CVE-2026-2625
- EPSS 0.01%
- Veröffentlicht 03.04.2026 18:38:09
- Zuletzt bearbeitet 01.05.2026 21:00:31
A flaw was found in rust-rpm-sequoia. An attacker can exploit this vulnerability by providing a specially crafted Red Hat Package Manager (RPM) file. During the RPM signature verification process, this crafted file can trigger an error in the OpenPGP...
CVE-2026-35092
- EPSS 0.27%
- Veröffentlicht 01.04.2026 13:18:55
- Zuletzt bearbeitet 06.05.2026 21:16:00
A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a remote, unauthenticated attacker to send crafted User Datagram Protocol (UDP) packets. This can cause the service to crash, leading ...
CVE-2026-35091
- EPSS 0.99%
- Veröffentlicht 01.04.2026 13:18:53
- Zuletzt bearbeitet 13.05.2026 08:16:16
A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Corosync membership commit token sanity check by sending a specially crafted User Datagram Protocol (UDP) packet. This can lead to a...
CVE-2026-5201
- EPSS 0.75%
- Veröffentlicht 31.03.2026 08:32:58
- Zuletzt bearbeitet 14.05.2026 23:16:37
A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component counts when processing a specially crafted JPEG image. A remote attacker can explo...
CVE-2026-5164
- EPSS 0.01%
- Veröffentlicht 30.03.2026 15:16:36
- Zuletzt bearbeitet 28.04.2026 14:22:23
A flaw was found in virtio-win. The `RhelDoUnMap()` function does not properly validate the number of descriptors provided by a user during an unmap request. A local user could exploit this input validation vulnerability by supplying an excessive num...
CVE-2026-5165
- EPSS 0.01%
- Veröffentlicht 30.03.2026 15:16:36
- Zuletzt bearbeitet 28.04.2026 14:17:41
A flaw was found in virtio-win, specifically within the VirtIO Block (BLK) device. When the device undergoes a reset, it fails to properly manage memory, resulting in a use-after-free vulnerability. This issue could allow a local attacker to corrupt ...
CVE-2026-5121
- EPSS 0.09%
- Veröffentlicht 30.03.2026 08:16:18
- Zuletzt bearbeitet 14.05.2026 23:16:37
A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buff...
CVE-2026-5119
- EPSS 0.01%
- Veröffentlicht 30.03.2026 05:35:57
- Zuletzt bearbeitet 14.05.2026 11:16:18
A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can ...
CVE-2026-28369
- EPSS 0.05%
- Veröffentlicht 27.03.2026 16:13:05
- Zuletzt bearbeitet 31.03.2026 18:08:21
A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, which violates HTTP standards, can...
CVE-2026-28368
- EPSS 0.03%
- Veröffentlicht 27.03.2026 16:13:03
- Zuletzt bearbeitet 31.03.2026 18:20:30
A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header interpretation can be exp...