CVEs (9)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2F5 Redhat13Discovery DosEnterprise Linux+10 moreAug 25, 2026 Jun 17, 2026 9.2 CRITICAL· v4 8.1 HIGH· v3 N/A· v2 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy...Show more |
2Opensuse Redhat6Enterprise Linux Hardened ImagesLibsolv+3 moreSep 3, 2026 May 26, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially...Show more |
3Debian F5Redhat12Debian Linux DiscoveryDos+9 moreAug 25, 2026 May 22, 2026 9.2 CRITICAL· v4 8.1 HIGH· v3 N/A· v2 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expr...Show more |
2Opensuse Redhat6Enterprise Linux Hardened ImagesLibsolv+3 moreSep 1, 2026 May 21, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an under...Show more |
2Opensuse Redhat6Enterprise Linux Hardened ImagesLibsolv+3 moreSep 1, 2026 May 20, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by provi...Show more |
3Couchbase Cryptography.ioRedhat5Ansible Automation Platform Couchbase ServerCryptography+2 moreJun 17, 2026 Feb 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive...Show more |
2M2crypto Project Redhat3Enterprise Linux M2cryptoUpdate InfrastructureJun 17, 2026 Feb 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data. |
2Pulpproject Redhat4Ansible Automation Platform Pulp AnsibleSatellite+1 moreJun 17, 2026 Oct 25, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only. |
RHUI (Red Hat Update Infrastructure) 2.1.3 has world readable PKI entitlement certificates |