CVEs (1,858)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Libarchive Redhat3Enterprise Linux LibarchiveOpenshift Container PlatformJun 30, 2026 Jun 9, 2025 N/A· v4 5.0 MEDIUM· v3 N/A· v2 A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes for file names. This can lead to a 1-byte write overflow. While seeming...Show more |
2Libarchive Redhat3Enterprise Linux LibarchiveOpenshift Container PlatformJun 30, 2026 Jun 9, 2025 N/A· v4 5.6 MEDIUM· v3 N/A· v2 A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content by...Show more |
2Libarchive Redhat3Enterprise Linux LibarchiveOpenshift Container PlatformJun 30, 2026 Jun 9, 2025 N/A· v4 6.6 MEDIUM· v3 N/A· v2 A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This mean...Show more |
2Libarchive Redhat3Enterprise Linux LibarchiveOpenshift Container PlatformJul 21, 2026 Jun 9, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condit...Show more |
2Nbdkit Project Redhat3Enterprise Linux Enterprise Linux Advanced VirtualizationNbdkitJun 30, 2026 Jun 9, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 There's a flaw in the nbdkit server when handling responses from its plugins regarding the status of data blocks. If a client makes a specific request for a very large data range, and a plugin responds with an even large...Show more |
5Debian LinuxOracle+2 more6Debian Linux Enterprise LinuxLinux+3 moreJun 30, 2026 May 30, 2025 N/A· v4 4.7 MEDIUM· v3 N/A· v2 A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attack...Show more |
2Freerdp Redhat2Enterprise Linux FreerdpJun 30, 2026 May 16, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in the FreeRDP used by Anaconda's remote install feature, where a crafted RDP packet could trigger a segmentation fault. This issue causes the service to crash and remain defunct, resulting in a denial o...Show more |
3Apache DebianRedhat3Debian Linux Enterprise LinuxHttp ServerJun 29, 2026 Apr 29, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is...Show more |
2Fig2dev Project Redhat2Enterprise Linux Fig2devJun 30, 2026 Apr 23, 2025 N/A· v4 5.5 MEDIUM· v3 N/A· v2 In xfig diagramming tool, a segmentation fault while running fig2dev allows an attacker to availability via local input manipulation via read_arcobject function. |
2Fig2dev Project Redhat2Enterprise Linux Fig2devJun 30, 2026 Apr 23, 2025 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in fig2dev. This vulnerability allows availability via local input manipulation via genge_itp_spline function. |
2Fig2dev Project Redhat2Enterprise Linux Fig2devJun 30, 2026 Apr 23, 2025 N/A· v4 5.5 MEDIUM· v3 N/A· v2 In xfig diagramming tool, a stack-overflow while running fig2dev allows memory corruption via local input manipulation via read_objects function. |
2Fig2dev Project Redhat2Enterprise Linux Fig2devJun 30, 2026 Apr 23, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 A flaw was found in xfig. This vulnerability allows possible code execution via local input manipulation via bezier_spline function. |
3Debian GnomeRedhat21Codeready Linux Builder Codeready Linux Builder For Arm64Codeready Linux Builder For Arm64 Eus+18 moreJun 29, 2026 Apr 3, 2025 N/A· v4 7.4 HIGH· v3 N/A· v2 A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an ex...Show more |
2Gnome Redhat21Codeready Linux Builder Codeready Linux Builder For Arm64Codeready Linux Builder For Arm64 Eus+18 moreJun 30, 2026 Apr 3, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_insight_whitespace() function. Libsoup clients may read one byte out-of-bounds in response to a crafted...Show more |
2Gnu Redhat3Enterprise Linux Grub2Openshift Container PlatformJun 30, 2026 Mar 3, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 A flaw was found in grub2. When reading data from a squash4 filesystem, grub's squash4 fs module uses user-controlled parameters from the filesystem geometry to determine the internal buffer size, however, it improperly...Show more |
2Gnu Redhat3Enterprise Linux Grub2Openshift Container PlatformJun 29, 2026 Mar 3, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 A flaw was found in the HFS filesystem. When reading an HFS volume's name at grub_fs_mount(), the HFS filesystem driver performs a strcpy() using the user-provided volume name as input without properly validating the vol...Show more |
2Gnu Redhat3Enterprise Linux Grub2Openshift Container PlatformJun 29, 2026 Mar 3, 2025 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A stack overflow flaw was found when reading a BFS file system. A crafted BFS filesystem may lead to an uncontrolled loop, causing grub2 to crash. |
3Redhat TigervncX.org4Enterprise Linux TigervncX Server+1 moreJun 29, 2026 Feb 25, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 A use-after-free flaw was found in X.Org and Xwayland. When changing an alarm, the values of the change mask are evaluated one after the other, changing the trigger values as requested, and eventually, SyncInitTrigger()...Show more |
3Redhat TigervncX.org4Enterprise Linux TigervncX Server+1 moreJun 29, 2026 Feb 25, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 A use-after-free flaw was found in X.Org and Xwayland. When a device is removed while still frozen, the events queued for that device remain while the device is freed. Replaying the events will cause a use-after-free. |
3Redhat TigervncX.org4Enterprise Linux TigervncX Server+1 moreJun 29, 2026 Feb 25, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 An access to an uninitialized pointer flaw was found in X.Org and Xwayland. The function compCheckRedirect() may fail if it cannot allocate the backing pixmap. In that case, compRedirectWindow() will return a BadAlloc er...Show more |