CVE-2026-78475
- EPSS 0.12%
- Veröffentlicht 24.08.2026 17:20:48
- Zuletzt bearbeitet 01.09.2026 14:12:15
A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array (VLA) on the stack without proper bounds checking, causing an unbounded stack allocation followed ...
CVE-2026-11861
- EPSS -
- Veröffentlicht 20.08.2026 10:39:08
- Zuletzt bearbeitet 28.09.2026 10:16:42
A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory. This is possible b...
CVE-2026-73198
- EPSS -
- Veröffentlicht 20.08.2026 10:39:00
- Zuletzt bearbeitet 28.09.2026 10:16:45
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages` endpoint by sending an arbitrarily large request body. This can cause the service to consume excessive memory, leading to memory e...
CVE-2026-13097
- EPSS -
- Veröffentlicht 20.08.2026 10:37:55
- Zuletzt bearbeitet 28.09.2026 10:16:43
A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name, allowing a ...
CVE-2026-73196
- EPSS -
- Veröffentlicht 20.08.2026 10:31:58
- Zuletzt bearbeitet 24.08.2026 17:49:31
A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by submitting an oversized One-Time Password (OTP) key value. This oversized key is then decoded and re-encoded without proper size limits, consuming exces...
CVE-2026-73197
- EPSS -
- Veröffentlicht 20.08.2026 10:31:31
- Zuletzt bearbeitet 28.09.2026 10:16:44
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the `/ipa/migration/migration.py` endpoint. This can force the migration handler to read attacker-controlled req...
CVE-2026-13002
- EPSS 0.11%
- Veröffentlicht 14.08.2026 15:02:26
- Zuletzt bearbeitet 31.08.2026 18:17:12
A flow has been identified into dnssec.c library, causing an infinite loop to dnsmasq service. An attacker who controls any DNSSEC-signed zone can hang the dnsmasq process with a single crafted response, killing all DNS resolution for its clients.
CVE-2026-58224
- EPSS 0.41%
- Veröffentlicht 14.08.2026 14:38:51
- Zuletzt bearbeitet 23.09.2026 14:27:26
A flaw was found in Samba's CTDB, the clustered database service used by Samba. Insufficient integrity validation of received CTDB protocol packets allows malformed packets containing invalid field lengths, improperly terminated strings, or inconsist...
CVE-2026-19617
- EPSS 0.11%
- Veröffentlicht 14.08.2026 05:59:29
- Zuletzt bearbeitet 02.10.2026 14:17:10
A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration with deeply nested structures. This could lead to uncontrolled recursion in the libdm configuration file parser, exhausting the st...
CVE-2026-73584
- EPSS 0.09%
- Veröffentlicht 13.08.2026 12:44:16
- Zuletzt bearbeitet 25.08.2026 15:26:08
A flaw was found in sblim-sfcb. A local, low-privileged attacker can exploit a race condition during privileged instance migration by manipulating a temporary file in the `/tmp` directory. By repeatedly recreating a symbolic link, the attacker can re...