Search

Found 5,871 results in 1751ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-40918 medium 5.5 5.5 FIX debian debian rhel gimp 2mo ago A flaw was found in GIMP. Processing a specially crafted PVR image file with large dimensions can lead to a denial of service (DoS). This occurs due to a stack-based buffer overflow and an out-of-bou…
CVE-2026-40916 medium 5.5 5.5 FIX debian debian rhel gimp 2mo ago A flaw was found in GIMP. A stack buffer overflow vulnerability in the TIM image loader's 4BPP decoding path allows a local user to cause a Denial of Service (DoS). By opening a specially crafted TIM…
CVE-2026-28421 medium 5.3 5.3 FIX rocky rhel sles 2mo ago Important: vim security update
CVE-2026-28417 medium 4.4 4.4 FIX rocky rhel sles 2mo ago Important: vim security update
CVE-2026-4631 critical 10.0 EXPFIX rheldebian debian sles 2mo ago Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit…
CVE-2026-21717 medium 5.9 5.9 FIX rhel slesdebian debian 2mo ago RHSA-2026:7670: nodejs:24 security update (Important)
CVE-2026-21713 medium 5.9 5.9 FIX rhel slesdebian debian 2mo ago RHSA-2026:7670: nodejs:24 security update (Important)
CVE-2026-21712 medium 5.7 5.7 FIX rhel slesdebian debian 2mo ago RHSA-2026:7670: nodejs:24 security update (Important)
CVE-2026-5745 medium 5.5 5.5 debian debian sles rhel libarchiveredhat 2mo ago A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL …
CVE-2026-23210 medium 5.5 FIX rhel slesdebian debian 2mo ago In the Linux kernel, the following vulnerability has been resolved: ice: Fix PTP NULL pointer dereference during VSI rebuild Fix race condition where PTP periodic work runs while VSI is being rebui…
CVE-2025-71238 medium 5.5 FIX slesdebian debian rocky 2mo ago In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix bsg_done() causing double free Kernel panic observed on system, [5353358.825191] BUG: unable to handle page f…
CVE-2025-38109 medium 5.5 FIX rhel slesdebian debian 2mo ago In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix ECVF vports unload on shutdown flow Fix shutdown flow UAF when a virtual function is created on the embedded chip (…
CVE-2026-2625 medium 5.5 5.5 FIX rheldebian debian redhatsequoia-pgp 2mo ago A flaw was found in rust-rpm-sequoia. An attacker can exploit this vulnerability by providing a specially crafted Red Hat Package Manager (RPM) file. During the RPM signature verification process, th…
CVE-2026-23455 critical 9.1 9.1 FIX sles rheldebian debian 2mo ago In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() In DecodeQ931(), the UserUserIE code path reads a 16-bit leng…
CVE-2025-10158 medium 5.5 FIX rocky rhel sles 2mo ago RHSA-2026:6436: rsync security update (Moderate)
CVE-2023-40403 medium 5.5 FIX rhel rocky sles 2mo ago RHSA-2025:8676: libxslt security update (Moderate)
CVE-2026-5164 medium 5.5 5.5 rhel redhat 2mo ago A flaw was found in virtio-win. The `RhelDoUnMap()` function does not properly validate the number of descriptors provided by a user during an unmap request. A local user could exploit this input val…
CVE-2026-23209 medium 5.5 FIX rocky rhel sles 2mo ago In the Linux kernel, the following vulnerability has been resolved: macvlan: fix error recovery in macvlan_common_newlink() valis provided a nice repro to crash the kernel: ip link add p1 type vet…
CVE-2026-23193 medium 5.5 FIX rhel sles rocky 2mo ago In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix use-after-free in iscsit_dec_session_usage_count() In iscsit_dec_session_usage_count(), the function cal…
CVE-2026-23144 medium 5.5 FIX rhel sles rocky 2mo ago In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs: cleanup attrs subdirs on context dir setup failure When a context DAMON sysfs directory setup is failed after set…
CVE-2025-38180 medium 5.5 FIX rocky rhel sles 2mo ago In the Linux kernel, the following vulnerability has been resolved: net: atm: fix /proc/net/atm/lec handling /proc/net/atm/lec must ensure safety against dev_lec[] changes. It appears it had dev_p…
CVE-2026-4948 medium 5.5 5.5 FIX debian debian sles rhel firewalld 2mo ago A flaw was found in firewalld. A local unprivileged user can exploit this vulnerability by mis-authorizing two runtime D-Bus (Desktop Bus) setters, setZoneSettings2 and setPolicySettings. This mis-au…
CVE-2026-2100 medium 5.3 5.3 FIX rhel slesdebian debian p11-kit_projectredhat 2mo ago A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters se…
CVE-2026-4698 critical 9.8 9.8 FIX rocky rheldebian debian mozilla 2mo ago JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
CVE-2026-25749 medium 5.5 FIX rocky rhel sles 2mo ago Moderate: vim security update
CVE-2026-23893 medium 5.5 FIX rocky rhel sles 2mo ago RHSA-2026:5587: opencryptoki security update (Moderate)
CVE-2026-4426 medium 6.5 6.5 FIX debian debian sles rhel libarchiveredhat 3mo ago A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge exte…
CVE-2026-21964 medium 5.5 FIX rocky rhel sles 3mo ago RHSA-2026:6391: mysql:8.4 security update (Moderate)
CVE-2026-21948 medium 5.5 FIX rocky rhel sles 3mo ago RHSA-2026:6391: mysql:8.4 security update (Moderate)
CVE-2026-21941 medium 5.5 FIX rocky rhel sles 3mo ago RHSA-2026:6391: mysql:8.4 security update (Moderate)
CVE-2026-21937 medium 5.5 FIX rocky rhel sles 3mo ago RHSA-2026:6391: mysql:8.4 security update (Moderate)
CVE-2026-21936 medium 5.5 FIX rocky rhel sles 3mo ago RHSA-2026:6391: mysql:8.4 security update (Moderate)
CVE-2025-39818 medium 5.5 FIX rhel sles rocky 3mo ago In the Linux kernel, the following vulnerability has been resolved: HID: intel-thc-hid: intel-thc: Fix incorrect pointer arithmetic in I2C regs save Improper use of secondary pointer (&dev->i2c_sub…
CVE-2026-2376 medium 5.4 5.4 rhel redhat 3mo ago A flaw was found in mirror-registry where an authenticated user can trick the system into accessing unintended internal or restricted systems by providing malicious web addresses. When the applicat…
CVE-2026-1299 medium 5.5 FIX rocky rhel sles 3mo ago The email module, specifically the "BytesGenerator" class, didn’t properly quote newlines for email headers when serializing an email message allowing for header injection when an email is seriali…
CVE-2025-9820 medium 4.0 4.0 FIX rocky rheldebian debian 3mo ago RHSA-2026:5585: gnutls security update (Moderate)
CVE-2025-15367 medium 5.5 FIX rocky rheldebian debian 3mo ago The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.
CVE-2025-15366 medium 5.5 FIX rocky rheldebian debian 3mo ago The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.
CVE-2025-14831 medium 5.3 5.3 FIX rocky rheldebian debian 3mo ago RHSA-2026:5585: gnutls security update (Moderate)
CVE-2026-23001 medium 5.5 FIX rocky rhel sles 3mo ago In the Linux kernel, the following vulnerability has been resolved: macvlan: fix possible UAF in macvlan_forward_source() Add RCU protection on (struct macvlan_source_entry)->vlan. Whenever macvla…
CVE-2025-38106 medium 5.5 FIX rhel slesdebian debian 3mo ago In the Linux kernel, the following vulnerability has been resolved: io_uring: fix use-after-free of sq->thread in __io_uring_show_fdinfo() syzbot reports: BUG: KASAN: slab-use-after-free in getrus…
CVE-2025-12801 medium 5.5 FIX rocky rhel sles 3mo ago RHSA-2026:3938: nfs-utils security update (Moderate)
CVE-2021-30952 medium 7.0 KEVFIX sles rockydebian debian 3mo ago Apple tvOS, macOS, Safari, iPadOS and watchOS contain an integer overflow or wraparound vulnerability due to the processing of maliciously crafted web content that may lead to arbitrary code executio…
CVE-2026-1642 medium 5.5 FIX rocky rhel sles 3mo ago RHSA-2026:5581: nginx:1.24 security update (Moderate)
CVE-2026-23097 medium 5.5 FIX rocky rhel sles 3mo ago In the Linux kernel, the following vulnerability has been resolved: migrate: correct lock ordering for hugetlb file folios Syzbot has found a deadlock (analyzed by Lance Yang): 1) Task (5749): Hol…
CVE-2025-71085 medium 5.5 FIX rocky rhel sles 3mo ago In the Linux kernel, the following vulnerability has been resolved: ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr() There exists a kernel oops caused by a BUG_ON(nhead < 0) at…
CVE-2025-40168 medium 5.5 FIX rocky rhel sles 3mo ago In the Linux kernel, the following vulnerability has been resolved: smc: Use __sk_dst_get() and dst_dev_rcu() in smc_clc_prfx_match(). smc_clc_prfx_match() is called from smc_listen_work() and not …
CVE-2026-2786 critical 9.8 9.8 FIX rocky rheldebian debian mozilla 3mo ago Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
CVE-2025-14905 medium 5.5 FIX debian debian rocky rhel 3mo ago RHSA-2026:5513: 389-ds:1.4 security update (Moderate)
CVE-2025-38206 medium 5.5 FIX rhel slesdebian debian 3mo ago In the Linux kernel, the following vulnerability has been resolved: exfat: fix double free in delayed_free The double free could happen in the following path. exfat_create_upcase_table() e…
CVE-2026-0915 medium 5.5 FIX rocky rheldebian debian google 4mo ago RHSA-2026:4772: glibc security update (Moderate)
CVE-2026-0861 medium 5.5 FIX rheldebian debian sles google 4mo ago Moderate: glibc security update
CVE-2025-15281 medium 5.5 FIX rocky rheldebian debian google 4mo ago RHSA-2026:4772: glibc security update (Moderate)
CVE-2026-22998 medium 5.5 FIX rocky rhel sles 4mo ago In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix NULL pointer dereferences in nvmet_tcp_build_pdu_iovec Commit efa56305908b ("nvmet-tcp: Fix a kernel panic when hos…
CVE-2025-68811 medium 5.5 FIX rhel sles rocky 4mo ago In the Linux kernel, the following vulnerability has been resolved: svcrdma: use rc_pageoff for memcpy byte offset svc_rdma_copy_inline_range added rc_curpage (page index) to the page base instead …
CVE-2025-68349 medium 5.5 FIX rocky rhel sles 4mo ago In the Linux kernel, the following vulnerability has been resolved: NFSv4/pNFS: Clear NFS_INO_LAYOUTCOMMIT in pnfs_mark_layout_stateid_invalid Fixes a crash when layout is null during this call sta…
CVE-2025-40322 medium 5.5 FIX rocky rhel sles 4mo ago In the Linux kernel, the following vulnerability has been resolved: fbdev: bitblit: bound-check glyph index in bit_putcs* bit_putcs_aligned()/unaligned() derived the glyph pointer from the characte…
CVE-2025-40304 medium 5.5 FIX rocky rhel sles 4mo ago In the Linux kernel, the following vulnerability has been resolved: fbdev: Add bounds checking in bit_putcs to fix vmalloc-out-of-bounds Add bounds checking to prevent writes past framebuffer bound…
CVE-2023-53034 medium 5.5 FIX rhel sles rocky 4mo ago In the Linux kernel, the following vulnerability has been resolved: ntb_hw_switchtec: Fix shift-out-of-bounds in switchtec_ntb_mw_set_trans There is a kernel API ntb_mw_clear_trans() would pass 0 t…
CVE-2025-40318 medium 5.5 FIX rhel sles rocky 4mo ago In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: fix race in hci_cmd_sync_dequeue_once hci_cmd_sync_dequeue_once() does lookup and then cancel the entry unde…
CVE-2025-40271 medium 6.5 EXPFIX rocky rhel sles 4mo ago In the Linux kernel, the following vulnerability has been resolved: fs/proc: fix uaf in proc_readdir_de() Pde is erased from subdir rbtree through rb_erase(), but not set the node to EMPTY, which m…
CVE-2025-40269 medium 5.5 FIX rocky rhel sles 4mo ago In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix potential overflow of PCM transfer buffer The PCM stream data in USB-audio driver is transferred over USB UR…
CVE-2025-40170 medium 5.5 FIX rocky rhel sles 4mo ago In the Linux kernel, the following vulnerability has been resolved: net: use dst_dev_rcu() in sk_setup_caps() Use RCU to protect accesses to dst->dev from sk_setup_caps() and sk_dst_gso_max_size().…
CVE-2025-40158 medium 5.5 FIX rocky rhel sles 4mo ago In the Linux kernel, the following vulnerability has been resolved: ipv6: use RCU in ip6_output() Use RCU in ip6_output() in order to use dst_dev_rcu() to prevent possible UAF. We can remove rcu_r…
CVE-2025-40141 medium 5.5 FIX rhel sles rocky 4mo ago In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: Fix possible UAF on iso_conn_free This attempt to fix similar issue to sco_conn_free where if the conn->sk is not…
CVE-2025-40135 medium 5.5 FIX rocky rhel sles google 4mo ago In the Linux kernel, the following vulnerability has been resolved: ipv6: use RCU in ip6_xmit() Use RCU in ip6_xmit() in order to use dst_dev_rcu() to prevent possible UAF.
CVE-2025-38730 medium 5.5 FIX rhel sles rocky 4mo ago In the Linux kernel, the following vulnerability has been resolved: io_uring/net: commit partial buffers on retry Ring provided buffers are potentially only valid within the single execution contex…
CVE-2025-38459 medium 5.5 FIX rocky rhel sles 4mo ago In the Linux kernel, the following vulnerability has been resolved: atm: clip: Fix infinite recursive call of clip_push(). syzbot reported the splat below. [0] This happens if we call ioctl(ATMARP…
CVE-2025-38415 medium 5.5 FIX rocky rhel sles 4mo ago In the Linux kernel, the following vulnerability has been resolved: Squashfs: check return result of sb_min_blocksize Syzkaller reports an "UBSAN: shift-out-of-bounds in squashfs_bio_read" bug. Sy…
CVE-2025-38403 medium 5.5 FIX rocky rhel sles 4mo ago In the Linux kernel, the following vulnerability has been resolved: vsock/vmci: Clear the vmci transport packet properly when initializing it In vmci_transport_packet_init memset the vmci_transport…
CVE-2025-38024 medium 5.5 FIX rocky rhel sles 4mo ago In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix slab-use-after-free Read in rxe_queue_cleanup bug Call Trace: <TASK> __dump_stack lib/dump_stack.c:94 [inline] d…
CVE-2025-38022 medium 5.5 FIX rocky rhel sles 4mo ago In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix "KASAN: slab-use-after-free Read in ib_register_device" problem Call Trace: __dump_stack lib/dump_stack.c:94 [in…
CVE-2025-37819 medium 5.5 FIX rhel sles rocky 4mo ago In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v2m: Prevent use after free of gicv2m_get_fwnode() With ACPI in place, gicv2m_get_fwnode() is registered with the pci…
CVE-2025-37789 medium 5.5 FIX rhel sles rocky 4mo ago In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: fix nested key length validation in the set() action It's not safe to access nla_len(ovs_key) if the data is sm…
CVE-2026-1709 critical 9.5 FIX rhel sles rocky 4mo ago Critical: keylime security update
CVE-2025-14104 medium 5.5 FIX rocky rhel sles 4mo ago A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-…
CVE-2025-40251 medium 5.5 5.5 FIX rhel sles rocky 4mo ago In the Linux kernel, the following vulnerability has been resolved: devlink: rate: Unset parent pointer in devl_rate_nodes_destroy The function devl_rate_nodes_destroy is documented to "Unset paren…
CVE-2025-38568 medium 5.5 FIX rhel sles rocky 4mo ago In the Linux kernel, the following vulnerability has been resolved: net/sched: mqprio: fix stack out-of-bounds write in tc entry parsing TCA_MQPRIO_TC_ENTRY_INDEX is validated using NLA_POLICY_MAX(…
CVE-2024-26766 medium 5.5 FIX rocky slesdebian debian 4mo ago In the Linux kernel, the following vulnerability has been resolved: IB/hfi1: Fix sdma.h tx->num_descs off-by-one error Unfortunately the commit `fd8958efe877` introduced another error causing the `…
CVE-2025-54349 medium 5.5 FIX rocky rheldebian debian 4mo ago RHSA-2026:1592: iperf3 security update (Moderate)
CVE-2026-22796 medium 5.3 5.3 FIX rhel sles rocky openssl 4mo ago Important: openssl security update
CVE-2026-22795 medium 5.5 5.5 FIX rhel sles rocky openssl 4mo ago Important: openssl security update
CVE-2025-69418 medium 4.0 4.0 FIX rhel sles rocky openssl 4mo ago Important: openssl security update
CVE-2025-68160 medium 4.7 4.7 FIX rhel sles rocky openssl 4mo ago Important: openssl security update
CVE-2025-14178 medium 5.5 FIX rockyalmalinux almalinux rhel 4mo ago RHSA-2026:2470: php:7.4 security update (Moderate)
CVE-2025-14177 medium 5.5 FIX rocky rhelalmalinux almalinux 4mo ago RHSA-2026:2470: php:7.4 security update (Moderate)
CVE-2025-12084 medium 5.5 FIX rocky rheldebian debian 4mo ago When building nested elements using xml.dom.minidom methods such as appendChild() that have a dependency on _clear_id_cache() the algorithm is quadratic. Availability can be impacted when building ex…
CVE-2025-40258 medium 5.5 FIX rocky rhel sles 4mo ago In the Linux kernel, the following vulnerability has been resolved: mptcp: fix race condition in mptcp_schedule_work() syzbot reported use-after-free in mptcp_schedule_work() [1] Issue here is tha…
CVE-2026-21933 medium 6.1 6.1 FIX rocky rhel sles oracle 4mo ago RHSA-2026:4832: java-1.8.0-ibm security update (Important)
CVE-2026-21925 medium 4.8 4.8 FIX rocky rhel sles oracle 4mo ago RHSA-2026:4832: java-1.8.0-ibm security update (Important)
CVE-2025-67726 medium 5.5 FIX rocky slesdebian debian 4mo ago RHSA-2026:0930: pcs security update (Moderate)
CVE-2025-67725 medium 5.5 FIX rocky slesdebian debian 4mo ago RHSA-2026:0930: pcs security update (Moderate)
CVE-2025-68285 medium 5.5 FIX rocky rhel sles 5mo ago In the Linux kernel, the following vulnerability has been resolved: libceph: fix potential use-after-free in have_mon_and_osd_map() The wait loop in __ceph_open_session() can race with the client r…
CVE-2025-46397 medium 5.5 FIX rocky rheldebian debian 5mo ago RHSA-2026:0756: transfig security update (Moderate)
CVE-2025-14242 medium 5.5 FIX rocky rhel sles 5mo ago RHSA-2026:0608: vsftpd security update (Moderate)
CVE-2025-12817 medium 5.5 FIX rocky rhel sles 5mo ago RHSA-2026:0524: postgresql:15 security update (Moderate)
CVE-2025-39883 medium 5.5 FIX rocky rhel sles 5mo ago In the Linux kernel, the following vulnerability has been resolved: mm/memory-failure: fix VM_BUG_ON_PAGE(PagePoisoned(page)) when unpoison memory When I did memory failure tests, below panic occur…
CVE-2025-39840 medium 5.5 FIX rhel sles rocky 5mo ago In the Linux kernel, the following vulnerability has been resolved: audit: fix out-of-bounds read in audit_compare_dname_path() When a watch on dir=/ is combined with an fsnotify event for a single…
CVE-2025-12818 medium 5.5 FIX rocky rhel sles 5mo ago RHSA-2026:0695: libpq security update (Moderate)
CVE-2025-61915 medium 5.5 FIX rocky rheldebian debian 5mo ago RHSA-2026:0596: cups security update (Moderate)