CVE-2026-3634
- EPSS 0.03%
- Veröffentlicht 17.03.2026 09:44:19
- Zuletzt bearbeitet 19.03.2026 19:52:33
A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage Return Line Feed (CRLF) sequence due to improper input sanitization in the `soup_message_headers_set_content_type()` function. Th...
CVE-2026-3441
- EPSS 0.01%
- Veröffentlicht 15.03.2026 00:19:07
- Zuletzt bearbeitet 20.03.2026 18:24:05
A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCO...
CVE-2026-3442
- EPSS 0.01%
- Veröffentlicht 15.03.2026 00:19:02
- Zuletzt bearbeitet 20.03.2026 18:23:46
A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious X...
CVE-2026-3099
- EPSS 0.54%
- Veröffentlicht 12.03.2026 13:53:48
- Zuletzt bearbeitet 23.03.2026 14:02:25
A flaw was found in Libsoup. The server-side digest authentication implementation in the SoupAuthDomainDigest class does not properly track issued nonces or enforce the required incrementing nonce-count (nc) attribute. This vulnerability allows a rem...
CVE-2025-12801
- EPSS 0.02%
- Veröffentlicht 04.03.2026 15:25:53
- Zuletzt bearbeitet 02.04.2026 15:16:22
A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to a...
CVE-2025-9572
- EPSS 0.01%
- Veröffentlicht 27.02.2026 07:28:44
- Zuletzt bearbeitet 24.03.2026 12:16:12
n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, which correctly enforces access controls, the GraphQL endpoint does not apply proper filtering, leadi...
CVE-2026-26104
- EPSS 0.01%
- Veröffentlicht 25.02.2026 10:51:15
- Zuletzt bearbeitet 25.03.2026 19:16:48
A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization. The issue occurs because a privileged D-Bus method responsible for exporting encryption metadata does no...
CVE-2026-26103
- EPSS 0.01%
- Veröffentlicht 25.02.2026 10:31:50
- Zuletzt bearbeitet 25.03.2026 19:16:47
A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper authorization checks. The issue allows a local unprivileged user to instruct the root-owned udisks daemo...
CVE-2026-2443
- EPSS 0.04%
- Veröffentlicht 13.02.2026 11:58:20
- Zuletzt bearbeitet 23.03.2026 20:16:25
A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing specially crafted HTTP Range headers, the library may improperly validate requested byte ranges. In certain build configurations, this could allow a ...
CVE-2026-1709
- EPSS 0.03%
- Veröffentlicht 06.02.2026 19:13:27
- Zuletzt bearbeitet 05.03.2026 20:58:02
A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authentication bypass vulnerability allows unauthenticated clients with network access to perfo...