CVEs (779)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
6Canonical DebianFedoraproject+3 more37Bootstrap Os Codeready Linux BuilderCodeready Linux Builder For Power Little Endian+34 moreJun 3, 2026 Mar 3, 2022 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to esca...Show more |
3Linux NetappRedhat323scale Api Management Build Of QuarkusCodeready Linux Builder Eus+29 moreNov 21, 2024 Mar 3, 2022 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 .A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can abuse a flaw in the CAN subsystem to corrupt memory, crash the system or escalate privileges. This race condition in ne...Show more |
6Canonical DebianFedoraproject+3 more23Codeready Linux Builder Debian LinuxDiskstation Manager+20 moreApr 23, 2025 Feb 21, 2022 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4...Show more |
5Canonical DebianFedoraproject+2 more17Debian Linux Enterprise LinuxEnterprise Linux Desktop+14 moreNov 21, 2024 Feb 18, 2022 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not strictl...Show more |
5Canonical DebianFedoraproject+2 more25Codeready Linux Builder Debian LinuxEnterprise Linux+22 moreNov 21, 2024 Feb 18, 2022 N/A· v4 8.1 HIGH· v3 8.5 HIGH· v2 A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalation. |
5Canonical DebianFedoraproject+2 more24Codeready Linux Builder Debian LinuxEnterprise Linux+21 moreNov 21, 2024 Feb 18, 2022 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required. |
4Dogtagpki FedoraprojectOracle+1 more12Dogtagpki Enterprise LinuxEnterprise Linux Eus+9 moreNov 21, 2024 Feb 16, 2022 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the installation log file. This flaw allows a local attacker to retrieve the file to obtain the admin p...Show more |
7Canonical OraclePolkit Project+4 more30Command Center Enterprise LinuxEnterprise Linux Desktop+27 moreNov 6, 2025 Jan 28, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined polic...Show more |
2Fedoraproject Redhat8Enterprise Linux Enterprise Linux EusEnterprise Linux Server Aus+5 moreNov 3, 2025 Dec 23, 2021 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially c...Show more |
6C Ares Project FedoraprojectNodejs+3 more17C Ares Enterprise LinuxEnterprise Linux Computer Node+14 moreNov 21, 2024 Nov 23, 2021 N/A· v4 5.6 MEDIUM· v3 6.8 MEDIUM· v2 A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The h...Show more |
11Apache BroadcomDebian+8 more39Brocade Fabric Operating System Firmware Cloud BackupClustered Data Ontap+36 moreOct 27, 2025 Sep 16, 2021 N/A· v4 9.0 CRITICAL· v3 6.8 MEDIUM· v2 A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. |
4Debian FedoraprojectLinuxptp Project+1 more7Debian Linux Enterprise LinuxEnterprise Linux Aus+4 moreNov 21, 2024 Jul 9, 2021 N/A· v4 8.8 HIGH· v3 8.0 HIGH· v2 A flaw was found in the ptp4l program of the linuxptp package. A missing length check when forwarding a PTP message between ports allows a remote attacker to cause an information leak, crash, or potentially remote code e...Show more |
2Netapp Redhat13Codeready Linux Builder Enterprise LinuxEnterprise Linux Eus+10 moreNov 21, 2024 May 27, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies used to access network-based disks were saved in the XML dump of the guest domain. This flaw allows an attacker to acces...Show more |
5Canonical DebianOpensuse+2 more10Debian Linux Enterprise LinuxEnterprise Linux Aus+7 moreNov 21, 2024 Oct 7, 2020 N/A· v4 6.6 MEDIUM· v3 6.5 MEDIUM· v2 Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws....Show more |
3Fedoraproject MicrosoftRedhat6Asp.net Core Enterprise LinuxEnterprise Linux Aus+3 moreFeb 23, 2026 Sep 11, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 <p>A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.</p> <p>The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker...Show more |
7Apache CanonicalDebian+4 more25Communications Element Manager Communications Session Report ManagerCommunications Session Route Manager+22 moreNov 21, 2024 Aug 7, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Confi...Show more |
4Canonical GnuOpensuse+1 more7Enterprise Linux Enterprise Linux EusEnterprise Linux Server Aus+4 moreNov 21, 2024 Jul 31, 2020 N/A· v4 6.0 MEDIUM· v3 3.6 LOW· v2 There is an issue with grub2 before version 2.06 while handling symlink on ext filesystems. A filesystem containing a symbolic link with an inode size of UINT32_MAX causes an arithmetic overflow leading to a zero-sized m...Show more |
4Canonical GnuOpensuse+1 more7Enterprise Linux Enterprise Linux EusEnterprise Linux Server Aus+4 moreNov 21, 2024 Jul 31, 2020 N/A· v4 6.0 MEDIUM· v3 3.6 LOW· v2 There is an issue on grub2 before version 2.06 at function read_section_as_string(). It expects a font name to be at max UINT32_MAX - 1 length in bytes but it doesn't verify it before proceed with buffer allocation to re...Show more |
5Debian NodejsOpensuse+2 more7Communications Cloud Native Core Network Function Cloud Native Environment Debian LinuxEnterprise Linux+4 moreNov 21, 2024 Feb 7, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons |
6Debian FedoraprojectNodejs+3 more13Debian Linux Enterprise LinuxEnterprise Linux Desktop+10 moreNov 21, 2024 Feb 7, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed |