CVE-2025-5351
- EPSS 0.1%
- Veröffentlicht 04.07.2025 08:16:47
- Zuletzt bearbeitet 08.01.2026 04:15:54
A flaw was found in the key export functionality of libssh. The issue occurs in the internal function responsible for converting cryptographic keys into serialized formats. During error handling, a memory structure is freed but not cleared, leading t...
CVE-2025-5372
- EPSS 0.09%
- Veröffentlicht 04.07.2025 06:01:27
- Zuletzt bearbeitet 10.12.2025 19:16:14
A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL uses 0 to indicate failure and li...
CVE-2025-32463
- EPSS 21.11%
- Veröffentlicht 30.06.2025 00:00:00
- Zuletzt bearbeitet 05.11.2025 19:26:48
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.
CVE-2025-5318
- EPSS 0.11%
- Veröffentlicht 24.06.2025 14:15:30
- Zuletzt bearbeitet 27.02.2026 17:16:24
A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect comparison check that permits the function to access memory beyond the valid handle list and t...
CVE-2025-6170
- EPSS 0.03%
- Veröffentlicht 16.06.2025 15:24:05
- Zuletzt bearbeitet 03.11.2025 20:19:18
A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow...
CVE-2025-6021
- EPSS 0.61%
- Veröffentlicht 12.06.2025 12:49:16
- Zuletzt bearbeitet 20.03.2026 19:16:13
A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.
CVE-2025-5914
- EPSS 0.03%
- Veröffentlicht 09.06.2025 19:53:48
- Zuletzt bearbeitet 05.02.2026 20:15:52
A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free ...
- EPSS 0.04%
- Veröffentlicht 09.06.2025 19:49:13
- Zuletzt bearbeitet 12.12.2025 01:15:46
A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes for file names. This can lead to a 1-byte write overflow. While seemingly small, such an overflow can...
CVE-2025-5918
- EPSS 0.04%
- Veröffentlicht 09.06.2025 19:49:13
- Zuletzt bearbeitet 15.08.2025 18:35:04
A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences,...
CVE-2025-5916
- EPSS 0.04%
- Veröffentlicht 09.06.2025 19:49:07
- Zuletzt bearbeitet 12.12.2025 01:15:46
A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content bytes. An attacker could craft a...