Search

Found 4,677 results in 2648ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2024-53104 high 9.5 KEVFIX rhel rocky sles 1y ago Important: kernel security update
CVE-2025-1015 high 8.0 FIX rhel rocky sles 1y ago RHSA-2025:1292: thunderbird security update (Important)
CVE-2025-0510 high 8.0 FIX rhel rocky sles 1y ago RHSA-2025:1292: thunderbird security update (Important)
CVE-2025-1017 high 8.0 FIX rhel rockydebian debian 1y ago Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 128.6, and Thunderbird 128.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort so…
CVE-2025-1016 high 8.0 FIX rhel rockydebian debian 1y ago Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 115.19, Firefox ESR 128.6, Thunderbird 115.19, and Thunderbird 128.6. Some of these bugs showed evidence of memory corruption a…
CVE-2025-1014 high 8.0 FIX rhel rockydebian debian 1y ago Certificate length was not properly checked when added to a certificate store. In practice only trusted data was processed. This vulnerability was fixed in Firefox 135, Firefox ESR 128.7, Thunderbird…
CVE-2025-1013 high 8.0 FIX rhel rockydebian debian 1y ago A race condition could have led to private browsing tabs being opened in normal browsing windows. This could have resulted in a potential privacy leak. This vulnerability was fixed in Firefox 135, Fi…
CVE-2025-1012 high 8.0 FIX rhel rockydebian debian 1y ago A race during concurrent delazification could have led to a use-after-free. This vulnerability was fixed in Firefox 135, Firefox ESR 115.20, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.
CVE-2025-1011 high 8.0 FIX rhel rockydebian debian 1y ago A bug in WebAssembly code generation could have lead to a crash. It may have been possible for an attacker to leverage this to achieve code execution. This vulnerability was fixed in Firefox 135, Fir…
CVE-2025-1010 high 8.0 FIX rhel rockydebian debian 1y ago An attacker could have caused a use-after-free via the Custom Highlight API, leading to a potentially exploitable crash. This vulnerability was fixed in Firefox 135, Firefox ESR 115.20, Firefox ESR 1…
CVE-2025-1009 high 8.0 FIX rhel rockydebian debian 1y ago An attacker could have caused a use-after-free via crafted XSLT data, leading to a potentially exploitable crash. This vulnerability was fixed in Firefox 135, Firefox ESR 115.20, Firefox ESR 128.7, T…
CVE-2024-11218 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:1372: container-tools:rhel8 security update (Important)
CVE-2024-52531 high 8.0 FIX rhel rocky sles 1y ago RHSA-2025:0838: libsoup security update (Important)
CVE-2024-51741 high 8.0 FIX rhel sles rocky 1y ago Important: redis:7 security update
CVE-2024-46981 high 8.0 FIX rhel rocky sles 1y ago Important: redis security update
CVE-2022-24834 high 8.0 FIX rhel rocky sles 1y ago Important: redis security update
CVE-2024-53263 high 8.0 FIX rhel rockydebian debian 1y ago Git LFS is a Git extension for versioning large files. When Git LFS requests credentials from Git for a remote host, it passes portions of the host's URL to the `git-credential(1)` command without ch…
CVE-2023-28856 high 8.0 FIX rocky slesdebian debian 1y ago RHSA-2025:0595: redis:6 security update (Important)
CVE-2023-25155 high 8.0 FIX rocky slesdebian debian 1y ago RHSA-2025:0595: redis:6 security update (Important)
CVE-2023-22458 high 8.0 FIX rocky slesdebian debian 1y ago RHSA-2025:0595: redis:6 security update (Important)
CVE-2022-36021 high 8.0 FIX rocky slesdebian debian 1y ago RHSA-2025:0595: redis:6 security update (Important)
CVE-2022-35977 high 8.0 FIX rocky slesdebian debian 1y ago RHSA-2025:0595: redis:6 security update (Important)
CVE-2024-12085 high 8.0 FIX arch arch rhel rocky 1y ago RHSA-2025:0325: rsync security update (Important)
CVE-2025-21176 high 8.0 rhel rocky 1y ago RHSA-2025:0382: .NET 9.0 security update (Important)
CVE-2025-21173 high 8.0 rhel rocky 1y ago RHSA-2025:0382: .NET 9.0 security update (Important)
CVE-2025-21172 high 8.0 rhel rocky 1y ago RHSA-2025:0382: .NET 9.0 security update (Important)
CVE-2025-21171 high 8.0 rhel rocky 1y ago RHSA-2025:0382: .NET 9.0 security update (Important)
CVE-2024-57823 high 8.0 FIX rhel rocky sles 1y ago In Raptor RDF Syntax Library through 2.0.16, there is an integer underflow when normalizing a URI with the turtle parser in raptor_uri_normalize_path().
CVE-2024-56326 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:0711: python-jinja2 security update (Important)
CVE-2024-56201 high 8.0 FIX rheldebian debian sles 1y ago Important: fence-agents security update
CVE-2024-54508 high 7.5 7.5 FIX rhel rocky sles apple 1y ago The issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.6, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processi…
CVE-2024-54505 high 8.0 FIX rhel rocky sles 1y ago A type confusion issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 1…
CVE-2024-54502 high 8.0 FIX rhel rocky sles 1y ago The issue was addressed with improved checks. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.6, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing malici…
CVE-2024-54479 high 8.0 FIX rhel rocky sles 1y ago The issue was addressed with improved checks. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing malici…
CVE-2024-53580 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:0168: iperf3 security update (Important)
CVE-2024-11614 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:0222: dpdk security update (Important)
CVE-2025-0243 high 8.0 FIX rhel rockydebian debian 1y ago Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 128.5, and Thunderbird 128.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort so…
CVE-2025-0242 high 8.0 FIX rhel rockydebian debian 1y ago Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 115.18, Firefox ESR 128.5, Thunderbird 115.18, and Thunderbird 128.5. Some of these bugs showed evidence of memory corruption a…
CVE-2025-0241 high 8.0 FIX rhel rockydebian debian 1y ago When segmenting specially crafted text, segmentation would corrupt memory leading to a potentially exploitable crash. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, …
CVE-2025-0240 high 8.0 FIX rhel rockydebian debian 1y ago Parsing a JavaScript module as JSON could, under some circumstances, cause cross-compartment access, which may result in a use-after-free. This vulnerability was fixed in Firefox 134, Firefox ESR 128…
CVE-2025-0239 high 8.0 FIX rhel rockydebian debian 1y ago When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbir…
CVE-2025-0238 high 8.0 FIX rhel rockydebian debian 1y ago Assuming a controlled failed memory allocation, an attacker could have caused a use-after-free, leading to a potentially exploitable crash. This vulnerability was fixed in Firefox 134, Firefox ESR 12…
CVE-2025-0237 high 8.0 FIX rhel rockydebian debian 1y ago The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege…
CVE-2024-53122 high 8.0 FIX rhel rocky sles 1y ago Important: kernel security update
CVE-2024-50252 high 8.0 FIX rhel slesdebian debian 1y ago Important: kernel security update
CVE-2024-50208 high 8.0 FIX rhel slesdebian debian 1y ago Important: kernel security update
CVE-2024-46713 high 8.0 FIX rhel slesdebian debian 1y ago Important: kernel security update
CVE-2025-21614 high 8.0 FIX rockydebian debian rhel 1y ago go-git is a highly extensible git implementation library written in pure Go. A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.13. This vulnerability allows an att…
CVE-2025-21613 high 8.0 FIX rockydebian debian sles 1y ago go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vuln…
CVE-2024-50262 high 7.8 7.8 FIX rhel slesdebian debian 2y ago Moderate: kernel security update
CVE-2024-8508 high 8.0 FIX rhel rocky sles 2y ago RHSA-2025:0837: unbound security update (Important)
CVE-2024-34156 high 8.0 FIX rhel rockydebian debian 2y ago RHSA-2024:8038: container-tools:rhel8 security update (Important)
CVE-2024-10041 high 8.0 FIX rhel rocky sles 2y ago RHSA-2024:10379: pam security update (Important)
CVE-2024-47615 high 8.0 FIX rhel rockydebian debian 2y ago RHSA-2024:11345: gstreamer1-plugins-base security update (Important)
CVE-2024-47613 high 8.0 FIX rhel rockydebian debian 2y ago GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been identified in `gst_gdk_pixbuf_dec_flush` within `gstgdkpixbufdec.c`. Thi…
CVE-2024-47607 high 8.0 FIX rhel rockydebian debian 2y ago RHSA-2024:11345: gstreamer1-plugins-base security update (Important)
CVE-2024-47606 high 8.0 FIX rhel rockydebian debian 2y ago GStreamer is a library for constructing graphs of media-handling components. An integer underflow has been detected in the function qtdemux_parse_theora_extension within qtdemux.c. The vulnerability …
CVE-2024-47540 high 8.0 FIX rhel rockydebian debian 2y ago GStreamer is a library for constructing graphs of media-handling components. An uninitialized stack variable vulnerability has been identified in the gst_matroska_demux_add_wvpk_header function withi…
CVE-2024-47539 high 8.0 FIX rhel rockydebian debian 2y ago GStreamer is a library for constructing graphs of media-handling components. An out-of-bounds write vulnerability was identified in the convert_to_s334_1a function in isomp4/qtdemux.c. The vulnerabil…
CVE-2024-47538 high 8.0 FIX rhel rockydebian debian 2y ago RHSA-2024:11345: gstreamer1-plugins-base security update (Important)
CVE-2024-47537 high 8.0 FIX rhel rockydebian debian 2y ago GStreamer is a library for constructing graphs of media-handling components. The program attempts to reallocate the memory pointed to by stream->samples to accommodate stream->n_samples + samples_cou…
CVE-2024-9287 high 8.0 FIX rocky rhel sles 2y ago A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands int…
CVE-2024-12254 high 8.0 FIX rhel rocky sles 2y ago RHSA-2024:10980: python3.12 security update (Important)
CVE-2024-11168 high 8.0 FIX rocky rhel sles 2y ago The urllib.parse.urlsplit() and urlparse() functions improperly validated bracketed hosts (`[]`), allowing hosts that weren't IPv6 or IPvFuture. This behavior was not conformant to RFC 3986 and poten…
CVE-2024-31449 high 8.0 FIX rhel rocky sles 2y ago Important: redis security update
CVE-2024-31228 high 8.0 FIX rhel rocky sles 2y ago Important: redis security update
CVE-2023-45145 high 8.0 FIX rhel rocky sles 2y ago Important: redis security update
CVE-2024-10979 high 8.0 FIX rhel rocky sles 2y ago RHSA-2024:10832: postgresql:13 security update (Important)
CVE-2024-10978 high 8.0 FIX rhel rocky sles 2y ago RHSA-2024:10832: postgresql:13 security update (Important)
CVE-2024-10976 high 8.0 FIX rhel rocky sles 2y ago RHSA-2024:10832: postgresql:13 security update (Important)
CVE-2024-52804 high 8.0 FIX rhel rocky sles 2y ago RHSA-2025:2872: pcs security update (Important)
CVE-2024-11699 high 8.0 FIX rhel rockydebian debian 2y ago Memory safety bugs present in Firefox 132, Firefox ESR 128.4, and Thunderbird 128.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could…
CVE-2024-11697 high 8.0 FIX rhel rockydebian debian 2y ago When handling keypress events, an attacker may have been able to trick a user into bypassing the "Open Executable File?" confirmation dialog. This could have led to malicious code execution. This vul…
CVE-2024-11696 high 8.0 FIX rhel rockydebian debian 2y ago The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature verification. This flaw, triggered by an invalid or unsupported extension manifest…
CVE-2024-11695 high 8.0 FIX rhel rockydebian debian 2y ago A crafted URL containing Arabic script and whitespace characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability affects Firefox < 133, Fir…
CVE-2024-11694 high 8.0 FIX rhel rockydebian debian 2y ago Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass and DOM-based XSS through the Google SafeFrame shim in the Web Compatibility extension. This issue c…
CVE-2024-11692 high 8.0 FIX rhel rockydebian debian 2y ago An attacker could cause a select dropdown to be shown over another tab; this could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 133, Firefox ESR < 12…
CVE-2024-11159 high 8.0 FIX rhel rocky sles 2y ago RHSA-2024:10591: thunderbird security update (Important)
CVE-2024-44309 high 9.5 KEVFIX rhel rocky sles 2y ago Apple iOS, macOS, and other Apple products contain an unspecified vulnerability when processing maliciously crafted web content that may lead to a cross-site scripting (XSS) attack.
CVE-2024-52336 high 8.0 FIX rhel sles rocky 2y ago Important: tuned security update
CVE-2024-10963 high 8.0 FIX rhel rocky sles 2y ago RHSA-2024:10379: pam security update (Important)
CVE-2024-53899 high 8.0 FIX rocky slesdebian debian 2y ago virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same…
CVE-2024-9632 high 8.0 FIX rhel rocky sles 2y ago A flaw was found in the X.org server. Due to improperly tracked allocation size in _XkbSetCompatMap, a local attacker may be able to trigger a buffer overflow condition via a specially crafted payloa…
CVE-2024-45802 high 8.0 FIX rhel rocky sles 2y ago RHSA-2024:9644: squid:4 security update (Important)
CVE-2024-9050 high 8.0 rhel rocky 2y ago RHSA-2024:8353: NetworkManager-libreswan security update (Important)
CVE-2024-52532 high 8.0 FIX rhel rocky sles 2y ago RHSA-2024:9573: libsoup security update (Important)
CVE-2024-52530 high 8.0 FIX rhel rocky sles 2y ago RHSA-2024:9573: libsoup security update (Important)
CVE-2024-44296 high 8.0 FIX rocky slesdebian debian 2y ago The issue was addressed with improved checks. This issue is fixed in Safari 18.1, iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. Pr…
CVE-2024-44244 high 8.0 FIX rhel rocky sles 2y ago A memory corruption issue was addressed with improved input validation. This issue is fixed in Safari 18.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. Proces…
CVE-2024-43499 high 8.0 FIX rhelalmalinux almalinux 2y ago Important: .NET 9.0 security update
CVE-2024-43498 high 8.0 FIX rhelalmalinux almalinux 2y ago Important: .NET 9.0 security update
CVE-2024-44970 high 8.0 FIX rhel rocky sles 2y ago In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: SHAMPO, Fix invalid WQ linked list unlink When all the strides in a WQE have been consumed, the WQE is unlinked from t…
CVE-2024-43830 high 7.8 7.8 FIX rhel rocky sles 2y ago In the Linux kernel, the following vulnerability has been resolved: leds: trigger: Unregister sysfs attributes before calling deactivate() Triggers which have trigger specific sysfs attributes typi…
CVE-2024-42240 high 8.0 FIX rhel rocky sles 2y ago In the Linux kernel, the following vulnerability has been resolved: x86/bhi: Avoid warning in #DB handler due to BHI mitigation When BHI mitigation is enabled, if SYSENTER is invoked with the TF fl…
CVE-2024-42238 high 8.0 FIX rhel rocky sles 2y ago In the Linux kernel, the following vulnerability has been resolved: firmware: cs_dsp: Return error if block header overflows file Return an error from cs_dsp_power_up() if a block header is longer …
CVE-2024-42237 high 8.0 FIX rhel rocky sles 2y ago In the Linux kernel, the following vulnerability has been resolved: firmware: cs_dsp: Validate payload length before processing block Move the payload length check in cs_dsp_load() and cs_dsp_coeff…
CVE-2024-42228 high 8.0 FIX rhel rocky sles 2y ago In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Using uninitialized value *size when calling amdgpu_vce_cs_reloc Initialize the size before calling amdgpu_vce_cs_rel…
CVE-2024-42226 high 8.0 FIX rhel rocky sles 2y ago RHSA-2024:7001: kernel-rt security update (Important)
CVE-2024-42159 high 8.0 FIX rhel slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: scsi: mpi3mr: Sanitise num_phys Information is stored in mr_sas_port->phy_mask, values larger then size of this field shouldn't b…
CVE-2024-42154 high 8.0 FIX rhel rocky sles 2y ago In the Linux kernel, the following vulnerability has been resolved: tcp_metrics: validate source addr length I don't see anything checking that TCP_METRICS_ATTR_SADDR_IPV4 is at least 4 bytes long,…