CVEs (1,858)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Redhat Shadow Maint9Codeready Linux Builder Codeready Linux Builder For Arm64Codeready Linux Builder For Ibm Z Systems+6 moreJun 17, 2026 Dec 27, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password fails on the second attempt, shadow-utils fails in cleaning the buffer used to store the first entry...Show more |
3Fedoraproject OpenbsdRedhat3Enterprise Linux FedoraOpensshJun 17, 2026 Dec 24, 2023 N/A· v4 7.0 HIGH· v3 N/A· v2 OpenSSH through 10.0, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer value of authenticated in mm_answer_authpassword does not resist flips of a single...Show more |
3Freebsd RedhatSendmail3Enterprise Linux FreebsdSendmailJun 17, 2026 Dec 24, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 sendmail through 8.17.2 allows SMTP smuggling in certain configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF p...Show more |
3Fedoraproject PostfixRedhat3Enterprise Linux FedoraPostfixJun 17, 2026 Dec 24, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_keywords=chunking (or certain other options that exist in recent versions). Remot...Show more |
3Fedoraproject LinuxRedhat3Enterprise Linux FedoraLinux KernelJun 17, 2026 Dec 21, 2023 N/A· v4 7.0 HIGH· v3 N/A· v2 A race condition was found in the GSM 0710 tty multiplexor in the Linux kernel. This issue occurs when two threads execute the GSMIOC_SETCONF ioctl on the same tty file descriptor with the gsm line discipline enabled, an...Show more |
3Fedoraproject LibsshRedhat3Enterprise Linux FedoraLibsshJun 17, 2026 Dec 19, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A flaw was found in the libssh implements abstract layer for message digest (MD) operations implemented by different supported crypto backends. The return values from these were not properly checked, which could cause lo...Show more |
429bis ApacheApple+39 more68Advanced Cluster Security AsyncsshCeph Storage+65 moreJun 17, 2026 Dec 18, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negoti...Show more |
3Fedoraproject PerlRedhat5Enterprise Linux Enterprise Linux AusEnterprise Linux Eus+2 moreJun 17, 2026 Dec 18, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A vulnerability was found in perl 5.30.0 through 5.38.0. This issue occurs when a crafted regular expression is compiled by perl, which can allow an attacker controlled byte buffer overflow in a heap allocated buffer. |
2Modcluster Redhat2Enterprise Linux Mod Proxy ClusterJun 17, 2026 Dec 12, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 A flaw was found in the mod_proxy_cluster in the Apache server. This issue may allow a malicious user to add a script in the 'alias' parameter in the URL to trigger the stored cross-site scripting (XSS) vulnerability. By...Show more |
3Fedoraproject LinuxRedhat3Enterprise Linux FedoraLinux KernelJun 17, 2026 Dec 11, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A null pointer dereference vulnerability was found in dpll_pin_parent_pin_set() in drivers/dpll/dpll_netlink.c in the Digital Phase Locked Loop (DPLL) subsystem in the Linux kernel. This issue could be exploited to trig...Show more |
2Postgresql Redhat16Codeready Linux Builder Eus Codeready Linux Builder Eus For Power Little Endian EusCodeready Linux Builder For Arm64 Eus+13 moreJun 17, 2026 Dec 10, 2023 N/A· v4 4.4 MEDIUM· v3 N/A· v2 A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum workers, and the autovacuum launcher. Successful exploitation re...Show more |
2Postgresql Redhat21Codeready Linux Builder Eus Codeready Linux Builder Eus For Power Little Endian EusCodeready Linux Builder For Arm64 Eus+18 moreJun 17, 2026 Dec 10, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A flaw was found in PostgreSQL that allows authenticated database users to execute arbitrary code through missing overflow checks during SQL array value modification. This issue exists due to an integer overflow during a...Show more |
2Postgresql Redhat16Codeready Linux Builder Eus Codeready Linux Builder Eus For Power Little Endian EusCodeready Linux Builder For Arm64 Eus+13 moreJun 23, 2026 Dec 10, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by exploiting certain aggregate function calls with 'unknown'-type arguments. Handling 'unknown'-type val...Show more |
3Fedoraproject LinuxRedhat3Enterprise Linux FedoraLinux KernelJun 17, 2026 Dec 8, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A null pointer dereference vulnerability was found in nft_dynset_init() in net/netfilter/nft_dynset.c in nf_tables in the Linux kernel. This issue may allow a local attacker with CAP_NET_ADMIN user privilege to trigger a...Show more |
2Linux Redhat2Enterprise Linux Linux KernelJun 17, 2026 Dec 8, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 An out-of-bounds read vulnerability was found in smb2_dump_detail in fs/smb/client/smb2ops.c in the Linux Kernel. This issue could allow a local attacker to crash the system or leak internal kernel information. |
2Linux Redhat5Enterprise Linux Enterprise Linux EusEnterprise Linux Server Aus+2 moreJun 17, 2026 Dec 8, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 An out-of-bounds read vulnerability was found in smbCalcSize in fs/smb/client/netmisc.c in the Linux Kernel. This issue could allow a local attacker to crash the system or leak internal kernel information. |
A flaw was found in libnbd, due to a malicious Network Block Device (NBD), a protocol for accessing Block Devices such as hard disks over a Network. This issue may allow a malicious NBD server to cause a Denial of Servic...Show more |
2Linux Redhat2Enterprise Linux Linux KernelJun 17, 2026 Nov 16, 2023 N/A· v4 4.7 MEDIUM· v3 N/A· v2 A null pointer dereference flaw was found in the Linux kernel API for the cryptographic algorithm scatterwalk functionality. This issue occurs when a user constructs a malicious packet with specific socket configuration,...Show more |
An out-of-bounds read vulnerability was found in the NVMe-oF/TCP subsystem in the Linux kernel. This issue may allow a remote attacker to send a crafted TCP packet, triggering a heap-based buffer overflow that results in...Show more |
3Fedoraproject MoodleRedhat3Enterprise Linux FedoraMoodleJun 17, 2026 Nov 9, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The course upload preview contained an XSS risk for users uploading unsafe data. |