CVE-2026-1767
- EPSS 0.25%
- Veröffentlicht 16.06.2026 00:34:48
- Zuletzt bearbeitet 16.06.2026 20:29:22
A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component. A remote attacker could exploit this heap buffer overflow vulnerability by providing a specially crafted MP3 file containing...
CVE-2026-1766
- EPSS 0.16%
- Veröffentlicht 16.06.2026 00:34:39
- Zuletzt bearbeitet 16.06.2026 20:27:50
A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracker-extract-mp3 component. This heap buffer overflow vulnerability occurs when processing specially crafted MP3 files containing mal...
CVE-2026-54231
- EPSS 0.13%
- Veröffentlicht 13.06.2026 02:34:37
- Zuletzt bearbeitet 21.09.2026 06:17:01
A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal for log entries matching the crashed process and writes the results to files in the dump directory wi...
CVE-2026-54230
- EPSS 0.14%
- Veröffentlicht 13.06.2026 02:34:35
- Zuletzt bearbeitet 21.09.2026 06:17:01
A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink, the shell pr...
CVE-2026-44172
- EPSS 0.59%
- Veröffentlicht 12.06.2026 17:34:04
- Zuletzt bearbeitet 17.09.2026 12:18:20
MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text protocol and bi...
CVE-2026-11774
- EPSS 0.8%
- Veröffentlicht 11.06.2026 17:54:34
- Zuletzt bearbeitet 15.07.2026 02:18:03
An integer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), adding sizeof(uint32_t) to a crafted SASL packet length prefix of 0xFFFFFFFC causes unsigned wraparound to zero, bypassing the ...
CVE-2026-46625
- EPSS 0.67%
- Veröffentlicht 10.06.2026 21:18:05
- Zuletzt bearbeitet 09.09.2026 13:20:18
JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version 3.0.7, js-cookie's internal assign() helper copies properties with for...in + plain assignment. When the source object is produced by JSON.parse, the JSON objec...
CVE-2025-71319
- EPSS 0.73%
- Veröffentlicht 09.06.2026 19:57:16
- Zuletzt bearbeitet 24.07.2026 20:19:12
image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attacke...
CVE-2026-11790
- EPSS 0.29%
- Veröffentlicht 09.06.2026 13:09:29
- Zuletzt bearbeitet 23.07.2026 08:10:00
A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plugin does not enforce an upper bound on the iteration count extracted from stored password hashes. A privileged attacker who can modify a user's password hash can cause ex...
CVE-2026-11789
- EPSS 0.28%
- Veröffentlicht 09.06.2026 13:02:59
- Zuletzt bearbeitet 23.07.2026 08:10:00
A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when computing salt length from a crafted password hash shorter than 16 bytes, causing a buffer over-read that crashes the LDAP server duri...