CVEs (768)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Gnome Redhat4Enterprise Linux Enterprise Linux Server AusEnterprise Linux Server Tus+1 moreJul 15, 2026 Mar 31, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component counts when processing a specially crafted JPEG imag...Show more |
2Gnome Redhat29Ceph Storage Codeready Linux BuilderCodeready Linux Builder For Arm64+26 moreJun 30, 2026 Nov 26, 2025 N/A· v4 7.7 HIGH· v3 N/A· v2 A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable character...Show more |
2Redhat Xmlsoft20Enterprise Linux Enterprise Linux EusEnterprise Linux For Arm 64+17 moreJun 30, 2026 Jun 12, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when...Show more |
3Debian GnomeRedhat21Codeready Linux Builder Codeready Linux Builder For Arm64Codeready Linux Builder For Arm64 Eus+18 moreJun 29, 2026 Apr 3, 2025 N/A· v4 7.4 HIGH· v3 N/A· v2 A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an ex...Show more |
2Gnome Redhat21Codeready Linux Builder Codeready Linux Builder For Arm64Codeready Linux Builder For Arm64 Eus+18 moreJun 30, 2026 Apr 3, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_insight_whitespace() function. Libsoup clients may read one byte out-of-bounds in response to a crafted...Show more |
8Almalinux ArchlinuxGentoo+5 more22Almalinux Arch LinuxEnterprise Linux+19 moreJul 20, 2026 Jan 14, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized...Show more |
2Buildah Project Redhat14Buildah Enterprise LinuxEnterprise Linux Eus+11 moreJun 29, 2026 Oct 9, 2024 N/A· v4 4.4 MEDIUM· v3 N/A· v2 A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in a Container file to mount an arbitrary d...Show more |
2Fedoraproject Redhat23Codeready Linux Builder Codeready Linux Builder EusCodeready Linux Builder For Arm64+20 moreJun 17, 2026 Apr 18, 2024 N/A· v4 7.1 HIGH· v3 N/A· v2 A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denying access to resources inappropriately. |
2Fedoraproject Redhat19Codeready Linux Builder Codeready Linux Builder EusCodeready Linux Builder Eus For Power Little Endian+16 moreJun 17, 2026 Feb 15, 2024 N/A· v4 7.3 HIGH· v3 N/A· v2 A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953,...Show more |
2Fedoraproject Redhat13389 Directory Server Directory ServerEnterprise Linux+10 moreJun 17, 2026 Feb 12, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than 256 chars in log_entry_attr. |
3Debian LinuxRedhat17Codeready Linux Builder Eus Codeready Linux Builder Eus For Power Little Endian EusCodeready Linux Builder For Arm64 Eus+14 moreJun 17, 2026 Feb 7, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer derefe...Show more |
2Linux Redhat16Codeready Linux Builder Eus Codeready Linux Builder Eus For Power Little Endian EusCodeready Linux Builder For Arm64 Eus+13 moreJun 17, 2026 Feb 7, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer derefe...Show more |
3Debian LinuxRedhat17Codeready Linux Builder Eus Codeready Linux Builder Eus For Power Little Endian EusCodeready Linux Builder For Arm64 Eus+14 moreJun 17, 2026 Feb 7, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer derefe...Show more |
3Fedoraproject FreeipaRedhat21Codeready Linux Builder Enterprise LinuxEnterprise Linux Desktop+18 moreJun 17, 2026 Jan 10, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the...Show more |
2Postgresql Redhat16Codeready Linux Builder Eus Codeready Linux Builder Eus For Power Little Endian EusCodeready Linux Builder For Arm64 Eus+13 moreJun 17, 2026 Dec 10, 2023 N/A· v4 4.4 MEDIUM· v3 N/A· v2 A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum workers, and the autovacuum launcher. Successful exploitation re...Show more |
2Postgresql Redhat21Codeready Linux Builder Eus Codeready Linux Builder Eus For Power Little Endian EusCodeready Linux Builder For Arm64 Eus+18 moreJun 17, 2026 Dec 10, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A flaw was found in PostgreSQL that allows authenticated database users to execute arbitrary code through missing overflow checks during SQL array value modification. This issue exists due to an integer overflow during a...Show more |
2Postgresql Redhat16Codeready Linux Builder Eus Codeready Linux Builder Eus For Power Little Endian EusCodeready Linux Builder For Arm64 Eus+13 moreJun 23, 2026 Dec 10, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by exploiting certain aggregate function calls with 'unknown'-type arguments. Handling 'unknown'-type val...Show more |
2Linux Redhat6Enterprise Linux Enterprise Linux EusEnterprise Linux For Power Little Endian+3 moreJun 17, 2026 Nov 3, 2023 N/A· v4 7.0 HIGH· v3 N/A· v2 A use-after-free flaw was found in the Linux kernel’s mm/mremap memory address space accounting source code. This issue occurs due to a race condition between rmap walk and mremap, allowing a local user to crash the syst...Show more |
2Redhat Squid Cache5Enterprise Linux Enterprise Linux EusEnterprise Linux Server Aus+2 moreJun 17, 2026 Nov 3, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Squid is vulnerable to Denial of Service, where a remote attacker can perform DoS by sending ftp:// URLs in HTTP Request messages or constructing ftp:// URLs from FTP Native input. |
2Redhat Squid Cache10Enterprise Linux Enterprise Linux EusEnterprise Linux For Arm 64+7 moreJun 17, 2026 Nov 3, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication...Show more |