CVE-2026-9256
- EPSS 9.96%
- Veröffentlicht 22.05.2026 14:11:41
- Zuletzt bearbeitet 25.08.2026 13:19:33
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for ex...
CVE-2026-9149
- EPSS 0.31%
- Veröffentlicht 20.05.2026 23:34:56
- Zuletzt bearbeitet 01.09.2026 12:17:49
A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a ...
CVE-2026-9150
- EPSS 0.41%
- Veröffentlicht 20.05.2026 23:16:36
- Zuletzt bearbeitet 01.09.2026 12:17:50
A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA51...
CVE-2026-9064
- EPSS 0.82%
- Veröffentlicht 20.05.2026 09:00:42
- Zuletzt bearbeitet 21.08.2026 12:16:37
A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request c...
CVE-2026-42009
- EPSS 1.34%
- Veröffentlicht 18.05.2026 12:44:45
- Zuletzt bearbeitet 08.10.2026 21:18:00
A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle...
CVE-2026-42010
- EPSS 1.05%
- Veröffentlicht 07.05.2026 12:16:17
- Zuletzt bearbeitet 08.10.2026 21:18:00
A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted...
CVE-2026-34000
- EPSS 0.49%
- Veröffentlicht 05.05.2026 16:16:11
- Zuletzt bearbeitet 08.06.2026 05:16:30
A flaw was found in the X.Org X server. This out-of-bounds read vulnerability in the XKB geometry processing, specifically within the `CheckSetGeom()` and `XkbAddGeomKeyAlias` functions, allows an attacker to read uninitialized or out-of-bounds memor...
CVE-2026-34002
- EPSS 0.49%
- Veröffentlicht 05.05.2026 16:16:11
- Zuletzt bearbeitet 08.06.2026 05:16:31
A flaw was found in the X.Org X server. This vulnerability, an out-of-bounds read, affects the XKB (X Keyboard Extension) modifier map handling. An attacker with access to the X11 server can exploit this by sending a malformed request, which causes t...
CVE-2026-34956
- EPSS 0.41%
- Veröffentlicht 05.05.2026 16:16:11
- Zuletzt bearbeitet 01.09.2026 13:18:58
A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the userspace datapath, a remote attacker can send a specially crafted FTP stream with an EPASV command exceeding 255 characters. This heap...
CVE-2026-33845
- EPSS 0.81%
- Veröffentlicht 30.04.2026 17:41:34
- Zuletzt bearbeitet 08.10.2026 21:17:58
A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause inform...