CVE-2026-53000
- EPSS 0.13%
- Veröffentlicht 24.06.2026 16:29:12
- Zuletzt bearbeitet 17.08.2026 12:18:54
In the Linux kernel, the following vulnerability has been resolved: netfilter: nat: use kfree_rcu to release ops Florian Westphal says: "Historically this is not an issue, even for normal base hooks: the data path doesn't use the original nf_hook_...
CVE-2026-12892
- EPSS 0.12%
- Veröffentlicht 23.06.2026 19:53:23
- Zuletzt bearbeitet 06.07.2026 18:02:05
A flaw was found in GStreamer's gst-plugins-bad package. When processing a specially crafted H.264 video file containing malformed MVC or SVC extension slice NAL units, a 1-byte heap out-of-bounds read can occur during parsing. This happens when the ...
CVE-2026-12891
- EPSS 0.27%
- Veröffentlicht 23.06.2026 19:53:21
- Zuletzt bearbeitet 01.07.2026 18:02:08
A flaw was found in the GStreamer gst-plugins-bad package. When processing a malformed H.266/VVC video stream with a crafted aspect ratio indicator value, the H.266 parser performs an out-of-bounds read of up to 8 bytes from adjacent memory. This fla...
CVE-2026-11820
- EPSS 0.29%
- Veröffentlicht 23.06.2026 19:53:19
- Zuletzt bearbeitet 01.07.2026 18:27:53
A flaw was found in the community.general Ansible collection's nexmo module. The module constructs HTTP requests to the Vonage/Nexmo SMS API by encoding API credentials (api_key and api_secret) into URL query parameters and sending them via GET reque...
CVE-2026-11819
- EPSS 0.12%
- Veröffentlicht 23.06.2026 19:53:17
- Zuletzt bearbeitet 08.07.2026 15:11:07
Module: plugins/modules/keyring_info.py CVSS 3.1: 5.5 MEDIUM — AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Issue: The module retrieves a passphrase from the OS native keyring (GNOME Keyring, macOS Keychain, Windows Credential Manager) and places it direc...
CVE-2026-12969
- EPSS 0.24%
- Veröffentlicht 23.06.2026 13:28:56
- Zuletzt bearbeitet 08.07.2026 15:10:14
An out-of-bounds read vulnerability exists in dnsmasq's find_soa() function in src/rfc1035.c. When parsing NS section records, extract_name() is called with extrabytes=0, failing to validate that 10 additional bytes exist for fixed-length DNS record ...
CVE-2026-55654
- EPSS 0.43%
- Veröffentlicht 23.06.2026 03:37:00
- Zuletzt bearbeitet 21.08.2026 12:16:28
A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the auth-indicators...
CVE-2026-55655
- EPSS 0.09%
- Veröffentlicht 23.06.2026 03:36:25
- Zuletzt bearbeitet 21.08.2026 12:16:29
A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a local UNIX-...
CVE-2026-55653
- EPSS 0.29%
- Veröffentlicht 23.06.2026 03:36:22
- Zuletzt bearbeitet 21.08.2026 12:16:28
A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when...
CVE-2026-12549
- EPSS 0.41%
- Veröffentlicht 22.06.2026 13:55:06
- Zuletzt bearbeitet 08.07.2026 15:10:43
The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison. When a client sends a Range request with a suffix length exceeding the content size, the resulting negative...