%
- Veröffentlicht 25.02.2025 16:15:38
- Zuletzt bearbeitet 06.04.2026 13:17:15
A heap overflow flaw was found in X.Org and Xwayland. The computation of the length in XkbSizeKeySyms() differs from what is written in XkbWriteKeySyms(), which may lead to a heap-based buffer overflow.
CVE-2025-26597
- EPSS 0.03%
- Veröffentlicht 25.02.2025 16:15:38
- Zuletzt bearbeitet 06.04.2026 13:17:15
A buffer overflow flaw was found in X.Org and Xwayland. If XkbChangeTypesOfKey() is called with a 0 group, it will resize the key symbols table to 0 but leave the key actions unchanged. If the same function is later called with a non-zero value of gr...
CVE-2025-26598
- EPSS 0.04%
- Veröffentlicht 25.02.2025 16:15:38
- Zuletzt bearbeitet 06.04.2026 13:17:16
An out-of-bounds write flaw was found in X.Org and Xwayland. The function GetBarrierDevice() searches for the pointer device based on its device ID and returns the matching value, or supposedly NULL, if no match was found. However, the code will retu...
CVE-2024-45777
- EPSS 0.02%
- Veröffentlicht 19.02.2025 18:15:23
- Zuletzt bearbeitet 11.11.2025 17:15:37
A flaw was found in grub2. The calculation of the translation buffer when reading a language .mo file in grub_gettext_getstr_from_position() may overflow, leading to a Out-of-bound write. This issue can be leveraged by an attacker to overwrite grub2'...
CVE-2025-26465
- EPSS 61.22%
- Veröffentlicht 18.02.2025 19:15:29
- Zuletzt bearbeitet 12.05.2026 13:16:40
A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in spec...
CVE-2024-12084
- EPSS 3.46%
- Veröffentlicht 15.01.2025 15:15:10
- Zuletzt bearbeitet 03.11.2025 22:16:38
A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacker can write...
CVE-2024-12085
- EPSS 19.14%
- Veröffentlicht 14.01.2025 18:15:25
- Zuletzt bearbeitet 14.04.2026 22:16:24
A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of un...