Vulnerabilities
Summary — last 7 days
New vulnerabilities3,302▲ 384 vs. last week
Critical / high1,464▲ 142 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)591▲ 117 vs. last week
231 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Awaiting Analysis | Low (3.7) | 0.29% | — | GNU GlibcAI | 9/28/2026 | 9/29/2026 | The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable. This condition may happen when the input strings to the strncasecmp function are attacker controlled in an… | |
| Awaiting Analysis | Low (3.6) | 0.13% | — | GNU GlibcAI | 9/22/2026 | 9/22/2026 | A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs. When such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader… | |
| Awaiting Analysis | Medium (6.3) | 0.12% | — | GNU GlibcAI | 9/22/2026 | 9/23/2026 | A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path… | |
| Awaiting Analysis | Medium (5.3) | 0.34% | — | GNU GlibcAI | 9/17/2026 | 9/18/2026 | Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process. The resolver truncates the search list when… | |
| Awaiting Analysis | Medium (4.2) | 0.27% | — | GNU GlibcAI | 9/11/2026 | 9/11/2026 | The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack overflow when a malicious DNS server returns too large a response for a DNS query, resulting in degraded DNS resolution for the system. Exploitation of this bug needs a system that has nscd enabled and using an untrusted DNS server for name… | |
| Awaiting Analysis | Medium (5.3) | 0.14% | — | Glib2AI | 9/7/2026 | 9/8/2026 | A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unlinks the destination and recreates it without exclusive creation or symlink protection. A local attacker who can write to the destination directory… | |
| Awaiting Analysis | Medium (6.6) | 0.33% | — | Glibc WordexpAI | 8/10/2026 | 9/3/2026 | When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory. The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was… | |
| Awaiting Analysis | Medium (5.3) | 0.48% | — | Gnome GlibAI | 7/20/2026 | 9/30/2026 | A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending… | |
| Modified | Critical (9.1) | 0.99% | — | Gnome GlibRedhat Enterprise Linux | 6/30/2026 | 9/30/2026 | A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an… | |
| Modified | High (7.5) | 0.91% | — | Gnome GlibRedhat Enterprise Linux | 6/30/2026 | 9/30/2026 | A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary… | |
| Modified | High (8.6) | 0.72% | — | Gnome GlibRedhat Enterprise Linux | 6/30/2026 | 9/30/2026 | A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary. | |
| Modified | High (8.2) | 0.85% | — | Gnome GlibRedhat Enterprise Linux | 6/30/2026 | 9/30/2026 | A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of… | |
| Modified | High (8.2) | 0.85% | — | Gnome GlibRedhat Enterprise Linux | 6/30/2026 | 9/30/2026 | A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated… | |
| Modified | High (7.5) | 0.82% | — | Gnome GlibRedhat Enterprise Linux | 6/30/2026 | 9/30/2026 | A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead… | |
| Modified | High (8.2) | 0.85% | — | Gnome GlibRedhat Enterprise Linux | 6/30/2026 | 9/30/2026 | A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1… | |
| Awaiting Analysis | Medium (4.3) | 0.18% | — | Gnome Glib-networkingAIGnutlsAI | 5/28/2026 | 7/21/2026 | A flaw was found in glib-networking. A remote attacker can exploit this vulnerability by presenting a specially crafted certificate chain to an application that uses glib-networking with the GnuTLS backend enabled and performs certificate verification. This crafted chain, which contains circular issuer relationships,… | |
| Modified | Medium (6.5) | 0.44% | — | GNU Glibc | 4/28/2026 | 7/14/2026 | The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target… | |
| Modified | High (7.3) | 0.39% | — | GNU Glibc | 4/28/2026 | 7/14/2026 | The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records. | |
| Modified | High (7.5) | 0.49% | — | GNU Glibc | 4/20/2026 | 7/14/2026 | Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in… | |
| Modified | Critical (9.8) | 0.72% | — | GNU Glibc | 4/20/2026 | 7/14/2026 | Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow. | |
| Modified | High (7.5) | 0.66% | — | GNU Glibc | 3/30/2026 | 7/14/2026 | The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application. This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character… | |
| Modified | Medium (5.4) | 0.25% | — | GNU Glibc | 3/20/2026 | 7/14/2026 | Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification. | |
| Modified | High (7.5) | 0.49% | — | GNU Glibc | 3/20/2026 | 7/14/2026 | Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response from the configured DNS server, result in a violation of the DNS specification that causes the application to treat a… | |
| Modified | Medium (6.2) | 0.16% | — | GNU Glibc | 3/11/2026 | 7/14/2026 | Calling NSS-backed functions that support caching via nscd may call the nscd client side code and in the GNU C Library version 2.36 under high load on x86_64 systems, the client may call memcmp on inputs that are concurrently modified by other processes or threads and crash. The nscd client in the GNU C Library uses… | |
| Deferred | Medium (4.8) | 0.25% | — | GNU GlibcAI | 2/18/2026 | 6/17/2026 | An insufficient entropy vulnerability was found in glibc. The getrandom and arc4random family of functions may return predictable randomness if these functions are called again after the fork, which happens concurrently with a call to any of these functions. |