Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 40

Количество 40

fstec логотип

BDU:2026-09340

6 месяцев назад

Уязвимость функции parse_handshake_header() криптографической библиотеки GnuTLS, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20260625-73-0011

3 месяца назад

Уязвимость gnutls

CVSS3: 9.1
EPSS: Низкий
ubuntu логотип

CVE-2026-42009

4 месяца назад

A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-42009

5 месяцев назад

A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-42009

4 месяца назад

A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2026-42009

4 месяца назад

Gnutls: gnutls: denial of service via dtls packet reordering vulnerability

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-42009

4 месяца назад

A flaw was found in gnutls. A remote attacker could exploit an issue i ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-33846

4 месяца назад

A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-33846

4 месяца назад

A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-33846

4 месяца назад

A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2026-33846

4 месяца назад

Gnutls: gnutls: denial of service via heap buffer overflow in dtls handshake fragment reassembly

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-33846

4 месяца назад

A heap buffer overflow vulnerability exists in the DTLS handshake frag ...

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20260625-80-0004

3 месяца назад

Уязвимость gnutls

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20260625-80-0002

3 месяца назад

Уязвимость gnutls

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20260625-73-0004

3 месяца назад

Уязвимость gnutls

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-qcj7-gqxf-2cqq

4 месяца назад

A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-9gx7-g5hv-xjjj

4 месяца назад

A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2026-09651

5 месяцев назад

Уязвимость реализации протокола DTLS криптографической библиотеки GnuTLS, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2026-09344

6 месяцев назад

Уязвимость функции merge_handshake_packet() криптографической библиотеки GnuTLS, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20260625-73-0002

3 месяца назад

Уязвимость gnutls

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-09340

Уязвимость функции parse_handshake_header() криптографической библиотеки GnuTLS, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
1%
Низкий
6 месяцев назад
redos логотип
ROS-20260625-73-0011

Уязвимость gnutls

CVSS3: 9.1
1%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-42009

A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.

CVSS3: 7.5
1%
Низкий
4 месяца назад
redhat логотип
CVE-2026-42009

A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.

CVSS3: 7.5
1%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-42009

A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.

CVSS3: 7.5
1%
Низкий
4 месяца назад
msrc логотип
CVE-2026-42009

Gnutls: gnutls: denial of service via dtls packet reordering vulnerability

CVSS3: 7.5
1%
Низкий
4 месяца назад
debian логотип
CVE-2026-42009

A flaw was found in gnutls. A remote attacker could exploit an issue i ...

CVSS3: 7.5
1%
Низкий
4 месяца назад
ubuntu логотип
CVE-2026-33846

A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption.

CVSS3: 7.5
1%
Низкий
4 месяца назад
redhat логотип
CVE-2026-33846

A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption.

CVSS3: 7.5
1%
Низкий
4 месяца назад
nvd логотип
CVE-2026-33846

A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption.

CVSS3: 7.5
1%
Низкий
4 месяца назад
msrc логотип
CVE-2026-33846

Gnutls: gnutls: denial of service via heap buffer overflow in dtls handshake fragment reassembly

CVSS3: 7.5
1%
Низкий
4 месяца назад
debian логотип
CVE-2026-33846

A heap buffer overflow vulnerability exists in the DTLS handshake frag ...

CVSS3: 7.5
1%
Низкий
4 месяца назад
redos логотип
ROS-20260625-80-0004

Уязвимость gnutls

CVSS3: 7.5
1%
Низкий
3 месяца назад
redos логотип
ROS-20260625-80-0002

Уязвимость gnutls

CVSS3: 7.5
1%
Низкий
3 месяца назад
redos логотип
ROS-20260625-73-0004

Уязвимость gnutls

CVSS3: 7.5
1%
Низкий
3 месяца назад
github логотип
GHSA-qcj7-gqxf-2cqq

A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption.

CVSS3: 7.5
1%
Низкий
4 месяца назад
github логотип
GHSA-9gx7-g5hv-xjjj

A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.

CVSS3: 7.5
1%
Низкий
4 месяца назад
fstec логотип
BDU:2026-09651

Уязвимость реализации протокола DTLS криптографической библиотеки GnuTLS, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
1%
Низкий
5 месяцев назад
fstec логотип
BDU:2026-09344

Уязвимость функции merge_handshake_packet() криптографической библиотеки GnuTLS, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
1%
Низкий
6 месяцев назад
redos логотип
ROS-20260625-73-0002

Уязвимость gnutls

CVSS3: 7.5
1%
Низкий
3 месяца назад

Уязвимостей на страницу