CVEs (1,858)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Gnu Redhat3Enterprise Linux NanoOpenshift Container PlatformJun 17, 2026 Apr 22, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in nano. A local user could exploit a format string vulnerability in the `statusline()` function. By creating a directory with a name containing `printf` specifiers, the application attempts to display t...Show more |
12Amazon AristaCanonical+9 more45Amazon Linux Basesystem ModuleCaas Platform+42 moreJul 15, 2026 Apr 22, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is...Show more |
3Debian OcamlRedhat3Debian Linux Enterprise LinuxOpamJul 15, 2026 Apr 16, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory. |
A flaw was found in gimp. This buffer overflow vulnerability in the GIF image loading component's `ReadJeffsImage` function allows an attacker to write beyond an allocated buffer by processing a specially crafted GIF fil...Show more |
A flaw was found in GIMP. This vulnerability, a buffer overflow in the `file-seattle-filmworks` plugin, can be exploited when a user opens a specially crafted Seattle Filmworks file. A remote attacker could leverage this...Show more |
A flaw was found in GIMP. Processing a specially crafted PVR image file with large dimensions can lead to a denial of service (DoS). This occurs due to a stack-based buffer overflow and an out-of-bounds read in the PVR i...Show more |
A flaw was found in GIMP. This vulnerability, a heap buffer over-read in the `icns_slurp()` function, occurs when processing specially crafted ICNS image files. An attacker could provide a malicious ICNS file, potentiall...Show more |
A flaw was found in GIMP. A stack buffer overflow vulnerability in the TIM image loader's 4BPP decoding path allows a local user to cause a Denial of Service (DoS). By opening a specially crafted TIM image file, the appl...Show more |
A flaw was found in GIMP. A remote attacker could exploit an integer overflow vulnerability in the FITS image loader by providing a specially crafted FITS file. This integer overflow leads to a zero-byte memory allocatio...Show more |
2Libcap Project Redhat3Enterprise Linux LibcapOpenshift Container PlatformJul 21, 2026 Apr 9, 2026 N/A· v4 7.0 HIGH· v3 N/A· v2 A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory t...Show more |
2Libarchive Redhat4Enterprise Linux Hardened ImagesLibarchive+1 moreJun 17, 2026 Apr 7, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string (such as a bar...Show more |
2Gnu Redhat3Enterprise Linux Hardened ImagesTarJun 17, 2026 Apr 6, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspectio...Show more |
A flaw was found in libtheora. This heap-based out-of-bounds read vulnerability exists within the AVI (Audio Video Interleave) parser, specifically in the avi_parse_input_file() function. A local attacker could exploit t...Show more |
2Redhat Sequoia Pgp3Enterprise Linux Hardened ImagesRpm SequoiaJul 24, 2026 Apr 3, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in rust-rpm-sequoia. An attacker can exploit this vulnerability by providing a specially crafted Red Hat Package Manager (RPM) file. During the RPM signature verification process, this crafted file can t...Show more |
2Corosync Redhat3Corosync Enterprise LinuxOpenshiftJun 17, 2026 Apr 1, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a remote, unauthenticated attacker to send crafted User Datagram Protocol (UDP) packets. This can cause...Show more |
2Corosync Redhat3Corosync Enterprise LinuxOpenshiftJun 17, 2026 Apr 1, 2026 N/A· v4 8.2 HIGH· v3 N/A· v2 A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Corosync membership commit token sanity check by sending a specially crafted User Datagram Protocol (U...Show more |
2Gnome Redhat4Enterprise Linux Enterprise Linux Server AusEnterprise Linux Server Tus+1 moreJul 15, 2026 Mar 31, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component counts when processing a specially crafted JPEG imag...Show more |
A flaw was found in virtio-win, specifically within the VirtIO Block (BLK) device. When the device undergoes a reset, it fails to properly manage memory, resulting in a use-after-free vulnerability. This issue could allo...Show more |
A flaw was found in virtio-win. The `RhelDoUnMap()` function does not properly validate the number of descriptors provided by a user during an unmap request. A local user could exploit this input validation vulnerability...Show more |
2Libarchive Redhat4Enterprise Linux Hardened ImagesLibarchive+1 moreJul 14, 2026 Mar 30, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image,...Show more |