CVEs (1,928)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Gnome Redhat2Enterprise Linux LocalsearchJun 17, 2026 Jun 16, 2026 N/A· v4 8.1 HIGH· v3 N/A· v2 A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component. A remote attacker could exploit this heap buffer overflow vulnerability by providing a special...Show more |
2Gnome Redhat2Enterprise Linux LocalsearchJun 17, 2026 Jun 16, 2026 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracker-extract-mp3 component. This heap buffer overflow vulnerability occurs when processing specially cr...Show more |
2Gnome Redhat2Enterprise Linux LocalsearchJun 18, 2026 Jun 16, 2026 N/A· v4 5.6 MEDIUM· v3 N/A· v2 A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor. When processing specially crafted MP3 files containing ID3v2.4 tags, a missing bounds check in the `extract_performers_tags` funct...Show more |
3Abrt Project FedoraprojectRedhat4Abrt Automatic Bug Reporting ToolEnterprise Linux+1 moreAug 26, 2026 Jun 13, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal for log entries matching the crashed process and writes the results to...Show more |
3Abrt Project FedoraprojectRedhat4Abrt Automatic Bug Reporting ToolEnterprise Linux+1 moreAug 26, 2026 Jun 13, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replace...Show more |
2Mariadb Redhat2Enterprise Linux MariadbJul 30, 2026 Jun 12, 2026 6.9 MEDIUM· v4 9.1 CRITICAL· v3 N/A· v2 MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the datab...Show more |
2Js Cookie Redhat63scale Api Management Ansible Automation PlatformEnterprise Linux+3 moreSep 7, 2026 Jun 10, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version 3.0.7, js-cookie's internal assign() helper copies properties with for...in + plain assignment. When the source object is produced...Show more |
1Redhat 3389 Directory Server Directory ServerEnterprise LinuxJun 30, 2026 Jun 9, 2026 N/A· v4 4.9 MEDIUM· v3 N/A· v2 A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plugin does not enforce an upper bound on the iteration count extracted from stored password hashes. A privileged attacker who can modify a use...Show more |
1Redhat 3389 Directory Server Directory ServerEnterprise LinuxJun 30, 2026 Jun 9, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when computing salt length from a crafted password hash shorter than 16 bytes, causing a buffer over-read tha...Show more |
1Redhat 3389 Directory Server Directory ServerEnterprise LinuxAug 18, 2026 Jun 9, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the s...Show more |
1Redhat 3389 Directory Server Directory ServerEnterprise LinuxJun 30, 2026 Jun 9, 2026 N/A· v4 6.3 MEDIUM· v3 N/A· v2 A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a heap buffer over-read in string filter parsing that may influence interna...Show more |
1Redhat 3389 Directory Server Directory ServerEnterprise LinuxJun 30, 2026 Jun 9, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when processing attribute types with trailing semicolons during database import, causing an out-of-bounds read detectable unde...Show more |
1Redhat 3389 Directory Server Directory ServerEnterprise LinuxJun 30, 2026 Jun 9, 2026 N/A· v4 4.3 MEDIUM· v3 N/A· v2 A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation handler causes partial stack address information to be disclosed in LDAP responses to authenticated users. |
1Redhat 3389 Directory Server Directory ServerEnterprise LinuxJul 23, 2026 Jun 8, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in 389 Directory Server. The Content Synchronization persistent search plugin allows unbounded memory growth when an authenticated client stops reading sync responses, enabling denial of service. Additio...Show more |
2Redhat X.org3Enterprise Linux X ServerXwaylandJul 27, 2026 Jun 5, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DRI2BufferBackLeft attachments and one DRI2BufferFrontLeft can trigger an...Show more |
2Redhat X.org3Enterprise Linux X ServerXwaylandAug 5, 2026 Jun 5, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-after-free read after changing window attributes and forcing the screen saver, leading to information...Show more |
2Redhat X.org3Enterprise Linux X ServerXwaylandAug 5, 2026 Jun 5, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size validation check can read a client-controlled number of bytes, exceeding the request buffer, l...Show more |
2Redhat X.org3Enterprise Linux X ServerXwaylandAug 5, 2026 Jun 5, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a use-after-free when destroying those counters via a second client conne...Show more |
2Redhat X.org3Enterprise Linux X ServerXwaylandAug 5, 2026 Jun 5, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple SyncCounters and awaits on those triggers can trigger a use-after-free when destroying those counters vi...Show more |
2Redhat X.org3Enterprise Linux X ServerXwaylandAug 5, 2026 Jun 5, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. _XkbSetMapChecks() declares a fixed-size stack buffer mapWidths[256] indexed by key type index. The helper function CheckKeyTypes() writes...Show more |