Количество 13
Количество 13
BDU:2025-10928
Уязвимость библиотеки libsoup графического интерфейса GNOME, связанная с ошибками разыменования указателей, позволяющая нарушителю вызвать отказ в обслуживании
CVE-2025-4476
A denial-of-service vulnerability has been identified in the libsoup HTTP client library. This flaw can be triggered when a libsoup client receives a 401 (Unauthorized) HTTP response containing a specifically crafted domain parameter within the WWW-Authenticate header. Processing this malformed header can lead to a crash of the client application using libsoup. An attacker could exploit this by setting up a malicious HTTP server. If a user's application using the vulnerable libsoup library connects to this malicious server, it could result in a denial-of-service. Successful exploitation requires tricking a user's client application into connecting to the attacker's malicious server.
CVE-2025-4476
A denial-of-service vulnerability has been identified in the libsoup HTTP client library. This flaw can be triggered when a libsoup client receives a 401 (Unauthorized) HTTP response containing a specifically crafted domain parameter within the WWW-Authenticate header. Processing this malformed header can lead to a crash of the client application using libsoup. An attacker could exploit this by setting up a malicious HTTP server. If a user's application using the vulnerable libsoup library connects to this malicious server, it could result in a denial-of-service. Successful exploitation requires tricking a user's client application into connecting to the attacker's malicious server.
CVE-2025-4476
A denial-of-service vulnerability has been identified in the libsoup HTTP client library. This flaw can be triggered when a libsoup client receives a 401 (Unauthorized) HTTP response containing a specifically crafted domain parameter within the WWW-Authenticate header. Processing this malformed header can lead to a crash of the client application using libsoup. An attacker could exploit this by setting up a malicious HTTP server. If a user's application using the vulnerable libsoup library connects to this malicious server, it could result in a denial-of-service. Successful exploitation requires tricking a user's client application into connecting to the attacker's malicious server.
CVE-2025-4476
Libsoup: null pointer dereference in libsoup may lead to denial of service
CVE-2025-4476
A denial-of-service vulnerability has been identified in the libsoup H ...
GHSA-qgq4-89p9-qfrh
A denial-of-service vulnerability has been identified in the libsoup HTTP client library. This flaw can be triggered when a libsoup client receives a 401 (Unauthorized) HTTP response containing a specifically crafted domain parameter within the WWW-Authenticate header. Processing this malformed header can lead to a crash of the client application using libsoup. An attacker could exploit this by setting up a malicious HTTP server. If a user's application using the vulnerable libsoup library connects to this malicious server, it could result in a denial-of-service. Successful exploitation requires tricking a user's client application into connecting to the attacker's malicious server.
SUSE-SU-2026:0574-1
Security update for libsoup2
SUSE-SU-2026:0497-1
Security update for libsoup2
SUSE-SU-2025:01817-1
Security update for libsoup
SUSE-SU-2025:01812-1
Security update for libsoup
SUSE-SU-2026:0703-1
Security update for libsoup
openSUSE-SU-2026:20354-1
Security update for libsoup2
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2025-10928 Уязвимость библиотеки libsoup графического интерфейса GNOME, связанная с ошибками разыменования указателей, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7.3 | 0% Низкий | 11 месяцев назад | |
CVE-2025-4476 A denial-of-service vulnerability has been identified in the libsoup HTTP client library. This flaw can be triggered when a libsoup client receives a 401 (Unauthorized) HTTP response containing a specifically crafted domain parameter within the WWW-Authenticate header. Processing this malformed header can lead to a crash of the client application using libsoup. An attacker could exploit this by setting up a malicious HTTP server. If a user's application using the vulnerable libsoup library connects to this malicious server, it could result in a denial-of-service. Successful exploitation requires tricking a user's client application into connecting to the attacker's malicious server. | CVSS3: 4.3 | 0% Низкий | 11 месяцев назад | |
CVE-2025-4476 A denial-of-service vulnerability has been identified in the libsoup HTTP client library. This flaw can be triggered when a libsoup client receives a 401 (Unauthorized) HTTP response containing a specifically crafted domain parameter within the WWW-Authenticate header. Processing this malformed header can lead to a crash of the client application using libsoup. An attacker could exploit this by setting up a malicious HTTP server. If a user's application using the vulnerable libsoup library connects to this malicious server, it could result in a denial-of-service. Successful exploitation requires tricking a user's client application into connecting to the attacker's malicious server. | CVSS3: 4.3 | 0% Низкий | 11 месяцев назад | |
CVE-2025-4476 A denial-of-service vulnerability has been identified in the libsoup HTTP client library. This flaw can be triggered when a libsoup client receives a 401 (Unauthorized) HTTP response containing a specifically crafted domain parameter within the WWW-Authenticate header. Processing this malformed header can lead to a crash of the client application using libsoup. An attacker could exploit this by setting up a malicious HTTP server. If a user's application using the vulnerable libsoup library connects to this malicious server, it could result in a denial-of-service. Successful exploitation requires tricking a user's client application into connecting to the attacker's malicious server. | CVSS3: 4.3 | 0% Низкий | 11 месяцев назад | |
CVE-2025-4476 Libsoup: null pointer dereference in libsoup may lead to denial of service | CVSS3: 4.3 | 0% Низкий | около 1 месяца назад | |
CVE-2025-4476 A denial-of-service vulnerability has been identified in the libsoup H ... | CVSS3: 4.3 | 0% Низкий | 11 месяцев назад | |
GHSA-qgq4-89p9-qfrh A denial-of-service vulnerability has been identified in the libsoup HTTP client library. This flaw can be triggered when a libsoup client receives a 401 (Unauthorized) HTTP response containing a specifically crafted domain parameter within the WWW-Authenticate header. Processing this malformed header can lead to a crash of the client application using libsoup. An attacker could exploit this by setting up a malicious HTTP server. If a user's application using the vulnerable libsoup library connects to this malicious server, it could result in a denial-of-service. Successful exploitation requires tricking a user's client application into connecting to the attacker's malicious server. | CVSS3: 4.3 | 0% Низкий | 11 месяцев назад | |
SUSE-SU-2026:0574-1 Security update for libsoup2 | около 1 месяца назад | |||
SUSE-SU-2026:0497-1 Security update for libsoup2 | около 2 месяцев назад | |||
SUSE-SU-2025:01817-1 Security update for libsoup | 10 месяцев назад | |||
SUSE-SU-2025:01812-1 Security update for libsoup | 10 месяцев назад | |||
SUSE-SU-2026:0703-1 Security update for libsoup | около 1 месяца назад | |||
openSUSE-SU-2026:20354-1 Security update for libsoup2 | 21 день назад |
Уязвимостей на страницу