CVEs (1,858)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker...Show more |
1Redhat 10Build Of Apache Camel Hawtio Build Of Apache Camel For Spring BootData Grid+7 moreJul 22, 2026 Mar 27, 2026 N/A· v4 9.1 CRITICAL· v3 N/A· v2 A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, whic...Show more |
1Redhat 10Build Of Apache Camel Hawtio Build Of Apache Camel For Spring BootData Grid+7 moreJun 29, 2026 Mar 27, 2026 N/A· v4 9.1 CRITICAL· v3 N/A· v2 A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in he...Show more |
2Firewalld Redhat2Enterprise Linux FirewalldJun 17, 2026 Mar 27, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in firewalld. A local unprivileged user can exploit this vulnerability by mis-authorizing two runtime D-Bus (Desktop Bus) setters, setZoneSettings2 and setPolicySettings. This mis-authorization allows th...Show more |
A flaw was found in GIMP. An integer overflow vulnerability exists when processing ICO image files, specifically in the `ico_read_info` and `ico_read_icon` functions. This issue arises because a size calculation for imag...Show more |
A flaw was found in GIMP. Heap-buffer-overflow vulnerability exists in the fread_pascal_string function when processing a specially crafted PSD (Photoshop Document) file. This occurs because the buffer allocated for a Pa...Show more |
2P11 Kit Project Redhat3Enterprise Linux Hardened ImagesP11 KitJul 19, 2026 Mar 26, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters set to NULL. This could...Show more |
A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an `SSH_FXP_NAME` message during a file listing operation. This mis...Show more |
2Libssh Redhat2Enterprise Linux LibsshJun 17, 2026 Mar 26, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could craft specific hostnames that when processed by the `match_pattern()` function can lead to inefficient...Show more |
2Libssh Redhat4Enterprise Linux Hardened ImagesLibssh+1 moreJun 17, 2026 Mar 26, 2026 N/A· v4 8.2 HIGH· v3 N/A· v2 A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited remotely by an attacker during GSSAPI (Generic Security Service...Show more |
A flaw was found in libssh where it can attempt to open arbitrary files during configuration parsing. A local attacker can exploit this by providing a malicious configuration file or when the system is misconfigured. Thi...Show more |
2Libssh Redhat4Enterprise Linux Hardened ImagesLibssh+1 moreJun 17, 2026 Mar 26, 2026 N/A· v4 6.3 MEDIUM· v3 N/A· v2 A malicious SCP server can send unexpected paths that could make the client application override local files outside of working directory. This could be misused to create malicious executable or configuration files and m...Show more |
A flaw was found in libsoup's SoupServer. A remote attacker could exploit a use-after-free vulnerability where the `soup_server_disconnect()` function frees connection objects prematurely, even if a TLS handshake is stil...Show more |
2Freedesktop Redhat3Enterprise Linux Openshift Container PlatformPolkitJun 17, 2026 Mar 26, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in polkit. A local user can exploit this by providing a specially crafted, excessively long input to the `polkit-agent-helper-1` setuid binary via standard input (stdin). This unbounded input can lead to...Show more |
3Debian LibtiffRedhat4Debian Linux Enterprise LinuxHardened Images+1 moreJul 15, 2026 Mar 24, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile function by providing a specially crafted TIFF file. This flaw can lead to...Show more |
1Redhat 10Build Of Apache Camel Hawtio Build Of Apache Camel For Spring BootData Grid+7 moreJul 7, 2026 Mar 24, 2026 N/A· v4 N/A· v3 N/A· v2 Rejected reason: The Undertow web server enforces a default maximum HTTP request entity size limit. Any request (including GET or HEAD) containing a body that exceeds this configurable limit is safely dropped by the serv...Show more |
4Debian FreedesktopGstreamer+1 more4Debian Linux Enterprise LinuxGst Plugins Good+1 moreJun 17, 2026 Mar 23, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function. The patch added a size validation check lsize + 8 > size, but it does not account for the GST_ROUND_UP_2(lsize) use...Show more |
2Gnu Redhat3Binutils Enterprise LinuxOpenshift Container PlatformJul 15, 2026 Mar 23, 2026 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a rel...Show more |
2Libarchive Redhat4Enterprise Linux Hardened ImagesLibarchive+1 moreJun 17, 2026 Mar 19, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote atta...Show more |
2Libarchive Redhat7Enterprise Linux Enterprise Linux Server AusHardened Images+4 moreJul 15, 2026 Mar 19, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression metho...Show more |