Search

Found 22,468 results in 2044ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-6846 high 7.8 7.8 debian debian sles rhel gnuredhat 2mo ago A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker c…
CVE-2026-6845 medium 5.0 5.0 debian debian sles rhel gnuredhat 2mo ago A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially c…
CVE-2026-6844 medium 5.5 5.5 debian debian sles rhel gnuredhat 2mo ago A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable …
CVE-2026-6843 medium 5.5 5.5 FIX debian debian rhelubuntu ubuntu gnuredhat 2mo ago Nano vulnerabilities
CVE-2026-31433 high 8.8 8.8 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix potencial OOB in get_file_all_info() for compound requests When a compound request consists of QUERY_DIRECTORY + QUERY…
CVE-2026-31432 high 8.8 8.8 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix OOB write in QUERY_INFO for compound requests When a compound request such as READ + QUERY_INFO(Security) is received,…
CVE-2026-40542 high 7.3 7.3 FIX debian debian sles apache 2mo ago Apache HttpClient accepts SCRAM-SHA-256 authentication without proper mutual authentication verification
CVE-2026-26740 high 8.0 FIX rheldebian debian sles 2mo ago Buffer Overflow vulnerability in giflib v.5.2.2 allows a remote attacker to cause a denial of service via the EGifGCBToExtension overwriting an existing Graphic Control Extension block without valida…
CVE-2026-22008 high 8.0 FIX rhel slesdebian debian 2mo ago CRaC JDK 25 vulnerabilities
CVE-2026-34319 medium 5.0 5.0 FIX debian debianubuntu ubuntu oracle 2mo ago MySQL vulnerabilities
CVE-2026-34318 medium 5.8 5.8 FIX debian debianubuntu ubuntu oracle 2mo ago MySQL vulnerabilities
CVE-2026-34317 medium 5.0 5.0 FIX debian debianubuntu ubuntu oracle 2mo ago MySQL vulnerabilities
CVE-2026-33813 high 7.5 7.5 FIX debian debian golang 2mo ago Parsing a WEBP image with an invalid, large size panics on 32-bit platforms.
CVE-2026-33812 medium 6.1 6.1 FIX debian debian golang 2mo ago Parsing a malicious font file can cause excessive memory allocation.
CVE-2026-34839 high 8.0 FIX debian debian 2mo ago Glances: Cross-Origin Information Disclosure via Unauthenticated REST API (/api/4) due to Permissive CORS
CVE-2026-6784 high 7.5 7.5 FIX debian debian mozilla 2mo ago Memory safety bugs present in Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited t…
CVE-2026-32147 medium 4.3 4.3 FIX debian debian sles erlang 2mo ago Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an authenticated SFTP user to modify file attributes outside t…
CVE-2026-3219 medium 5.5 FIX slesdebian debian 2mo ago pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as ins…
CVE-2026-31430 high 7.1 7.1 FIX slesdebian debian linux-kernel google 2mo ago In the Linux kernel, the following vulnerability has been resolved: X.509: Fix out-of-bounds access when parsing extensions Leo reports an out-of-bounds access when parsing a certificate with empty…
CVE-2026-31429 medium 5.5 5.5 FIX slesdebian debian linux-kernel google 2mo ago In the Linux kernel, the following vulnerability has been resolved: net: skb: fix cross-cache free of KFENCE-allocated skb head SKB_SMALL_HEAD_CACHE_SIZE is intentionally set to a non-power-of-2 va…
CVE-2026-27622 high 8.0 FIX rhel slesdebian debian 2mo ago OpenEXR vulnerabilities
CVE-2026-41254 high 7.5 7.5 FIX debian debian slesubuntu ubuntu littlecms 2mo ago Little CMS vulnerability
CVE-2026-40527 high 7.8 7.8 FIX debian debian radare 2mo ago radare2 prior to commit bc5a890 contains a command injection vulnerability in the afsv/afsvj command path where crafted ELF binaries can embed malicious r2 command sequences as DWARF DW_TAG_formal_pa…
CVE-2026-6491 medium 5.3 5.3 debian debian 2mo ago A security vulnerability has been detected in libvips up to 8.18.2. The affected element is the function im_minpos_vec of the file libvips/deprecated/vips7compat.c of the component nip2 Handler. Such…
CVE-2026-41493 high 7.5 7.5 debian debianubuntu ubuntu yardoc 2mo ago YARD vulnerability
CVE-2026-40170 high 7.5 7.5 FIX slesdebian debianubuntu ubuntu tatsuhiro-t 2mo ago ngtcp2 vulnerability
CVE-2026-41313 medium 6.5 6.5 debian debian pypdf_project 2mo ago pypdf: Possible long runtimes for wrong size values in incremental mode
CVE-2026-41312 medium 6.5 6.5 debian debian pypdf_project 2mo ago pypdf: Manipulated FlateDecode predictor parameters can exhaust RAM
CVE-2026-5121 high 7.5 7.5 FIX rheldebian debian sles libarchiveredhat 2mo ago libarchive vulnerabilities
CVE-2026-6384 high 7.8 7.8 FIX debian debian rhel gimp 2mo ago A flaw was found in gimp. This buffer overflow vulnerability in the GIF image loading component's `ReadJeffsImage` function allows an attacker to write beyond an allocated buffer by processing a spec…
CVE-2026-6364 medium 6.5 6.5 FIX debian debian google 2mo ago Out of bounds read in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted file. (Chromium security se…
CVE-2026-6362 medium 4.3 4.3 FIX debian debian google 2mo ago Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform out of bounds memory access via a crafted video file. (Chromium security severity: H…
CVE-2026-6361 high 8.3 8.3 FIX debian debian google 2mo ago Heap buffer overflow in PDFium in Google Chrome on Windows prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a …
CVE-2026-6360 high 8.8 8.8 FIX debian debian google 2mo ago Use after free in FileSystem in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2026-6317 high 8.8 8.8 FIX debian debian linux-kernelmacos macos google 2mo ago Use after free in Cast in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
CVE-2026-6315 high 8.8 8.8 FIX debian debian google 2mo ago Use after free in Permissions in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a craf…
CVE-2026-6314 high 8.3 8.3 FIX debian debian linux-kernelmacos macos google 2mo ago Out of bounds write in GPU in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the GPU process to potentially perform a sandbox escape via a crafted HTML page. (Chr…
CVE-2026-6309 high 8.3 8.3 FIX debian debian linux-kernelmacos macos google 2mo ago Use after free in Viz in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chr…
CVE-2026-6308 high 7.5 7.5 FIX debian debian linux-kernelmacos macos google 2mo ago Out of bounds read in Media in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page…
CVE-2026-6306 high 8.8 8.8 FIX debian debian linux-kernelmacos macos google 2mo ago Heap buffer overflow in PDFium in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High)
CVE-2026-6304 high 8.3 8.3 FIX debian debian linux-kernelmacos macos google 2mo ago Use after free in Graphite in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.…
CVE-2026-6302 high 8.8 8.8 FIX debian debian linux-kernelmacos macos google 2mo ago Use after free in Video in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-6301 high 8.8 8.8 FIX debian debian linux-kernelmacos macos google 2mo ago Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-6300 high 8.8 8.8 FIX debian debian linux-kernelmacos macos google 2mo ago Use after free in CSS in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-6299 high 8.8 8.8 FIX debian debian linux-kernelmacos macos google 2mo ago Use after free in Prerender in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
CVE-2026-40919 medium 5.5 5.5 FIX debian debian rhel gimp 2mo ago A flaw was found in GIMP. This vulnerability, a buffer overflow in the `file-seattle-filmworks` plugin, can be exploited when a user opens a specially crafted Seattle Filmworks file. A remote attacke…
CVE-2026-40918 medium 5.5 5.5 FIX debian debian rhel gimp 2mo ago A flaw was found in GIMP. Processing a specially crafted PVR image file with large dimensions can lead to a denial of service (DoS). This occurs due to a stack-based buffer overflow and an out-of-bou…
CVE-2026-40917 high 7.1 7.1 FIX debian debian rhel gimp 2mo ago A flaw was found in GIMP. This vulnerability, a heap buffer over-read in the `icns_slurp()` function, occurs when processing specially crafted ICNS image files. An attacker could provide a malicious …
CVE-2026-40916 medium 5.5 5.5 FIX debian debian rhel gimp 2mo ago A flaw was found in GIMP. A stack buffer overflow vulnerability in the TIM image loader's 4BPP decoding path allows a local user to cause a Denial of Service (DoS). By opening a specially crafted TIM…
CVE-2026-40915 high 7.8 7.8 FIX debian debian rhel gimp 2mo ago A flaw was found in GIMP. A remote attacker could exploit an integer overflow vulnerability in the FITS image loader by providing a specially crafted FITS file. This integer overflow leads to a zero-…
CVE-2026-6319 high 7.5 7.5 FIX debian debian google 2mo ago Use after free in Payments in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted…
CVE-2026-6318 high 8.8 8.8 FIX debian debian linux-kernelmacos macos google 2mo ago Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-6363 high 8.8 8.8 FIX debian debian google 2mo ago Type Confusion in V8 in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-6316 high 8.8 8.8 FIX debian debian linux-kernelmacos macos google 2mo ago Use after free in Forms in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-6311 high 8.3 8.3 FIX debian debian google 2mo ago Uninitialized Use in Accessibility in Google Chrome on Windows prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a…
CVE-2026-6310 high 8.3 8.3 FIX debian debian linux-kernelmacos macos google 2mo ago Use after free in Dawn in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Ch…
CVE-2026-6305 high 8.8 8.8 FIX debian debian linux-kernelmacos macos google 2mo ago Heap buffer overflow in PDFium in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High)
CVE-2026-6303 high 8.8 8.8 FIX debian debian linux-kernelmacos macos google 2mo ago Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-6358 high 8.8 8.8 FIX debian debian google 2mo ago Use after free in XR in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Critic…
CVE-2026-6298 medium 4.3 4.3 FIX debian debian linux-kernelmacos macos google 2mo ago Heap buffer overflow in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium secu…
CVE-2026-6297 high 8.3 8.3 FIX debian debian linux-kernelmacos macos google 2mo ago Use after free in Proxy in Google Chrome prior to 147.0.7727.101 allowed an attacker in a privileged network position to potentially perform a sandbox escape via a crafted HTML page. (Chromium securi…
CVE-2026-40499 high 7.8 7.8 FIX debian debian radare 2mo ago radare2 prior to version 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute arbitrary commands by embedding a newline byte in…
CVE-2026-33412 high 8.0 FIX rocky rhel sles 2mo ago Important: vim security update
CVE-2026-28421 medium 5.3 5.3 FIX rocky rhel sles 2mo ago Important: vim security update
CVE-2026-28417 medium 4.4 4.4 FIX rocky rhel sles 2mo ago Important: vim security update
CVE-2026-40311 medium 5.5 FIX debian debian sles 2mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Versions below 7.1.2-19 and 6.9.13-44 contain a heap use-after-free vulnerability that can cause a crash…
CVE-2026-40491 high 7.8 7.8 FIX debian debian wkentaro 2mo ago gdown is a Google Drive public file/folder downloader. Versions prior to 5.2.2 are vulnerable to a Path Traversal attack within the extractall functionality. When extracting a maliciously crafted ZIP…
CVE-2026-6654 medium 5.1 5.1 FIX debian debian mozilla 2mo ago Double-Free / Use-After-Free (UAF) in the `IntoIter::drop` and `ThinVec::clear` functions in the thin_vec crate. A panic in `ptr::drop_in_place` skips setting the length to zero.
CVE-2026-6231 high 7.5 7.5 FIX debian debian mongodb 2mo ago The bson_validate function may return early on specific inputs and incorrectly report success. This behavior could result in skipping validation for BSON data, allowing malformed or invalid UTF-8 seq…
CVE-2026-31428 medium 5.5 5.5 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_log: fix uninitialized padding leak in NFULA_PAYLOAD __build_packet_message() manually constructs the NFULA_…
CVE-2026-31427 medium 5.5 5.5 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: fix use of uninitialized rtp_addr in process_sdp process_sdp() declares union nf_inet_addr rtp_addr …
CVE-2026-31426 high 7.0 7.0 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: ACPI: EC: clean up handlers on probe failure in acpi_ec_setup() When ec_install_handlers() returns -EPROBE_DEFER on reduced-hardw…
CVE-2026-31425 medium 5.5 5.5 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: rds: ib: reject FRMR registration before IB connection is established rds_ib_get_mr() extracts the rds_ib_connection from conn->c…
CVE-2026-31424 medium 5.5 5.5 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: netfilter: x_tables: restrict xt_check_match/xt_check_target extensions for NFPROTO_ARP Weiming Shi says: xt_match and xt_target…
CVE-2026-31423 medium 5.5 5.5 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_hfsc: fix divide-by-zero in rtsc_min() m2sm() converts a u32 slope to a u64 scaled value. For large inputs (e.g. …
CVE-2026-31422 medium 5.5 5.5 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_flow: fix NULL pointer dereference on shared blocks flow_change() calls tcf_block_q() and dereferences q->handle t…
CVE-2026-31421 medium 5.5 5.5 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_fw: fix NULL pointer dereference on shared blocks The old-method path in fw_classify() calls tcf_block_q() and der…
CVE-2026-31420 medium 5.5 5.5 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: bridge: mrp: reject zero test interval to avoid OOM panic br_mrp_start_test() and br_mrp_start_in_test() accept the user-supplied…
CVE-2026-31419 high 7.8 7.8 FIX slesdebian debian linux-kernel google 2mo ago Linux kernel vulnerabilities
CVE-2026-31418 medium 5.5 5.5 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: drop logically empty buckets in mtype_del mtype_del() counts empty slots below n->pos in k, but it only drops t…
CVE-2026-31417 high 7.5 7.5 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: net/x25: Fix overflow when accumulating packets Add a check to ensure that `x25_sock.fraglen` does not overflow. The `fraglen` a…
CVE-2026-31416 medium 5.5 5.5 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_log: account for netlink header size This is a followup to an old bug fix: NLMSG_DONE needs to account for t…
CVE-2026-31415 medium 5.5 5.5 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: ipv6: avoid overflows in ip6_datagram_send_ctl() Yiming Qian reported : <quote> I believe I found a locally triggerable kernel b…
CVE-2026-5734 high 8.0 FIX rhelalmalinux almalinuxdebian debian 2mo ago Important: thunderbird security update
CVE-2026-5732 high 8.0 FIX rhelalmalinux almalinuxdebian debian 2mo ago Important: thunderbird security update
CVE-2026-5731 high 8.0 FIX rhelalmalinux almalinuxdebian debian 2mo ago Important: thunderbird security update
CVE-2026-1519 high 7.5 7.5 FIX rheldebian debian sles isc 2mo ago Important: bind security update
CVE-2006-10003 high 8.0 FIX sles rheldebian debian 2mo ago RHSA-2026:7681: perl-XML-Parser security update (Important)
CVE-2006-10002 high 8.0 FIX sles rheldebian debian 2mo ago RHSA-2026:7681: perl-XML-Parser security update (Important)
CVE-2026-31413 high 7.8 7.8 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: bpf: Fix unsound scalar forking in maybe_fork_scalars() for BPF_OR maybe_fork_scalars() is called for both BPF_AND and BPF_OR whe…
CVE-2026-40354 medium 6.3 6.3 FIX slesdebian debianubuntu ubuntu flatpak 2mo ago XDG Desktop Portal vulnerability
CVE-2026-40175 medium 4.8 4.8 FIX debian debian axios 2mo ago Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
CVE-2026-34479 high 7.5 7.5 FIX debian debian sles apache 2mo ago Apache Log4j 1 to Log4j 2 bridge: silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters
CVE-2026-34477 medium 5.9 5.9 FIX debian debian sles apache 2mo ago Apache Log4j Core: `verifyHostName` attribute silently ignored in TLS configuration
CVE-2026-39304 high 7.5 7.5 debian debian apache 2mo ago Apache ActiveMQ: Denial of Service via Out of Memory vulnerability
CVE-2026-31412 medium 5.5 5.5 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_mass_storage: Fix potential integer overflow in check_command_size_in_blocks() The `check_command_size_in_blocks()…
CVE-2026-5479 high 8.1 8.1 FIX debian debian wolfssl 2mo ago In wolfSSL's EVP layer, the ChaCha20-Poly1305 AEAD decryption path in wolfSSL_EVP_CipherFinal (and related EVP cipher finalization functions) fails to verify the authentication tag before returning p…
CVE-2026-5466 high 8.1 8.1 FIX debian debian wolfssl 2mo ago wolfSSL's ECCSI signature verifier `wc_VerifyEccsiHash` decodes the `r` and `s` scalars from the signature blob via `mp_read_unsigned_bin` with no check that they lie in `[1, q-1]`. A crafted forged …
CVE-2026-5188 high 8.1 8.1 FIX debian debian wolfssl 2mo ago An integer underflow issue exists in wolfSSL when parsing the Subject Alternative Name (SAN) extension of X.509 certificates. A malformed certificate can specify an entry length larger than the enclo…
CVE-2026-33551 medium 5.3 5.3 FIX debian debian openstack 2mo ago An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application…