CVE-2026-73583
- EPSS 0.1%
- Veröffentlicht 13.08.2026 12:44:13
- Zuletzt bearbeitet 25.08.2026 15:18:00
A flaw was found in sblim-sfcb. A local attacker with access to the system can exploit an unsafe deserialization vulnerability in the provider-manager's inter-process communication (IPC) message parsing. By sending a specially crafted message, the at...
CVE-2026-73585
- EPSS 0.1%
- Veröffentlicht 13.08.2026 12:44:09
- Zuletzt bearbeitet 25.08.2026 15:28:06
A flaw was found in sblim-cmpi-base. Insecure temporary file creation in the provider registration scripts allows a local unprivileged user to perform a symlink attack. By creating a symlink in a world-writable directory, an attacker can redirect pri...
CVE-2026-18728
- EPSS 0.2%
- Veröffentlicht 13.08.2026 03:13:55
- Zuletzt bearbeitet 25.08.2026 15:04:06
A flaw was found in open-iscsi. An integer underflow vulnerability in the `iscsiuio` component, specifically during IPv4 Dynamic Host Configuration Protocol (DHCP) parsing, allows a remote attacker on the same local network segment to cause a denial ...
CVE-2026-18727
- EPSS 0.2%
- Veröffentlicht 12.08.2026 21:13:51
- Zuletzt bearbeitet 25.08.2026 14:41:11
A flaw was found in open-iscsi's iscsiuio component. This vulnerability involves an integer underflow and out-of-bounds read during Dynamic Host Configuration Protocol for IPv6 (DHCPv6) packet parsing. Specifically, crafted DHCPv6 Advertise traffic w...
CVE-2026-18726
- EPSS 0.22%
- Veröffentlicht 12.08.2026 21:13:47
- Zuletzt bearbeitet 25.08.2026 16:54:40
A flaw was found in open-iscsi. This vulnerability allows a remote attacker on the same local network segment to cause a Denial of Service (DoS) in the iscsiuio daemon. By sending a specially crafted Internet Control Message Protocol version 6 (ICMPv...
CVE-2026-19654
- EPSS 0.4%
- Veröffentlicht 12.08.2026 20:46:31
- Zuletzt bearbeitet 24.09.2026 17:17:04
A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or i...
CVE-2026-73433
- EPSS 0.13%
- Veröffentlicht 12.08.2026 19:05:27
- Zuletzt bearbeitet 23.09.2026 15:17:17
A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk, gst_avi_demux_parse_strd() decrements a remaining-length counter by fixed offsets (98 and 10 bytes) without verifying sufficient data rema...
CVE-2026-73434
- EPSS 0.13%
- Veröffentlicht 12.08.2026 19:05:23
- Zuletzt bearbeitet 23.09.2026 15:17:17
A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available gst_riff_vprp_video_field_desc entries is calculated by dividing the remaining buffer size by the attacker-controlled vprp->fields ...
CVE-2026-19548
- EPSS 0.12%
- Veröffentlicht 12.08.2026 15:51:39
- Zuletzt bearbeitet 01.09.2026 13:18:13
Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_cl...
CVE-2026-18663
- EPSS 0.4%
- Veröffentlicht 12.08.2026 09:35:26
- Zuletzt bearbeitet 14.08.2026 19:07:46
A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function frees the parsed controls array on the Session Tracking critical-control rejection path without clearing the SLAPI_REQCONTROLS pblock slot. Operation teardown then frees the...