CVE-2026-3832
- EPSS 0.72%
- Veröffentlicht 30.04.2026 17:41:28
- Zuletzt bearbeitet 29.09.2026 01:16:47
A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP...
CVE-2026-3833
- EPSS 0.57%
- Veröffentlicht 30.04.2026 17:37:05
- Zuletzt bearbeitet 09.10.2026 00:17:08
A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees...
CVE-2026-6732
- EPSS 0.63%
- Veröffentlicht 23.04.2026 22:19:34
- Zuletzt bearbeitet 31.08.2026 12:17:56
A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a malicious d...
CVE-2026-2708
- EPSS 0.32%
- Veröffentlicht 23.04.2026 21:51:23
- Zuletzt bearbeitet 04.05.2026 18:28:46
A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_common() function in libsoup/soup-message-headers.c unconditionally appends each header value without validating for duplicate or confl...
CVE-2026-6846
- EPSS 0.17%
- Veröffentlicht 22.04.2026 08:37:14
- Zuletzt bearbeitet 01.09.2026 12:17:45
A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious fi...
CVE-2026-6844
- EPSS 0.1%
- Veröffentlicht 22.04.2026 08:37:09
- Zuletzt bearbeitet 01.09.2026 12:17:44
A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource ex...
CVE-2026-6843
- EPSS 0.11%
- Veröffentlicht 22.04.2026 08:30:04
- Zuletzt bearbeitet 01.09.2026 12:17:44
A flaw was found in nano. A local user could exploit a format string vulnerability in the `statusline()` function. By creating a directory with a name containing `printf` specifiers, the application attempts to display this name, leading to a segment...
- EPSS 99.91%
- Veröffentlicht 22.04.2026 08:15:10
- Zuletzt bearbeitet 08.09.2026 15:13:07
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-pl...
- EPSS 0.15%
- Veröffentlicht 22.04.2026 07:54:19
- Zuletzt bearbeitet 01.09.2026 12:17:45
A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. T...
CVE-2026-41082
- EPSS 0.21%
- Veröffentlicht 16.04.2026 17:32:40
- Zuletzt bearbeitet 15.07.2026 02:21:12
In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.