CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Fedoraproject LinuxRedhat3Enterprise Linux FedoraLinux KernelJun 17, 2026 Aug 5, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 A flaw was found in KVM. When updating a guest's page table entry, vm_pgoff was improperly used as the offset to get the page's pfn. As vaddr and vm_pgoff are controllable by user-mode processes, this flaw allows unprivi...Show more |
6Apple DebianFedoraproject+3 more18Active Iq Unified Manager Debian LinuxFedora+15 moreJul 14, 2026 Aug 5, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applicati...Show more |
3Debian FedoraprojectPostgresql3Debian Linux FedoraPostgresql Jdbc DriverJun 17, 2026 Aug 3, 2022 N/A· v4 8.0 HIGH· v3 N/A· v2 PostgreSQL JDBC Driver (PgJDBC for short) allows Java programs to connect to a PostgreSQL database using standard, database independent Java code. The PGJDBC implementation of the `java.sql.ResultRow.refreshRow()` method...Show more |
An issue was discovered in rsync before 3.2.5 that allows malicious remote servers to write arbitrary files inside the directories of connecting peers. The server chooses which files/directories are sent to the client. H...Show more |
2Fedoraproject Rust Websocket Project2Fedora Rust WebsocketJun 17, 2026 Aug 1, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Rust-WebSocket is a WebSocket (RFC6455) library written in Rust. In versions prior to 0.26.5 untrusted websocket connections can cause an out-of-memory (OOM) process abort in a client or a server. The root cause of the i...Show more |
2Fedoraproject Nlnetlabs2Fedora UnboundJun 17, 2026 Aug 1, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 NLnet Labs Unbound, up to and including version 1.16.1, is vulnerable to a novel type of the "ghost domain names" attack. The vulnerability works by targeting an Unbound instance. Unbound is queried for a rogue domain na...Show more |
2Fedoraproject Nlnetlabs2Fedora UnboundJun 17, 2026 Aug 1, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 NLnet Labs Unbound, up to and including version 1.16.1 is vulnerable to a novel type of the "ghost domain names" attack. The vulnerability works by targeting an Unbound instance. Unbound is queried for a subdomain of a r...Show more |
4Debian FedoraprojectGnu+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Aug 1, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability found in gnutls. This security flaw happens because of a double free error occurs during verification of pkcs7 signatures in gnutls_pkcs7_verify function. |
4Debian FedoraprojectLibtiff+1 more5Active Iq Unified Manager Debian LinuxFedora+2 moreJun 17, 2026 Jul 29, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A stack overflow was discovered in the _TIFFVGetField function of Tiffsplit v4.4.0. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted TIFF file parsed by the "tiffsplit" or "tiffcrop" u...Show more |
2Fedoraproject Squirrel Lang2Fedora SquirrelJun 17, 2026 Jul 28, 2022 N/A· v4 10.0 CRITICAL· v3 N/A· v2 sqclass.cpp in Squirrel through 2.2.5 and 3.x through 3.1 allows an out-of-bounds read (in the core interpreter) that can lead to Code Execution. If a victim executes an attacker-controlled squirrel script, it is possibl...Show more |
3Clusterlabs DebianFedoraproject3Booth Debian LinuxFedoraJun 17, 2026 Jul 28, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a result, nodes that do not have the correct authentication key are not prevented from...Show more |
2Fedoraproject Google3Chrome Extra Packages For Enterprise LinuxFedoraJun 17, 2026 Jul 28, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Use after free in Chrome OS Shell in Google Chrome on Chrome OS prior to 103.0.5060.114 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via di...Show more |
2Fedoraproject Google3Chrome Extra Packages For Enterprise LinuxFedoraJun 17, 2026 Jul 28, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Type confusion in V8 in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
6Apple FedoraprojectGoogle+3 more12Chrome Extra Packages For Enterprise LinuxFedora+9 moreJun 17, 2026 Jul 28, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
2Fedoraproject Google3Chrome Extra Packages For Enterprise LinuxFedoraJun 17, 2026 Jul 28, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Use after free in Cast UI and Toolbar in Google Chrome prior to 103.0.5060.134 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via UI interaction. |
Insufficient data validation in URL formatting in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name. |
Inappropriate implementation in Extensions API in Google Chrome prior to 103.0.5060.53 allowed an attacker who convinced a user to install a malicious extension to bypass discretionary access control via a crafted HTML p...Show more |
Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 103.0.5060.53 allowed a remote attacker to bypass file system access via a crafted HTML page. |
Use after free in WebApp Provider in Google Chrome prior to 103.0.5060.53 allowed a remote attacker who convinced the user to engage in specific user interactions to potentially exploit heap corruption via specific UI in...Show more |
Insufficient policy enforcement in DevTools in Google Chrome on Windows prior to 103.0.5060.53 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from a...Show more |