CVEs (1,845)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Debian FedoraprojectLinux+2 more12500f Firmware A250 FirmwareC250 Firmware+9 moreOct 27, 2025 Jan 31, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the...Show more |
4Fedoraproject RedhatTigervnc+1 more12Enterprise Linux Enterprise Linux DesktopEnterprise Linux For Ibm Z Systems+9 moreAug 29, 2025 Jan 18, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 A flaw was found in the X.Org server. The cursor code in both Xephyr and Xwayland uses the wrong type of private at creation. It uses the cursor bits type with the cursor as private, and when initiating the cursor, that...Show more |
4Fedoraproject RedhatTigervnc+1 more12Enterprise Linux Enterprise Linux DesktopEnterprise Linux For Ibm Z Systems+9 moreAug 29, 2025 Jan 18, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in the X.Org server. The GLX PBuffer code does not call the XACE hook when creating the buffer, leaving it unlabeled. When the client issues another request to access that resource (as with a GetGeometry...Show more |
4Debian FedoraprojectRedhat+1 more7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreMar 19, 2026 Jan 18, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for each logical button currently down. Buttons can be arbitrarily mapped to any value up to 255, but the X.Org Server wa...Show more |
3Fedoraproject FreeipaRedhat21Codeready Linux Builder Enterprise LinuxEnterprise Linux Desktop+18 moreMar 18, 2026 Jan 10, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the...Show more |
2Postgresql Redhat21Codeready Linux Builder Eus Codeready Linux Builder Eus For Power Little Endian EusCodeready Linux Builder For Arm64 Eus+18 moreNov 4, 2025 Dec 10, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A flaw was found in PostgreSQL that allows authenticated database users to execute arbitrary code through missing overflow checks during SQL array value modification. This issue exists due to an integer overflow during a...Show more |
2Redhat Squid Cache10Enterprise Linux Enterprise Linux EusEnterprise Linux For Arm 64+7 moreNov 21, 2024 Nov 3, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication...Show more |
4Debian FedoraprojectRedhat+1 more12Debian Linux Enterprise LinuxEnterprise Linux Desktop+9 moreNov 4, 2025 Oct 25, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect calculation of a buffer offset when copying data stored in the heap in the XIChangeDeviceProperty function in Xi/xiproper...Show more |
2Fedoraproject Redhat20Enterprise Linux Enterprise Linux DesktopEnterprise Linux Eus+17 moreNov 21, 2024 Aug 23, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization. The D-Bus interface com.redhat.RHSM1 exposes a significant number of methods to all users that cou...Show more |
3Redhat WebkitgtkWpewebkit23Codeready Linux Builder Codeready Linux Builder EusCodeready Linux Builder For Arm64 Eus+20 moreNov 18, 2025 Mar 6, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issu...Show more |
2Fedoraproject Redhat13Enterprise Linux Enterprise Linux DesktopEnterprise Linux For Ibm Z Systems+10 moreMar 27, 2025 Feb 1, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters |
3Ibm RedhatSuse8Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+5 moreNov 21, 2024 Sep 29, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR1 FP10, 7 R1 before SR3 FP10, 7 before SR9 FP10, 6 R1 before SR8 FP7, 6 before SR16 FP7, and 5.0 before SR16 FP13 stores plaintext information i...Show more |
2Qemu Redhat9Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Openstack Platform+6 moreNov 21, 2024 Sep 29, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Qemu before 2.0 block driver for Hyper-V VHDX Images is vulnerable to infinite loops and other potential issues when calculating BAT entries, due to missing bounds checks for block_size and logical_sector_size variables....Show more |
3Fedoraproject QemuRedhat10Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Openstack Platform+7 moreNov 21, 2024 Sep 29, 2022 N/A· v4 6.2 MEDIUM· v3 N/A· v2 Qemu before 1.6.2 block diver for the various disk image formats used by Bochs and for the QCOW version 2 format, are vulnerable to a possible crash caused by signed data types or a logic error while creating QCOW2 snaps...Show more |
2Qemu Redhat9Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Openstack Platform+6 moreNov 21, 2024 Sep 29, 2022 N/A· v4 8.6 HIGH· v3 N/A· v2 QEMU before 2.0.0 block drivers for CLOOP, QCOW2 version 2 and various other image formats are vulnerable to potential memory corruptions, integer/buffer overflows or crash caused by missing input validations which could...Show more |
2Podman Project Redhat3Enterprise Linux Server Enterprise Linux WorkstationPodmanNov 21, 2024 Sep 1, 2022 N/A· v4 5.3 MEDIUM· v3 N/A· v2 The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing the fix for CVE-2020-14370, which was previously fixed via RHSA-2020:505...Show more |
2Podman Project Redhat3Enterprise Linux Server Enterprise Linux WorkstationPodmanNov 21, 2024 Sep 1, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing the fix for CVE-2020-8945, which was previously fixed via RHSA-2020:2117...Show more |
4Fedoraproject Podman ProjectPsgo Project+1 more16Developer Tools Enterprise LinuxEnterprise Linux Eus+13 moreNov 21, 2024 Apr 29, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a...Show more |
4Fedoraproject LinuxNetapp+1 more383scale Api Management Codeready Linux BuilderCodeready Linux Builder Eus+35 moreNov 21, 2024 Mar 25, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may run malicious code on the GPU. This flaw allows a local user to crash the system or escalate their pr...Show more |
3Fedoraproject LinuxRedhat263scale Api Management Codeready Linux BuilderEnterprise Linux+23 moreNov 21, 2024 Mar 4, 2022 N/A· v4 8.8 HIGH· v3 7.2 HIGH· v2 A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due...Show more |