CVEs (1,858)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Abrt Project FedoraprojectRedhat3Abrt Enterprise LinuxFedoraJun 29, 2026 Jun 13, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal for log entries matching the crashed process and writes the results to...Show more |
3Abrt Project FedoraprojectRedhat3Abrt Enterprise LinuxFedoraJul 15, 2026 Jun 13, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replace...Show more |
2Mariadb Redhat2Enterprise Linux MariadbJul 15, 2026 Jun 12, 2026 6.9 MEDIUM· v4 9.1 CRITICAL· v3 N/A· v2 MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the datab...Show more |
1Redhat 3389 Directory Server Directory ServerEnterprise LinuxJun 30, 2026 Jun 9, 2026 N/A· v4 4.9 MEDIUM· v3 N/A· v2 A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plugin does not enforce an upper bound on the iteration count extracted from stored password hashes. A privileged attacker who can modify a use...Show more |
1Redhat 3389 Directory Server Directory ServerEnterprise LinuxJun 30, 2026 Jun 9, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when computing salt length from a crafted password hash shorter than 16 bytes, causing a buffer over-read tha...Show more |
1Redhat 3389 Directory Server Directory ServerEnterprise LinuxJun 30, 2026 Jun 9, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the s...Show more |
1Redhat 3389 Directory Server Directory ServerEnterprise LinuxJun 30, 2026 Jun 9, 2026 N/A· v4 6.3 MEDIUM· v3 N/A· v2 A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a heap buffer over-read in string filter parsing that may influence interna...Show more |
1Redhat 3389 Directory Server Directory ServerEnterprise LinuxJun 30, 2026 Jun 9, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when processing attribute types with trailing semicolons during database import, causing an out-of-bounds read detectable unde...Show more |
1Redhat 3389 Directory Server Directory ServerEnterprise LinuxJun 30, 2026 Jun 9, 2026 N/A· v4 4.3 MEDIUM· v3 N/A· v2 A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation handler causes partial stack address information to be disclosed in LDAP responses to authenticated users. |
1Redhat 3389 Directory Server Directory ServerEnterprise LinuxJul 23, 2026 Jun 8, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in 389 Directory Server. The Content Synchronization persistent search plugin allows unbounded memory growth when an authenticated client stops reading sync responses, enabling denial of service. Additio...Show more |
2Redhat X.org3Enterprise Linux X ServerXwaylandJul 15, 2026 Jun 5, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DRI2BufferBackLeft attachments and one DRI2BufferFrontLeft can trigger an...Show more |
2Redhat X.org3Enterprise Linux X ServerXwaylandJul 13, 2026 Jun 5, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-after-free read after changing window attributes and forcing the screen saver, leading to information...Show more |
2Redhat X.org3Enterprise Linux X ServerXwaylandJul 13, 2026 Jun 5, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size validation check can read a client-controlled number of bytes, exceeding the request buffer, l...Show more |
2Redhat X.org3Enterprise Linux X ServerXwaylandJul 15, 2026 Jun 5, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a use-after-free when destroying those counters via a second client conne...Show more |
2Redhat X.org3Enterprise Linux X ServerXwaylandJul 15, 2026 Jun 5, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple SyncCounters and awaits on those triggers can trigger a use-after-free when destroying those counters vi...Show more |
2Redhat X.org3Enterprise Linux X ServerXwaylandJul 15, 2026 Jun 5, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. _XkbSetMapChecks() declares a fixed-size stack buffer mapWidths[256] indexed by key type index. The helper function CheckKeyTypes() writes...Show more |
2Redhat X.org3Enterprise Linux X ServerXwaylandJul 15, 2026 Jun 5, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers sized XkbMaxShiftLevel * XkbNumKbdGroups but CheckKeyTypes() does not verify or clamp non-canonical...Show more |
2Redhat X.org3Enterprise Linux X ServerXwaylandJul 15, 2026 Jun 5, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multiple fence triggers can trigger a use-after-free function pointer call. An attacker would connect to t...Show more |
2Redhat X.org3Enterprise Linux X ServerXwaylandJul 15, 2026 Jun 5, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the libXfont2 library's maximum font name length can cause a stack buffer overflow during font alias re...Show more |
2Redhat Samba3Enterprise Linux Openshift Container PlatformSambaJul 15, 2026 May 28, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u subs...Show more |