Количество 7
Количество 7
BDU:2026-12066
Уязвимость компонента soup-server-connection.c библиотеки доступа к HTTP серверам LibSoup, позволяющая нарушителю вызвать отказ в обслуживании
CVE-2026-2436
A flaw was found in libsoup's SoupServer. A remote attacker could exploit a use-after-free vulnerability where the `soup_server_disconnect()` function frees connection objects prematurely, even if a TLS handshake is still pending. If the handshake completes after the connection object has been freed, a dangling pointer is accessed, leading to a server crash and a Denial of Service.
CVE-2026-2436
A flaw was found in libsoup's SoupServer. A remote attacker could exploit a use-after-free vulnerability where the `soup_server_disconnect()` function frees connection objects prematurely, even if a TLS handshake is still pending. If the handshake completes after the connection object has been freed, a dangling pointer is accessed, leading to a server crash and a Denial of Service.
CVE-2026-2436
A flaw was found in libsoup's SoupServer. A remote attacker could exploit a use-after-free vulnerability where the `soup_server_disconnect()` function frees connection objects prematurely, even if a TLS handshake is still pending. If the handshake completes after the connection object has been freed, a dangling pointer is accessed, leading to a server crash and a Denial of Service.
CVE-2026-2436
Libsoup: libsoup: denial of service via use-after-free in soupserver during tls handshake
CVE-2026-2436
A flaw was found in libsoup's SoupServer. A remote attacker could expl ...
GHSA-wpfw-5xvc-wq9w
A flaw was found in libsoup's SoupServer. A remote attacker could exploit a use-after-free vulnerability where the `soup_server_disconnect()` function frees connection objects prematurely, even if a TLS handshake is still pending. If the handshake completes after the connection object has been freed, a dangling pointer is accessed, leading to a server crash and a Denial of Service.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-12066 Уязвимость компонента soup-server-connection.c библиотеки доступа к HTTP серверам LibSoup, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 8.2 | 0% Низкий | 10 месяцев назад | |
CVE-2026-2436 A flaw was found in libsoup's SoupServer. A remote attacker could exploit a use-after-free vulnerability where the `soup_server_disconnect()` function frees connection objects prematurely, even if a TLS handshake is still pending. If the handshake completes after the connection object has been freed, a dangling pointer is accessed, leading to a server crash and a Denial of Service. | CVSS3: 6.5 | 0% Низкий | 6 месяцев назад | |
CVE-2026-2436 A flaw was found in libsoup's SoupServer. A remote attacker could exploit a use-after-free vulnerability where the `soup_server_disconnect()` function frees connection objects prematurely, even if a TLS handshake is still pending. If the handshake completes after the connection object has been freed, a dangling pointer is accessed, leading to a server crash and a Denial of Service. | CVSS3: 6.5 | 0% Низкий | 7 месяцев назад | |
CVE-2026-2436 A flaw was found in libsoup's SoupServer. A remote attacker could exploit a use-after-free vulnerability where the `soup_server_disconnect()` function frees connection objects prematurely, even if a TLS handshake is still pending. If the handshake completes after the connection object has been freed, a dangling pointer is accessed, leading to a server crash and a Denial of Service. | CVSS3: 6.5 | 0% Низкий | 6 месяцев назад | |
CVE-2026-2436 Libsoup: libsoup: denial of service via use-after-free in soupserver during tls handshake | CVSS3: 6.5 | 0% Низкий | 6 месяцев назад | |
CVE-2026-2436 A flaw was found in libsoup's SoupServer. A remote attacker could expl ... | CVSS3: 6.5 | 0% Низкий | 6 месяцев назад | |
GHSA-wpfw-5xvc-wq9w A flaw was found in libsoup's SoupServer. A remote attacker could exploit a use-after-free vulnerability where the `soup_server_disconnect()` function frees connection objects prematurely, even if a TLS handshake is still pending. If the handshake completes after the connection object has been freed, a dangling pointer is accessed, leading to a server crash and a Denial of Service. | CVSS3: 6.5 | 0% Низкий | 6 месяцев назад |
Уязвимостей на страницу