Количество 20
Количество 20
GHSA-h2cc-wx97-xp8v
Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side. Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code. However, the issue only affects clients that make use of TLSA records with both the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate usage. By far the most common deployment of DANE is in SMTP MTAs for which RFC7672 recommends that clients treat as 'unusable' any TLSA records that have the PKIX certificate usages. These SMTP (or other similar) clients are not vulnerable to this issue. Conversely, any clients that support only the PKIX usages, and ignore the DANE-TA(2) usage are also not vulnerable. The client would also need to be communicating with a server that publishes a TLSA RRse...
CVE-2026-28387
Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side. Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code. However, the issue only affects clients that make use of TLSA records with both the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate usage. By far the most common deployment of DANE is in SMTP MTAs for which RFC7672 recommends that clients treat as 'unusable' any TLSA records that have the PKIX certificate usages. These SMTP (or other similar) clients are not vulnerable to this issue. Conversely, any clients that support only the PKIX usages, and ignore the DANE-TA(2) usage are also not vulnerable. The client would also need to be communicating with a server that publishes a TLSA RRset wi...
CVE-2026-28387
Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side. Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code. However, the issue only affects clients that make use of TLSA records with both the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate usage. By far the most common deployment of DANE is in SMTP MTAs for which RFC7672 recommends that clients treat as 'unusable' any TLSA records that have the PKIX certificate usages. These SMTP (or other similar) clients are not vulnerable to this issue. Conversely, any clients that support only the PKIX usages, and ignore the DANE-TA(2) usage are also not vulnerable. The client would also need to be communicating with a server that publishes a TLSA RRset wi...
CVE-2026-28387
Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side. Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code. However, the issue only affects clients that make use of TLSA records with both the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate usage. By far the most common deployment of DANE is in SMTP MTAs for which RFC7672 recommends that clients treat as 'unusable' any TLSA records that have the PKIX certificate usages. These SMTP (or other similar) clients are not vulnerable to this issue. Conversely, any clients that support only the PKIX usages, and ignore the DANE-TA(2) usage are also not vulnerable. The client would also need to be communicating with a server that publishes a TLSA RRset w
CVE-2026-28387
Potential Use-after-free in DANE Client Code
CVE-2026-28387
Issue summary: An uncommon configuration of clients performing DANE TL ...
BDU:2026-10552
Уязвимость инструмента для создания воспроизводимых и перемещаемых окружений Python relenv, связанная с использованием памяти после её освобождения, позволяющая нарушителю выполнить произвольный код
ROS-20260713-73-0031
Уязвимость python-relenv
SUSE-SU-2026:1290-1
Security update for openssl-1_1
SUSE-SU-2026:1255-1
Security update for openssl-1_1
SUSE-SU-2026:1577-1
Security update for openssl-1_1
SUSE-SU-2026:1386-1
Security update for openssl-1_1
SUSE-SU-2026:1291-1
Security update for openssl-1_0_0
SUSE-SU-2026:1257-1
Security update for openssl-1_1
SUSE-SU-2026:1256-1
Security update for openssl-1_0_0
SUSE-SU-2026:1215-1
Security update for openssl-3
SUSE-SU-2026:1214-1
Security update for openssl-3
SUSE-SU-2026:1213-1
Security update for openssl-3
SUSE-SU-2026:1375-1
Security update for openssl-3
openSUSE-SU-2026:20525-1
Security update for openssl-3
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-h2cc-wx97-xp8v Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side. Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code. However, the issue only affects clients that make use of TLSA records with both the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate usage. By far the most common deployment of DANE is in SMTP MTAs for which RFC7672 recommends that clients treat as 'unusable' any TLSA records that have the PKIX certificate usages. These SMTP (or other similar) clients are not vulnerable to this issue. Conversely, any clients that support only the PKIX usages, and ignore the DANE-TA(2) usage are also not vulnerable. The client would also need to be communicating with a server that publishes a TLSA RRse... | CVSS3: 8.1 | 1% Низкий | 4 месяца назад | |
CVE-2026-28387 Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side. Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code. However, the issue only affects clients that make use of TLSA records with both the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate usage. By far the most common deployment of DANE is in SMTP MTAs for which RFC7672 recommends that clients treat as 'unusable' any TLSA records that have the PKIX certificate usages. These SMTP (or other similar) clients are not vulnerable to this issue. Conversely, any clients that support only the PKIX usages, and ignore the DANE-TA(2) usage are also not vulnerable. The client would also need to be communicating with a server that publishes a TLSA RRset wi... | CVSS3: 8.1 | 1% Низкий | 4 месяца назад | |
CVE-2026-28387 Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side. Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code. However, the issue only affects clients that make use of TLSA records with both the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate usage. By far the most common deployment of DANE is in SMTP MTAs for which RFC7672 recommends that clients treat as 'unusable' any TLSA records that have the PKIX certificate usages. These SMTP (or other similar) clients are not vulnerable to this issue. Conversely, any clients that support only the PKIX usages, and ignore the DANE-TA(2) usage are also not vulnerable. The client would also need to be communicating with a server that publishes a TLSA RRset wi... | CVSS3: 3.7 | 1% Низкий | 4 месяца назад | |
CVE-2026-28387 Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side. Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code. However, the issue only affects clients that make use of TLSA records with both the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate usage. By far the most common deployment of DANE is in SMTP MTAs for which RFC7672 recommends that clients treat as 'unusable' any TLSA records that have the PKIX certificate usages. These SMTP (or other similar) clients are not vulnerable to this issue. Conversely, any clients that support only the PKIX usages, and ignore the DANE-TA(2) usage are also not vulnerable. The client would also need to be communicating with a server that publishes a TLSA RRset w | CVSS3: 8.1 | 1% Низкий | 4 месяца назад | |
CVE-2026-28387 Potential Use-after-free in DANE Client Code | CVSS3: 3.8 | 1% Низкий | 4 месяца назад | |
CVE-2026-28387 Issue summary: An uncommon configuration of clients performing DANE TL ... | CVSS3: 8.1 | 1% Низкий | 4 месяца назад | |
BDU:2026-10552 Уязвимость инструмента для создания воспроизводимых и перемещаемых окружений Python relenv, связанная с использованием памяти после её освобождения, позволяющая нарушителю выполнить произвольный код | CVSS3: 8.1 | 1% Низкий | 4 месяца назад | |
ROS-20260713-73-0031 Уязвимость python-relenv | CVSS3: 8.1 | 1% Низкий | 20 дней назад | |
SUSE-SU-2026:1290-1 Security update for openssl-1_1 | 4 месяца назад | |||
SUSE-SU-2026:1255-1 Security update for openssl-1_1 | 4 месяца назад | |||
SUSE-SU-2026:1577-1 Security update for openssl-1_1 | 3 месяца назад | |||
SUSE-SU-2026:1386-1 Security update for openssl-1_1 | 4 месяца назад | |||
SUSE-SU-2026:1291-1 Security update for openssl-1_0_0 | 4 месяца назад | |||
SUSE-SU-2026:1257-1 Security update for openssl-1_1 | 4 месяца назад | |||
SUSE-SU-2026:1256-1 Security update for openssl-1_0_0 | 4 месяца назад | |||
SUSE-SU-2026:1215-1 Security update for openssl-3 | 4 месяца назад | |||
SUSE-SU-2026:1214-1 Security update for openssl-3 | 4 месяца назад | |||
SUSE-SU-2026:1213-1 Security update for openssl-3 | 4 месяца назад | |||
SUSE-SU-2026:1375-1 Security update for openssl-3 | 4 месяца назад | |||
openSUSE-SU-2026:20525-1 Security update for openssl-3 | 4 месяца назад |
Уязвимостей на страницу