CVEs (313)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Gnu Redhat4Enterprise Linux GnutlsHardened Images+1 moreJul 22, 2026 Apr 30, 2026 N/A· v4 7.4 HIGH· v3 N/A· v2 A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedS...Show more |
2Gnu Redhat4Enterprise Linux GnutlsHardened Images+1 moreJul 13, 2026 Apr 30, 2026 N/A· v4 3.7 LOW· v3 N/A· v2 A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnut...Show more |
2Gnu Redhat3Enterprise Linux GnutlsOpenshift Container PlatformJul 20, 2026 Apr 30, 2026 N/A· v4 9.1 CRITICAL· v3 N/A· v2 A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely ex...Show more |
1Redhat 1Openshift Container Platform Jun 17, 2026 Apr 28, 2026 N/A· v4 4.3 MEDIUM· v3 N/A· v2 A flaw was found in the OpenShift Container Platform build system. A user with the `edit` ClusterRole can inject arbitrary environment variables, such as `LD_PRELOAD` or `http_proxy`, into `docker-build` containers throu...Show more |
3Ibm RedhatXmlsoft7Aix Enterprise LinuxHardened Images+4 moreJun 30, 2026 Apr 23, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit t...Show more |
2Gnu Redhat4Binutils Enterprise LinuxHardened Images+1 moreJul 15, 2026 Apr 22, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user int...Show more |
2Gnu Redhat4Binutils Enterprise LinuxHardened Images+1 moreJul 13, 2026 Apr 22, 2026 N/A· v4 5.0 MEDIUM· v3 N/A· v2 A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and...Show more |
2Gnu Redhat4Binutils Enterprise LinuxHardened Images+1 moreJun 17, 2026 Apr 22, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. On...Show more |
2Gnu Redhat3Enterprise Linux NanoOpenshift Container PlatformJun 17, 2026 Apr 22, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in nano. A local user could exploit a format string vulnerability in the `statusline()` function. By creating a directory with a name containing `printf` specifiers, the application attempts to display t...Show more |
12Amazon AristaCanonical+9 more45Amazon Linux Basesystem ModuleCaas Platform+42 moreJul 15, 2026 Apr 22, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is...Show more |
2Libcap Project Redhat3Enterprise Linux LibcapOpenshift Container PlatformJul 21, 2026 Apr 9, 2026 N/A· v4 7.0 HIGH· v3 N/A· v2 A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory t...Show more |
2Libarchive Redhat4Enterprise Linux Hardened ImagesLibarchive+1 moreJun 17, 2026 Apr 7, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string (such as a bar...Show more |
2Libarchive Redhat4Enterprise Linux Hardened ImagesLibarchive+1 moreJul 14, 2026 Mar 30, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image,...Show more |
2Libssh Redhat4Enterprise Linux Hardened ImagesLibssh+1 moreJun 17, 2026 Mar 26, 2026 N/A· v4 8.2 HIGH· v3 N/A· v2 A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited remotely by an attacker during GSSAPI (Generic Security Service...Show more |
2Libssh Redhat4Enterprise Linux Hardened ImagesLibssh+1 moreJun 17, 2026 Mar 26, 2026 N/A· v4 6.3 MEDIUM· v3 N/A· v2 A malicious SCP server can send unexpected paths that could make the client application override local files outside of working directory. This could be misused to create malicious executable or configuration files and m...Show more |
2Freedesktop Redhat3Enterprise Linux Openshift Container PlatformPolkitJun 17, 2026 Mar 26, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in polkit. A local user can exploit this by providing a specially crafted, excessively long input to the `polkit-agent-helper-1` setuid binary via standard input (stdin). This unbounded input can lead to...Show more |
2Gnu Redhat3Binutils Enterprise LinuxOpenshift Container PlatformJul 15, 2026 Mar 23, 2026 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a rel...Show more |
2Libarchive Redhat4Enterprise Linux Hardened ImagesLibarchive+1 moreJun 17, 2026 Mar 19, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote atta...Show more |
2Libarchive Redhat7Enterprise Linux Enterprise Linux Server AusHardened Images+4 moreJul 15, 2026 Mar 19, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression metho...Show more |
2Gnu Redhat3Binutils Enterprise LinuxOpenshift Container PlatformJul 13, 2026 Mar 16, 2026 N/A· v4 7.1 HIGH· v3 N/A· v2 A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a...Show more |