Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 22

Количество 22

rocky логотип

RLSA-2026:26410

около 2 месяцев назад

Important: rsync security update

EPSS: Низкий
rocky логотип

RLSA-2026:26408

около 2 месяцев назад

Important: rsync security update

EPSS: Низкий
rocky логотип

RLSA-2026:26332

около 1 месяца назад

Important: rsync security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-26410

около 1 месяца назад

ELSA-2026-26410: rsync security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-26408

около 2 месяцев назад

ELSA-2026-26408: rsync security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-26332

17 дней назад

ELSA-2026-26332: rsync security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20877-1

2 месяца назад

Security update for rsync

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2083-1

2 месяца назад

Security update for rsync

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2048-1

2 месяца назад

Security update for rsync

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2038-1

2 месяца назад

Security update for rsync

EPSS: Низкий
ubuntu логотип

CVE-2026-43618

2 месяца назад

Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigger an overflow that causes the receiver process to read and return data from outside the intended buffer bounds. Attackers can exploit this vulnerability to disclose process memory contents including environment variables, passwords, heap and stack data, and library memory pointers, significantly reducing ASLR effectiveness and facilitating further exploitation.

CVSS3: 8.1
EPSS: Низкий
redhat логотип

CVE-2026-43618

2 месяца назад

Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigger an overflow that causes the receiver process to read and return data from outside the intended buffer bounds. Attackers can exploit this vulnerability to disclose process memory contents including environment variables, passwords, heap and stack data, and library memory pointers, significantly reducing ASLR effectiveness and facilitating further exploitation.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-43618

2 месяца назад

Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigger an overflow that causes the receiver process to read and return data from outside the intended buffer bounds. Attackers can exploit this vulnerability to disclose process memory contents including environment variables, passwords, heap and stack data, and library memory pointers, significantly reducing ASLR effectiveness and facilitating further exploitation.

CVSS3: 8.1
EPSS: Низкий
msrc логотип

CVE-2026-43618

2 месяца назад

Rsync < 3.4.3 Integer Overflow Information Disclosure

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2026-43618

2 месяца назад

Rsync version3.4.2 and prior contain an integer overflow vulnerability ...

CVSS3: 8.1
EPSS: Низкий
ubuntu логотип

CVE-2026-29518

2 месяца назад

Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with symbolic links. Attackers with write access to a module path can exploit this race condition to create or overwrite arbitrary files, potentially modifying sensitive system files and achieving privilege escalation when the daemon runs with elevated privileges. This vulnerability can only be triggered if the chroot setting is false.

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2026-29518

2 месяца назад

Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with symbolic links. Attackers with write access to a module path can exploit this race condition to create or overwrite arbitrary files, potentially modifying sensitive system files and achieving privilege escalation when the daemon runs with elevated privileges. This vulnerability can only be triggered if the chroot setting is false.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-29518

2 месяца назад

Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with symbolic links. Attackers with write access to a module path can exploit this race condition to create or overwrite arbitrary files, potentially modifying sensitive system files and achieving privilege escalation when the daemon runs with elevated privileges. This vulnerability can only be triggered if the chroot setting is false.

CVSS3: 7
EPSS: Низкий
msrc логотип

CVE-2026-29518

2 месяца назад

Rsync < 3.4.3 TOCTOU Race Condition Allows Symlink-Based Arbitrary File Write

CVSS3: 7
EPSS: Низкий
debian логотип

CVE-2026-29518

2 месяца назад

Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TO ...

CVSS3: 7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2026:26410

Important: rsync security update

около 2 месяцев назад
rocky логотип
RLSA-2026:26408

Important: rsync security update

около 2 месяцев назад
rocky логотип
RLSA-2026:26332

Important: rsync security, bug fix, and enhancement update

около 1 месяца назад
oracle-oval логотип
ELSA-2026-26410

ELSA-2026-26410: rsync security update (IMPORTANT)

около 1 месяца назад
oracle-oval логотип
ELSA-2026-26408

ELSA-2026-26408: rsync security update (IMPORTANT)

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-26332

ELSA-2026-26332: rsync security, bug fix, and enhancement update (IMPORTANT)

17 дней назад
suse-cvrf логотип
openSUSE-SU-2026:20877-1

Security update for rsync

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2083-1

Security update for rsync

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2048-1

Security update for rsync

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2038-1

Security update for rsync

2 месяца назад
ubuntu логотип
CVE-2026-43618

Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigger an overflow that causes the receiver process to read and return data from outside the intended buffer bounds. Attackers can exploit this vulnerability to disclose process memory contents including environment variables, passwords, heap and stack data, and library memory pointers, significantly reducing ASLR effectiveness and facilitating further exploitation.

CVSS3: 8.1
1%
Низкий
2 месяца назад
redhat логотип
CVE-2026-43618

Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigger an overflow that causes the receiver process to read and return data from outside the intended buffer bounds. Attackers can exploit this vulnerability to disclose process memory contents including environment variables, passwords, heap and stack data, and library memory pointers, significantly reducing ASLR effectiveness and facilitating further exploitation.

CVSS3: 8.1
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-43618

Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigger an overflow that causes the receiver process to read and return data from outside the intended buffer bounds. Attackers can exploit this vulnerability to disclose process memory contents including environment variables, passwords, heap and stack data, and library memory pointers, significantly reducing ASLR effectiveness and facilitating further exploitation.

CVSS3: 8.1
1%
Низкий
2 месяца назад
msrc логотип
CVE-2026-43618

Rsync < 3.4.3 Integer Overflow Information Disclosure

CVSS3: 8.1
1%
Низкий
2 месяца назад
debian логотип
CVE-2026-43618

Rsync version3.4.2 and prior contain an integer overflow vulnerability ...

CVSS3: 8.1
1%
Низкий
2 месяца назад
ubuntu логотип
CVE-2026-29518

Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with symbolic links. Attackers with write access to a module path can exploit this race condition to create or overwrite arbitrary files, potentially modifying sensitive system files and achieving privilege escalation when the daemon runs with elevated privileges. This vulnerability can only be triggered if the chroot setting is false.

CVSS3: 7
0%
Низкий
2 месяца назад
redhat логотип
CVE-2026-29518

Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with symbolic links. Attackers with write access to a module path can exploit this race condition to create or overwrite arbitrary files, potentially modifying sensitive system files and achieving privilege escalation when the daemon runs with elevated privileges. This vulnerability can only be triggered if the chroot setting is false.

CVSS3: 7.8
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-29518

Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with symbolic links. Attackers with write access to a module path can exploit this race condition to create or overwrite arbitrary files, potentially modifying sensitive system files and achieving privilege escalation when the daemon runs with elevated privileges. This vulnerability can only be triggered if the chroot setting is false.

CVSS3: 7
0%
Низкий
2 месяца назад
msrc логотип
CVE-2026-29518

Rsync < 3.4.3 TOCTOU Race Condition Allows Symlink-Based Arbitrary File Write

CVSS3: 7
0%
Низкий
2 месяца назад
debian логотип
CVE-2026-29518

Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TO ...

CVSS3: 7
0%
Низкий
2 месяца назад

Уязвимостей на страницу