CVE-2025-5318
- EPSS 0.06%
- Published 24.06.2025 14:15:30
- Last modified 22.09.2025 20:15:39
A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect comparison check that permits the function to access memory beyond the valid handle list and t...
CVE-2025-6170
- EPSS 0.02%
- Published 16.06.2025 15:24:05
- Last modified 12.08.2025 13:04:06
A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow...
CVE-2025-5914
- EPSS 0.04%
- Published 09.06.2025 19:53:48
- Last modified 23.09.2025 20:15:33
A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free ...
- EPSS 0.02%
- Published 09.06.2025 19:49:13
- Last modified 15.08.2025 18:16:42
A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes for file names. This can lead to a 1-byte write overflow. While seemingly small, such an overflow can...
CVE-2025-5918
- EPSS 0.02%
- Published 09.06.2025 19:49:13
- Last modified 15.08.2025 18:35:04
A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences,...
CVE-2025-5916
- EPSS 0.02%
- Published 09.06.2025 19:49:07
- Last modified 15.08.2025 18:12:06
A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content bytes. An attacker could craft a...
CVE-2025-5915
- EPSS 0.01%
- Published 09.06.2025 19:49:02
- Last modified 25.08.2025 02:28:51
A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may attempt to r...
CVE-2025-47711
- EPSS 0.06%
- Published 09.06.2025 06:03:47
- Last modified 26.08.2025 16:26:35
There's a flaw in the nbdkit server when handling responses from its plugins regarding the status of data blocks. If a client makes a specific request for a very large data range, and a plugin responds with an even larger single block, the nbdkit ser...
CVE-2025-4598
- EPSS 0.05%
- Published 30.05.2025 13:13:26
- Last modified 27.08.2025 17:16:21
A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, suc...
CVE-2025-3891
- EPSS 0.96%
- Published 29.04.2025 11:56:50
- Last modified 28.07.2025 14:15:27
A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes c...