CVEs (7)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Opensuse Redhat6Enterprise Linux Hardened ImagesLibsolv+3 moreJul 23, 2026 May 26, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially...Show more |
2Opensuse Redhat6Enterprise Linux Hardened ImagesLibsolv+3 moreJul 23, 2026 May 21, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an under...Show more |
2Opensuse Redhat6Enterprise Linux Hardened ImagesLibsolv+3 moreJul 23, 2026 May 20, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by provi...Show more |
3Couchbase Cryptography.ioRedhat5Ansible Automation Platform Couchbase ServerCryptography+2 moreJun 17, 2026 Feb 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive...Show more |
2M2crypto Project Redhat3Enterprise Linux M2cryptoUpdate InfrastructureJun 17, 2026 Feb 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data. |
2Pulpproject Redhat4Ansible Automation Platform Pulp AnsibleSatellite+1 moreJun 17, 2026 Oct 25, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only. |
RHUI (Red Hat Update Infrastructure) 2.1.3 has world readable PKI entitlement certificates |