CVEs (24)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
12Amazon AristaCanonical+9 more45Amazon Linux Basesystem ModuleCaas Platform+42 moreJul 15, 2026 Apr 22, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is...Show more |
4Debian IbmRedhat+1 more11Aix Debian LinuxEnterprise Linux+8 moreJul 1, 2026 Oct 30, 2025 N/A· v4 7.3 HIGH· v3 N/A· v2 A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-af...Show more |
4Debian IbmRedhat+1 more11Aix Debian LinuxEnterprise Linux+8 moreJul 1, 2026 Oct 30, 2025 N/A· v4 7.3 HIGH· v3 N/A· v2 A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If an attacker sends specially crafted input...Show more |
4Apple RedhatWebkitgtk+1 more15Enterprise Linux Enterprise Linux AusEnterprise Linux Els+12 moreJul 15, 2026 Jul 30, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content m...Show more |
1Redhat 5Enterprise Linux Enterprise Linux AusEnterprise Linux Eus+2 moreJun 17, 2026 Jun 12, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 A vulnerability was found in FreeIPA in a way when a Kerberos TGS-REQ is encrypted using the client’s session key. This key is different for each new session, which protects it from brute force attacks. However, the tick...Show more |
3Fedoraproject RedhatX.org8Enterprise Linux Enterprise Linux AusEnterprise Linux Eus+5 moreJun 17, 2026 Feb 9, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 An out-of-bounds memory access flaw was found in the X.Org server. This issue can be triggered when a device frozen by a sync grab is reattached to a different master device. This issue may lead to an application crash,...Show more |
3Fedoraproject GnuRedhat22Codeready Linux Builder Eus Codeready Linux Builder Eus For Power Little EndianCodeready Linux Builder Eus For Power Little Endian Eus+19 moreJul 14, 2026 Sep 18, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A flaw has been identified in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an application crash. This issue is only exploitable when a NSS module imp...Show more |
4Fedoraproject GnuNetapp+1 more27Codeready Linux Builder Eus Codeready Linux Builder Eus For Power Little EndianCodeready Linux Builder Eus For Power Little Endian Eus+24 moreJun 17, 2026 Sep 18, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can...Show more |
3Debian RedhatSamba7Debian Linux Enterprise LinuxEnterprise Linux Aus+4 moreJun 17, 2026 Aug 23, 2022 N/A· v4 6.8 MEDIUM· v3 N/A· v2 A flaw was found in the way Samba handled file/directory metadata. This flaw allows an authenticated attacker with permissions to read or modify share metadata, to perform this operation outside of the share. |
5Canonical DebianFedoraproject+2 more25Codeready Linux Builder Debian LinuxEnterprise Linux+22 moreJun 17, 2026 Feb 18, 2022 N/A· v4 8.1 HIGH· v3 8.5 HIGH· v2 A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalation. |
5Canonical DebianFedoraproject+2 more24Codeready Linux Builder Debian LinuxEnterprise Linux+21 moreNov 21, 2024 Feb 18, 2022 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required. |
6C Ares Project FedoraprojectNodejs+3 more17C Ares Enterprise LinuxEnterprise Linux Computer Node+14 moreJun 17, 2026 Nov 23, 2021 N/A· v4 5.6 MEDIUM· v3 6.8 MEDIUM· v2 A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The h...Show more |
4Debian FedoraprojectLinuxptp Project+1 more7Debian Linux Enterprise LinuxEnterprise Linux Aus+4 moreJun 17, 2026 Jul 9, 2021 N/A· v4 8.8 HIGH· v3 8.0 HIGH· v2 A flaw was found in the ptp4l program of the linuxptp package. A missing length check when forwarding a PTP message between ports allows a remote attacker to cause an information leak, crash, or potentially remote code e...Show more |
2Netapp Redhat13Codeready Linux Builder Enterprise LinuxEnterprise Linux Eus+10 moreJun 17, 2026 May 27, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies used to access network-based disks were saved in the XML dump of the guest domain. This flaw allows an attacker to acces...Show more |
5Canonical DebianOpensuse+2 more10Debian Linux Enterprise LinuxEnterprise Linux Aus+7 moreJun 17, 2026 Oct 7, 2020 N/A· v4 6.6 MEDIUM· v3 6.5 MEDIUM· v2 Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws....Show more |
3Fedoraproject MicrosoftRedhat6Asp.net Core Enterprise LinuxEnterprise Linux Aus+3 moreJun 17, 2026 Sep 11, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 <p>A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.</p> <p>The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker...Show more |
7Canonical DebianMcafee+4 more24Active Iq Unified Manager Debian LinuxE Series Performance Analyzer+21 moreJun 17, 2026 Jan 15, 2020 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Security). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exp...Show more |
7Canonical DebianFedoraproject+4 more39A220 Firmware A320 FirmwareA700s Firmware+36 moreJun 17, 2026 Sep 20, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 There is heap-based buffer overflow in kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute ar...Show more |
7Apple CanonicalDebian+4 more147Alp Al00b Firmware AndroidAres Al00b Firmware+144 moreJun 17, 2026 Aug 14, 2019 N/A· v4 8.1 HIGH· v3 4.8 MEDIUM· v2 The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-...Show more |
6Canonical ClusterlabsDebian+3 more9Debian Linux Enterprise LinuxEnterprise Linux Aus+6 moreNov 21, 2024 Apr 18, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A flaw was found in pacemaker up to and including version 2.0.1. An insufficient verification inflicted preference of uncontrolled processes can lead to DoS |