CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Use after free in ANGLE in Google Chrome prior to 120.0.6099.199 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security sever...Show more |
3Fedoraproject Packagekit ProjectRedhat3Enterprise Linux FedoraPackagekitJun 17, 2026 Jan 3, 2024 N/A· v4 3.3 LOW· v3 N/A· v2 A use-after-free flaw was found in PackageKitd. In some conditions, the order of cleanup mechanics for a transaction could be impacted. As a result, some memory access could occur on memory regions that were previously f...Show more |
3Fedoraproject LibsshRedhat3Enterprise Linux FedoraLibsshJun 17, 2026 Jan 3, 2024 N/A· v4 4.8 MEDIUM· v3 N/A· v2 A flaw was found in libssh. By utilizing the ProxyCommand or ProxyJump feature, users can exploit unchecked hostname syntax on the client. This issue may allow an attacker to inject malicious code into the command of the...Show more |
3Fedoraproject QemuRedhat3Enterprise Linux FedoraQemuJun 17, 2026 Jan 2, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A stack based buffer overflow was found in the virtio-net device of QEMU. This issue occurs when flushing TX in the virtio_net_flush_tx function if guest features VIRTIO_NET_F_HASH_REPORT, VIRTIO_F_VERSION_1 and VIRTIO_N...Show more |
2Fedoraproject Sqlite2Fedora SqliteJun 17, 2026 Dec 29, 2023 N/A· v4 7.3 HIGH· v3 5.2 MEDIUM· v2 A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make alltest Handler. The m...Show more |
2Aomedia Fedoraproject2Aomedia FedoraJun 23, 2026 Dec 27, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc(). |
3Debian FedoraprojectJmcnamara3Debian Linux FedoraSpreadsheet\Jun 17, 2026 Dec 24, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file in...Show more |
3Fedoraproject OpenbsdRedhat3Enterprise Linux FedoraOpensshJun 17, 2026 Dec 24, 2023 N/A· v4 7.0 HIGH· v3 N/A· v2 OpenSSH through 10.0, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer value of authenticated in mm_answer_authpassword does not resist flips of a single...Show more |
3Debian EximFedoraproject4Debian Linux EximExtra Packages For Enterprise Linux+1 moreJun 17, 2026 Dec 24, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Exim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing byp...Show more |
3Fedoraproject PostfixRedhat3Enterprise Linux FedoraPostfixJun 17, 2026 Dec 24, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_keywords=chunking (or certain other options that exist in recent versions). Remot...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Dec 21, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
3Fedoraproject LinuxRedhat3Enterprise Linux FedoraLinux KernelJun 17, 2026 Dec 21, 2023 N/A· v4 7.0 HIGH· v3 N/A· v2 A race condition was found in the GSM 0710 tty multiplexor in the Linux kernel. This issue occurs when two threads execute the GSMIOC_SETCONF ioctl on the same tty file descriptor with the gsm line discipline enabled, an...Show more |
2Broadcom Fedoraproject3Extra Packages For Enterprise Linux FedoraTcpreplayJun 17, 2026 Dec 21, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Within tcpreplay's tcprewrite, a double free vulnerability has been identified in the tcpedit_dlt_cleanup() function within plugins/dlt_plugins.c. This vulnerability can be exploited by supplying a specifically crafted f...Show more |
2Fedoraproject Tats3Extra Packages For Enterprise Linux FedoraW3mJun 17, 2026 Dec 21, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An out-of-bounds write issue has been discovered in the backspace handling of the checkType() function in etc.c within the W3M application. This vulnerability is triggered by supplying a specially crafted HTML file to th...Show more |
3Fedoraproject LibsshRedhat3Enterprise Linux FedoraLibsshJun 17, 2026 Dec 19, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A flaw was found in the libssh implements abstract layer for message digest (MD) operations implemented by different supported crypto backends. The return values from these were not properly checked, which could cause lo...Show more |
429bis ApacheApple+39 more68Advanced Cluster Security AsyncsshCeph Storage+65 moreJun 17, 2026 Dec 18, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negoti...Show more |
3Fedoraproject PerlRedhat5Enterprise Linux Enterprise Linux AusEnterprise Linux Eus+2 moreJun 17, 2026 Dec 18, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A vulnerability was found in perl 5.30.0 through 5.38.0. This issue occurs when a crafted regular expression is compiled by perl, which can allow an attacker controlled byte buffer overflow in a heap allocated buffer. |
3Fedoraproject GoogleMicrosoft3Chrome Edge ChromiumFedoraJun 17, 2026 Dec 14, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Type confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
2Fedoraproject Redhat6Ansible Ansible Automation PlatformAnsible Developer+3 moreJun 17, 2026 Dec 12, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted...Show more |
When saving HSTS data to an excessively long file name, curl could end up
removing all contents, making subsequent requests using that file unaware of
the HSTS status they should otherwise use. |