CVE-2026-35092
- EPSS 0.99%
- Veröffentlicht 01.04.2026 13:18:55
- Zuletzt bearbeitet 26.05.2026 16:16:23
A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a remote, unauthenticated attacker to send crafted User Datagram Protocol (UDP) packets. This can cause the service to crash, leading ...
CVE-2026-35091
- EPSS 0.87%
- Veröffentlicht 01.04.2026 13:18:53
- Zuletzt bearbeitet 26.05.2026 16:16:23
A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Corosync membership commit token sanity check by sending a specially crafted User Datagram Protocol (UDP) packet. This can lead to a...
CVE-2025-14512
- EPSS 0.59%
- Veröffentlicht 11.12.2025 07:16:00
- Zuletzt bearbeitet 13.07.2026 17:16:31
A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when processing malicious file or remote filesystem attribu...
CVE-2025-9566
- EPSS 1.08%
- Veröffentlicht 05.09.2025 19:54:30
- Zuletzt bearbeitet 21.08.2026 12:16:20
There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In a successful...
CVE-2025-4437
- EPSS 0.24%
- Veröffentlicht 20.08.2025 12:19:18
- Zuletzt bearbeitet 15.04.2026 00:35:42
There's a vulnerability in the CRI-O application where when container is launched with securityContext.runAsUser specifying a non-existent user, CRI-O attempts to create the user, reading the container's entire /etc/passwd file into memory. If this f...
CVE-2025-6170
- EPSS 0.22%
- Veröffentlicht 16.06.2025 15:24:05
- Zuletzt bearbeitet 11.08.2026 10:17:09
A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow...
CVE-2025-2586
- EPSS 0.51%
- Veröffentlicht 31.03.2025 12:15:15
- Zuletzt bearbeitet 25.06.2026 23:17:00
A flaw was found in the OpenShift Lightspeed Service, which is vulnerable to unauthenticated API request flooding. Repeated queries to non-existent endpoints inflate metrics storage and processing, consuming excessive resources. This issue can lead t...
CVE-2024-25132
- EPSS 0.33%
- Veröffentlicht 19.03.2025 17:57:14
- Zuletzt bearbeitet 15.04.2026 00:35:42
A flaw was found in the Hive hibernation controller component of OpenShift Dedicated. The ClusterDeployment.hive.openshift.io/v1 resource can be created with the spec.installed field set to true, regardless of the installation status, and a positive ...
CVE-2025-0689
- EPSS 0.47%
- Veröffentlicht 03.03.2025 15:15:16
- Zuletzt bearbeitet 30.06.2026 00:16:50
When reading data from disk, the grub's UDF filesystem module utilizes the user controlled data length metadata to allocate its internal buffers. In certain scenarios, while iterating through disk sectors, it assumes the read size from the disk is al...
CVE-2024-45777
- EPSS 0.24%
- Veröffentlicht 19.02.2025 18:15:23
- Zuletzt bearbeitet 29.06.2026 23:16:41
A flaw was found in grub2. The calculation of the translation buffer when reading a language .mo file in grub_gettext_getstr_from_position() may overflow, leading to a Out-of-bound write. This issue can be leveraged by an attacker to overwrite grub2'...