CVEs (1,858)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian LinuxRedhat3Debian Linux Enterprise LinuxLinux KernelJun 17, 2026 Feb 18, 2022 N/A· v4 4.7 MEDIUM· v3 4.7 MEDIUM· v2 A race condition accessing file object in the Linux kernel OverlayFS subsystem was found in the way users do rename in specific way with OverlayFS. A local user could use this flaw to crash the system. |
3Fedoraproject LinuxRedhat3Enterprise Linux FedoraLinux KernelJun 17, 2026 Feb 18, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A flaw was found in s390 eBPF JIT in bpf_jit_insn in arch/s390/net/bpf_jit_comp.c in the Linux kernel. In this flaw, a local attacker with special user privilege can circumvent the verifier and may lead to a confidential...Show more |
5Canonical DebianFedoraproject+2 more17Debian Linux Enterprise LinuxEnterprise Linux Desktop+14 moreJun 17, 2026 Feb 18, 2022 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not strictl...Show more |
5Canonical DebianFedoraproject+2 more25Codeready Linux Builder Debian LinuxEnterprise Linux+22 moreJun 17, 2026 Feb 18, 2022 N/A· v4 8.1 HIGH· v3 8.5 HIGH· v2 A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalation. |
5Canonical DebianFedoraproject+2 more24Codeready Linux Builder Debian LinuxEnterprise Linux+21 moreNov 21, 2024 Feb 18, 2022 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required. |
4Fedoraproject LinuxOracle+1 more6Communications Cloud Native Core Binding Support Function Communications Cloud Native Core Network Exposure FunctionCommunications Cloud Native Core Policy+3 moreJun 17, 2026 Feb 16, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw in netfilter could allow a network-connected attacker to infer openvpn connection endpoint information for further use in traditional network attacks. |
3Linux NetappRedhat12Active Iq Unified Manager Bootstrap OsElement Software+9 moreJun 17, 2026 Feb 16, 2022 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 A race problem was seen in the vt_k_ioctl in drivers/tty/vt/vt_ioctl.c in the Linux kernel, which may cause an out of bounds read in vt as the write access to vc_mode is not protected by lock-in vt_ioctl (KDSETMDE). The...Show more |
6Debian FedoraprojectLinux+3 more193scale Communications Cloud Native Core Binding Support FunctionCommunications Cloud Native Core Network Exposure Function+16 moreJun 17, 2026 Feb 16, 2022 N/A· v4 7.1 HIGH· v3 7.9 HIGH· v2 A use-after-free flaw was found in the Linux kernel’s Bluetooth subsystem in the way user calls connect to the socket and disconnect simultaneously due to a race condition. This flaw allows a user to crash the system or...Show more |
4Dogtagpki FedoraprojectOracle+1 more12Dogtagpki Enterprise LinuxEnterprise Linux Eus+9 moreJun 17, 2026 Feb 16, 2022 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the installation log file. This flaw allows a local attacker to retrieve the file to obtain the admin p...Show more |
5Debian FedoraprojectLibtiff+2 more5Debian Linux Enterprise LinuxFedora+2 moreJun 17, 2026 Feb 11, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Null source pointer passed as an argument to memcpy() function within TIFFFetchStripThing() in tif_dirread.c in libtiff versions from 3.9.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file. For users that c...Show more |
5Apple DebianFedoraproject+2 more6Debian Linux Enterprise LinuxFedora+3 moreJun 17, 2026 Feb 9, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file,...Show more |
4Debian FedoraprojectRedhat+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Feb 9, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file,...Show more |
3Debian LinuxRedhat3Debian Linux Enterprise LinuxLinux KernelJun 17, 2026 Feb 4, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A use-after-free vulnerability was found in rtsx_usb_ms_drv_remove in drivers/memstick/host/rtsx_usb_ms.c in memstick in the Linux kernel. In this flaw, a local attacker with a user privilege may impact system Confidenti...Show more |
3Linux NetappRedhat4Enterprise Linux Hci Baseboard Management ControllerLinux Kernel+1 moreJun 17, 2026 Feb 4, 2022 N/A· v4 8.8 HIGH· v3 7.2 HIGH· v2 A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v1.c in the Linux kernel's cgroup v1 parser. A local attacker with a user privilege could cause a privilege escalation by exploiting the fsco...Show more |
7Canonical OraclePolkit Project+4 more30Command Center Enterprise LinuxEnterprise Linux Desktop+27 moreJun 17, 2026 Jan 28, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined polic...Show more |
2Qemu Redhat2Enterprise Linux QemuJun 17, 2026 Jan 25, 2022 N/A· v4 6.5 MEDIUM· v3 4.9 MEDIUM· v2 A NULL pointer dereference issue was found in the block mirror layer of QEMU in versions prior to 6.2.0. The `self` pointer is dereferenced in mirror_wait_on_conflicts() without ensuring that it's not NULL. A malicious u...Show more |
5Advanced Intrusion Detection Environment Project CanonicalDebian+2 more7Advanced Intrusion Detection Environment Debian LinuxEnterprise Linux+4 moreJun 17, 2026 Jan 20, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as XFS extended attributes or tmpfs ACLs), because of a heap-based buffer overflow. |
4Debian FedoraprojectFlatpak+1 more5Debian Linux Enterprise LinuxFedora+2 moreJun 17, 2026 Jan 13, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Flatpak is a Linux application sandboxing and distribution framework. A path traversal vulnerability affects versions of Flatpak prior to 1.12.3 and 1.10.6. flatpak-builder applies `finish-args` last in the build. At thi...Show more |
4Debian FedoraprojectFlatpak+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Jan 12, 2022 N/A· v4 8.6 HIGH· v3 6.8 MEDIUM· v2 Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.12.3 and 1.10.6, Flatpak doesn't properly validate that the permissions displayed to the user for an app at install time match the...Show more |
6Debian FedoraprojectOpensuse+3 more9Cgi Debian LinuxEnterprise Linux+6 moreJun 17, 2026 Jan 1, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby. |