CVE-2026-4948
- EPSS 0.02%
- Veröffentlicht 27.03.2026 05:30:23
- Zuletzt bearbeitet 15.05.2026 19:17:04
A flaw was found in firewalld. A local unprivileged user can exploit this vulnerability by mis-authorizing two runtime D-Bus (Desktop Bus) setters, setZoneSettings2 and setPolicySettings. This mis-authorization allows the user to modify the runtime f...
CVE-2026-0965
- EPSS 0.01%
- Veröffentlicht 26.03.2026 20:06:33
- Zuletzt bearbeitet 02.04.2026 17:33:46
A flaw was found in libssh where it can attempt to open arbitrary files during configuration parsing. A local attacker can exploit this by providing a malicious configuration file or when the system is misconfigured. This vulnerability could lead to ...
CVE-2026-0967
- EPSS 0.03%
- Veröffentlicht 26.03.2026 20:06:30
- Zuletzt bearbeitet 02.04.2026 17:28:27
A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could craft specific hostnames that when processed by the `match_pattern()` function can lead to inefficient regular expression backtrackin...
CVE-2026-0968
- EPSS 0.01%
- Veröffentlicht 26.03.2026 20:06:29
- Zuletzt bearbeitet 13.04.2026 20:15:09
A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an `SSH_FXP_NAME` message during a file listing operation. This missing null check can lead to re...
CVE-2026-0964
- EPSS 0.02%
- Veröffentlicht 26.03.2026 20:06:28
- Zuletzt bearbeitet 30.04.2026 16:43:18
A malicious SCP server can send unexpected paths that could make the client application override local files outside of working directory. This could be misused to create malicious executable or configuration files and make the user execute them unde...
CVE-2026-0966
- EPSS 0.05%
- Veröffentlicht 26.03.2026 20:06:28
- Zuletzt bearbeitet 11.05.2026 17:16:11
A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited remotely by an attacker during GSSAPI (Generic Security Service Application Program Interface)...
CVE-2026-2100
- EPSS 0.05%
- Veröffentlicht 26.03.2026 20:01:46
- Zuletzt bearbeitet 25.04.2026 02:16:01
A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters set to NULL. This could lead to the RPC-client attemp...
CVE-2026-2239
- EPSS 0.01%
- Veröffentlicht 26.03.2026 20:00:28
- Zuletzt bearbeitet 03.04.2026 20:12:51
A flaw was found in GIMP. Heap-buffer-overflow vulnerability exists in the fread_pascal_string function when processing a specially crafted PSD (Photoshop Document) file. This occurs because the buffer allocated for a Pascal string is not properly nu...
CVE-2026-2272
- EPSS 0.04%
- Veröffentlicht 26.03.2026 20:00:10
- Zuletzt bearbeitet 03.04.2026 20:17:54
A flaw was found in GIMP. An integer overflow vulnerability exists when processing ICO image files, specifically in the `ico_read_info` and `ico_read_icon` functions. This issue arises because a size calculation for image buffers can wrap around due ...
CVE-2026-2436
- EPSS 0.08%
- Veröffentlicht 26.03.2026 19:31:34
- Zuletzt bearbeitet 21.04.2026 15:48:48
A flaw was found in libsoup's SoupServer. A remote attacker could exploit a use-after-free vulnerability where the `soup_server_disconnect()` function frees connection objects prematurely, even if a TLS handshake is still pending. If the handshake co...