CVE-2026-68743
- EPSS 0.13%
- Veröffentlicht 04.08.2026 18:37:21
- Zuletzt bearbeitet 31.08.2026 19:17:10
A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted protocol v1 request to...
CVE-2026-68744
- EPSS 0.09%
- Veröffentlicht 04.08.2026 05:28:30
- Zuletzt bearbeitet 31.08.2026 19:17:10
A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet when groups are skipped, causing uninitialized heap bytes to be transmitted to t...
CVE-2026-42169
- EPSS 0.13%
- Veröffentlicht 04.08.2026 03:15:25
- Zuletzt bearbeitet 30.09.2026 18:31:51
A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file loader of GIMP. This flaw occurs when the `fcTL` width exceeds the `IHDR` width, leading to pixel data being written past the end of a heap allocation. Additionally, a heap-b...
CVE-2026-18477
- EPSS 0.1%
- Veröffentlicht 03.08.2026 15:34:36
- Zuletzt bearbeitet 22.09.2026 22:17:11
A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system...
CVE-2026-18651
- EPSS 0.17%
- Veröffentlicht 03.08.2026 14:55:33
- Zuletzt bearbeitet 09.08.2026 13:54:50
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the account is subsequently found to be locked, the bind is reported as fai...
CVE-2026-18508
- EPSS 0.14%
- Veröffentlicht 03.08.2026 14:51:41
- Zuletzt bearbeitet 22.09.2026 22:17:11
A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can creat...
CVE-2026-68742
- EPSS 0.13%
- Veröffentlicht 03.08.2026 10:16:33
- Zuletzt bearbeitet 31.08.2026 19:17:10
A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate the addrlen field against the remaining packet body size. A local attacker can exploit this via a crafted GETHOSTBYADDR request to the NSS res...
CVE-2026-6695
- EPSS 0.24%
- Veröffentlicht 03.08.2026 04:05:30
- Zuletzt bearbeitet 19.08.2026 20:28:20
A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially crafted PAA (Paint Shop Pro Array) image file. This vulnerability, a heap-based out-of-bounds write in the decode_lzss() function of the PAA fi...
CVE-2026-6694
- EPSS 0.15%
- Veröffentlicht 03.08.2026 04:05:27
- Zuletzt bearbeitet 04.09.2026 13:45:55
A flaw was found in GIMP's file-png plugin. A remote attacker can exploit this by crafting a malicious Animated Portable Network Graphics (APNG) image containing an oversized tRNS chunk. This can lead to a stack-based buffer overflow (CWE-121), causi...
CVE-2026-11770
- EPSS 0.69%
- Veröffentlicht 31.07.2026 09:18:58
- Zuletzt bearbeitet 08.10.2026 15:17:47
A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated repl...