CVEs (779)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Qemu Redhat9Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Openstack Platform+6 moreNov 21, 2024 Sep 29, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Qemu before 2.0 block driver for Hyper-V VHDX Images is vulnerable to infinite loops and other potential issues when calculating BAT entries, due to missing bounds checks for block_size and logical_sector_size variables....Show more |
3Fedoraproject QemuRedhat10Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Openstack Platform+7 moreNov 21, 2024 Sep 29, 2022 N/A· v4 6.2 MEDIUM· v3 N/A· v2 Qemu before 1.6.2 block diver for the various disk image formats used by Bochs and for the QCOW version 2 format, are vulnerable to a possible crash caused by signed data types or a logic error while creating QCOW2 snaps...Show more |
2Qemu Redhat9Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Openstack Platform+6 moreNov 21, 2024 Sep 29, 2022 N/A· v4 8.6 HIGH· v3 N/A· v2 QEMU before 2.0.0 block drivers for CLOOP, QCOW2 version 2 and various other image formats are vulnerable to potential memory corruptions, integer/buffer overflows or crash caused by missing input validations which could...Show more |
5Canonical DebianFedoraproject+2 more14Codeready Linux Builder Debian LinuxEnterprise Linux+11 moreNov 21, 2024 Aug 23, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock. This flaw could be tr...Show more |
5Debian FedoraprojectLibarchive+2 more14Codeready Linux Builder Debian LinuxEnterprise Linux+11 moreNov 21, 2024 Aug 23, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control lists, and flags of a file outside of the archive. An attacker may provide a malicious archive to a...Show more |
4Debian FedoraprojectLibarchive+1 more13Codeready Linux Builder Debian LinuxEnterprise Linux+10 moreNov 21, 2024 Aug 23, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacker may provide a malicious archive to a victim user, who would trigger t...Show more |
3Debian RedhatSamba7Debian Linux Enterprise LinuxEnterprise Linux Aus+4 moreNov 21, 2024 Aug 23, 2022 N/A· v4 6.8 MEDIUM· v3 N/A· v2 A flaw was found in the way Samba handled file/directory metadata. This flaw allows an authenticated attacker with permissions to read or modify share metadata, to perform this operation outside of the share. |
2Gnu Redhat12Codeready Linux Builder Developer ToolsEnterprise Linux+9 moreNov 21, 2024 Jul 6, 2022 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written in heap. To a successful to be performed the attacker needs to perform some triage over the heap la...Show more |
3Gnu NetappRedhat13Codeready Linux Builder Developer ToolsEnterprise Linux+10 moreNov 21, 2024 Jul 6, 2022 N/A· v4 4.5 MEDIUM· v3 6.9 MEDIUM· v2 A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corruption in the heap space. Confidentiality, Integrity and Availablity impact may be considered Low a...Show more |
4Fedoraproject GnuNetapp+1 more14Codeready Linux Builder Developer ToolsEnterprise Linux+11 moreNov 21, 2024 Jul 6, 2022 N/A· v4 4.5 MEDIUM· v3 4.4 MEDIUM· v2 A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and circumvent secure b...Show more |
4Fedoraproject Podman ProjectPsgo Project+1 more16Developer Tools Enterprise LinuxEnterprise Linux Eus+13 moreNov 21, 2024 Apr 29, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a...Show more |
3Fedoraproject Podman ProjectRedhat14Developer Tools Enterprise LinuxEnterprise Linux Eus+11 moreNov 21, 2024 Apr 4, 2022 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker Engine), where containers were started incorrectly with non-empty inheri...Show more |
5Fedoraproject LinuxNetapp+2 more30Codeready Linux Builder Codeready Linux Builder EusCodeready Linux Builder Eus For Power Little Endian+27 moreNov 21, 2024 Mar 25, 2022 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with malicious content where the number of domain member nodes is higher than the 64 allowed. This flaw a...Show more |
4Fedoraproject LinuxNetapp+1 more383scale Api Management Codeready Linux BuilderCodeready Linux Builder Eus+35 moreNov 21, 2024 Mar 25, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may run malicious code on the GPU. This flaw allows a local user to crash the system or escalate their pr...Show more |
6Debian FedoraprojectLinux+3 more30Build Of Quarkus Codeready Linux BuilderCommunications Cloud Native Core Binding Support Function+27 moreNov 21, 2024 Mar 18, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allows a local user to gain unauthorized access to data from the FUSE filesystem, resulting in privilege...Show more |
7Fedoraproject LinuxNetapp+4 more29Codeready Linux Builder Enterprise LinuxEnterprise Linux Eus+26 moreNov 6, 2025 Mar 10, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values....Show more |
5Debian FedoraprojectLinux+2 more23Codeready Linux Builder Debian LinuxEnterprise Linux+20 moreNov 21, 2024 Mar 10, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A vulnerability was found in kvm_s390_guest_sida_op in the arch/s390/kvm/kvm-s390.c function in KVM for s390 in the Linux kernel. This flaw allows a local attacker with a normal user privilege to obtain unauthorized memo...Show more |
4Fedoraproject NetappPython+1 more20Codeready Linux Builder Codeready Linux Builder For Ibm Z SystemsCodeready Linux Builder For Power Little Endian+17 moreNov 3, 2025 Mar 10, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReD...Show more |
3Fedoraproject LinuxRedhat263scale Api Management Codeready Linux BuilderEnterprise Linux+23 moreNov 21, 2024 Mar 4, 2022 N/A· v4 8.8 HIGH· v3 7.2 HIGH· v2 A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due...Show more |
5Debian FedoraprojectLinux+2 more23Build Of Quarkus Codeready Linux BuilderCodeready Linux Builder Eus+20 moreNov 21, 2024 Mar 4, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A memory leak flaw was found in the Linux kernel in the ccp_run_aes_gcm_cmd() function in drivers/crypto/ccp/ccp-ops.c, which allows attackers to cause a denial of service (memory consumption). This vulnerability is simi...Show more |