CVEs (313)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Gnu Redhat3Binutils Enterprise LinuxOpenshift Container PlatformJul 13, 2026 Mar 16, 2026 N/A· v4 7.1 HIGH· v3 N/A· v2 A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to p...Show more |
2Linux Nfs Redhat3Enterprise Linux Nfs UtilsOpenshift Container PlatformJun 30, 2026 Mar 4, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privileges assigned to it in the /etc/exports file at mount time. In particu...Show more |
3Ibm RedhatXmlsoft7Aix Enterprise LinuxHardened Images+4 moreJun 30, 2026 Jan 15, 2026 N/A· v4 2.9 LOW· v3 N/A· v2 A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated <nextCatalog> elements pointing to the same downstream catalog. A re...Show more |
3Ibm RedhatXmlsoft7Aix Enterprise LinuxHardened Images+4 moreJun 30, 2026 Jan 15, 2026 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A re...Show more |
3Ibm RedhatXmlsoft7Aix Enterprise LinuxHardened Images+4 moreJun 30, 2026 Jan 15, 2026 N/A· v4 3.7 LOW· v3 N/A· v2 A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially c...Show more |
2Gnome Redhat29Ceph Storage Codeready Linux BuilderCodeready Linux Builder For Arm64+26 moreJun 30, 2026 Nov 26, 2025 N/A· v4 7.7 HIGH· v3 N/A· v2 A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable character...Show more |
1Redhat 2Enterprise Linux Openshift Container PlatformJun 30, 2026 Jul 28, 2025 N/A· v4 3.7 LOW· v3 N/A· v2 A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as...Show more |
1Redhat 2Enterprise Linux Openshift Container PlatformJun 30, 2026 Jul 14, 2025 N/A· v4 6.7 MEDIUM· v3 N/A· v2 A flaw was found in polkit. When processing an XML policy with 32 or more nested elements in depth, an out-of-bounds write can be triggered. This issue can lead to a crash or other unexpected behavior, and arbitrary code...Show more |
2Redhat Xmlsoft3Enterprise Linux LibxsltOpenshift Container PlatformJun 29, 2026 Jul 10, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which can lead to type confusion during XML transformations. This vulnerability allows an attacker to cras...Show more |
2Gnu Redhat3Enterprise Linux GnutlsOpenshift Container PlatformJun 30, 2026 Jul 10, 2025 N/A· v4 8.2 HIGH· v3 N/A· v2 A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an...Show more |
2Gnu Redhat3Enterprise Linux GnutlsOpenshift Container PlatformJun 30, 2026 Jul 10, 2025 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transparency (CT) Signed Certificate Timestamp (SCT) extension during X.509 certificate parsing. This flaw allows a malicious use...Show more |
2Gnu Redhat3Enterprise Linux GnutlsOpenshift Container PlatformJun 30, 2026 Jul 10, 2025 N/A· v4 8.2 HIGH· v3 N/A· v2 A flaw was found in GnuTLS. A double-free vulnerability exists in GnuTLS due to incorrect ownership handling in the export logic of Subject Alternative Name (SAN) entries containing an otherName. If the type-id OID is in...Show more |
2Libssh Redhat3Enterprise Linux LibsshOpenshift Container PlatformJun 30, 2026 Jul 4, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in the key export functionality of libssh. The issue occurs in the internal function responsible for converting cryptographic keys into serialized formats. During error handling, a memory structure is fr...Show more |
2Libssh Redhat3Enterprise Linux LibsshOpenshift Container PlatformJun 17, 2026 Jul 4, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL use...Show more |
2Libssh Redhat3Enterprise Linux LibsshOpenshift Container PlatformJul 21, 2026 Jun 24, 2025 N/A· v4 8.1 HIGH· v3 N/A· v2 A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect comparison check that permits the function to access memory beyo...Show more |
2Redhat Xmlsoft4Enterprise Linux Jboss Core ServicesLibxml2+1 moreJul 23, 2026 Jun 16, 2025 N/A· v4 2.5 LOW· v3 N/A· v2 A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to...Show more |
2Redhat Xmlsoft20Enterprise Linux Enterprise Linux EusEnterprise Linux For Arm 64+17 moreJun 30, 2026 Jun 12, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when...Show more |
2Libarchive Redhat3Enterprise Linux LibarchiveOpenshift Container PlatformJun 30, 2026 Jun 9, 2025 N/A· v4 6.6 MEDIUM· v3 N/A· v2 A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can le...Show more |
2Libarchive Redhat3Enterprise Linux LibarchiveOpenshift Container PlatformJun 30, 2026 Jun 9, 2025 N/A· v4 5.0 MEDIUM· v3 N/A· v2 A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes for file names. This can lead to a 1-byte write overflow. While seeming...Show more |
2Libarchive Redhat3Enterprise Linux LibarchiveOpenshift Container PlatformJun 30, 2026 Jun 9, 2025 N/A· v4 5.6 MEDIUM· v3 N/A· v2 A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content by...Show more |