Search

Found 27,141 results in 3996ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2025-38687 medium 4.7 4.7 FIX slesdebian debian linux-kernel 9mo ago In the Linux kernel, the following vulnerability has been resolved: comedi: fix race between polling and detaching syzbot reports a use-after-free in comedi in the below link, which is due to comed…
CVE-2025-38683 medium 5.5 5.5 FIX slesdebian debian linux-kernel 9mo ago In the Linux kernel, the following vulnerability has been resolved: hv_netvsc: Fix panic during namespace deletion with VF The existing code move the VF NIC to new namespace when NETDEV_REGISTER is…
CVE-2025-38681 medium 4.7 4.7 FIX slesdebian debian linux-kernel 9mo ago In the Linux kernel, the following vulnerability has been resolved: mm/ptdump: take the memory hotplug lock inside ptdump_walk_pgd() Memory hot remove unmaps and tears down various kernel page tabl…
CVE-2025-58057 unknown FIX slesdebian debian 9mo ago Netty's decoders vulnerable to DoS via zip bomb style attack
CVE-2025-9901 medium 5.9 5.9 debian debian sles 9mo ago A flaw was found in libsoup’s caching mechanism, SoupCache, where the HTTP Vary header is ignored when evaluating cached responses. This header ensures that responses vary appropriately based on requ…
CVE-2025-9784 unknown FIX debian debian 9mo ago Undertow MadeYouReset HTTP/2 DDoS Vulnerability
CVE-2025-8194 medium 5.5 FIX rhel rocky sles 9mo ago There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error,…
CVE-2025-49812 medium 5.5 FIX debian debian rhel rocky 9mo ago In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle attacker to hijack an HTTP session via a TLS upgrade. Onl…
CVE-2025-49630 medium 5.5 FIX debian debian rhel rocky 9mo ago In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in mod_proxy_http2.…
CVE-2025-38684 medium 5.5 5.5 FIX rhel slesdebian debian 9mo ago Important: kernel security update
CVE-2025-23048 medium 5.5 FIX debian debian rhel rocky 9mo ago In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clients is possible using TLS 1.3 session resumption. Configurations are affected w…
CVE-2024-47252 medium 5.5 FIX debian debian rhel rocky 9mo ago Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/TLS client to insert escape characters into log files in some configurations. …
CVE-2025-9688 medium 5.0 5.0 debian debian 9mo ago A security vulnerability has been detected in Mupen64Plus up to 2.6.0. The affected element is the function write_is_viewer of the file src/device/cart/is_viewer.c. The manipulation leads to integer …
CVE-2025-9649 medium 5.5 5.5 FIX debian debian broadcom 9mo ago A security vulnerability has been detected in appneta tcpreplay 4.5.1. Impacted is the function calc_sleep_time of the file send_packets.c. Such manipulation leads to divide by zero. An attack has to…
CVE-2025-57803 unknown FIX debian debian sles 10mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2 for ImageMagick's 32-bit build, a 32-bit integer overflow in the…
CVE-2025-55298 unknown FIX debian debian sles 10mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to ImageMagick versions 6.9.13-28 and 7.1.2-2, a format string bug vulnerability exists in Interpr…
CVE-2025-55212 unknown FIX debian debian sles 10mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2, passing a geometry string containing only a colon (":") to mont…
CVE-2025-55160 unknown FIX debian debian sles 10mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-27 and 7.1.2-1, there is undefined behavior (function-type-mismatch) in splay t…
CVE-2025-55154 unknown FIX debian debian sles 10mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-27 and 7.1.2-1, the magnified size calculations in ReadOneMNGIMage (in coders/p…
CVE-2025-55004 unknown FIX debian debian sles 10mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-1, ImageMagick is vulnerable to heap-buffer overflow read around the handling of …
CVE-2025-68469 unknown FIX debian debian sles 10mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.1-14, ImageMagick crashes when processing a crafted TIFF file. Version 7.1.1-14 fix…
CVE-2025-53019 unknown FIX debian debian sles 10mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0 and 6.9.13-26, in ImageMagick's `magick stream` command, specifying multipl…
CVE-2025-53014 unknown FIX debian debian sles 10mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Versions prior to 7.1.2-0 and 6.9.13-26 have a heap buffer overflow in the `InterpretImageFilename` func…
CVE-2025-53101 unknown FIX debian debian sles 10mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0 and 6.9.13-26, in ImageMagick's `magick mogrify` command, specifying multip…
CVE-2025-9403 medium 5.5 5.5 debian debian sles jqlang 10mo ago A vulnerability was determined in jqlang jq up to 1.6. Impacted is the function run_jq_tests of the file jq_test.c of the component JSON Parser. Executing manipulation can lead to reachable assertion…
CVE-2025-9396 medium 5.5 5.5 debian debian ckolivas 10mo ago A security flaw has been discovered in ckolivas lrzip up to 0.651. This impacts the function __GI_____strtol_l_internal of the file strtol_l.c. Performing manipulation results in null pointer derefer…
CVE-2025-9394 medium 5.5 5.5 FIX debian debian sles podofo_project 10mo ago A flaw has been found in PoDoFo 1.1.0-dev. This issue affects the function PdfTokenizer::DetermineDataType of the file src/podofo/main/PdfTokenizer.cpp of the component PDF Dictionary Parser. Executi…
CVE-2025-9390 medium 5.5 5.5 FIX slesdebian debian vim 10mo ago A security flaw has been discovered in vim up to 9.1.1615. Affected by this vulnerability is the function main of the file src/xxd/xxd.c of the component xxd. The manipulation results in buffer overf…
CVE-2025-9389 medium 5.5 5.5 FIX debian debian vim 10mo ago A vulnerability was identified in vim 9.1.0000. Affected is the function __memmove_avx_unaligned_erms of the file memmove-vec-unaligned-erms.S. The manipulation leads to memory corruption. The attack…
CVE-2025-9386 medium 5.5 5.5 FIX debian debian broadcom 10mo ago A vulnerability has been found in appneta tcpreplay up to 4.5.1. The impacted element is the function get_l2len_protocol of the file get.c of the component tcprewrite. Such manipulation leads to use …
CVE-2025-9385 medium 5.5 5.5 FIX debian debian broadcom 10mo ago A flaw has been found in appneta tcpreplay up to 4.5.1. The affected element is the function fix_ipv6_checksums of the file edit_packet.c of the component tcprewrite. This manipulation causes use aft…
CVE-2025-9384 medium 5.5 5.5 FIX debian debian broadcom 10mo ago A vulnerability was detected in appneta tcpreplay up to 4.5.1. Impacted is the function tcpedit_post_args of the file /src/tcpedit/parse_args.c. The manipulation results in null pointer dereference. …
CVE-2025-38659 medium 5.5 5.5 FIX slesdebian debian linux-kernel 10mo ago In the Linux kernel, the following vulnerability has been resolved: gfs2: No more self recovery When a node withdraws and it turns out that it is the only node that has the filesystem mounted, gfs2…
CVE-2025-38626 medium 5.5 5.5 FIX slesdebian debian linux-kernel 10mo ago In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to trigger foreground gc during f2fs_map_blocks() in lfs mode w/ "mode=lfs" mount option, generic/299 will cause system…
CVE-2025-54988 unknown FIX debian debian 10mo ago Apache Tika XXE Vulnerability via Crafted XFA File Inside a PDF
CVE-2025-5115 unknown FIX debian debian sles 10mo ago Eclipse Jetty affected by MadeYouReset HTTP/2 vulnerability
CVE-2025-9157 medium 5.3 5.3 FIX debian debian 10mo ago A vulnerability was determined in appneta tcpreplay up to 4.5.2-beta2. The impacted element is the function untrunc_packet of the file src/tcpedit/edit_packet.c of the component tcprewrite. Executing…
CVE-2022-24130 medium 5.5 FIX rhel sles rocky 10mo ago Moderate: xterm security update
CVE-2025-41242 unknown debian debian 10mo ago Spring Framework MVC Applications Path Traversal Vulnerability
CVE-2025-47906 medium 5.5 FIX rocky rheldebian debian 10mo ago RHSA-2025:22668: go-toolset:rhel8 security update (Moderate)
CVE-2025-38124 medium 5.5 5.5 FIX rhel slesdebian debian 10mo ago Important: kernel security update
CVE-2025-9019 medium 5.9 5.9 FIX debian debian broadcom 10mo ago A vulnerability has been found in tcpreplay 4.5.1. This vulnerability affects the function mask_cidr6 of the file cidr.c of the component tcpprep. The manipulation leads to heap-based buffer overflow…
CVE-2025-55163 unknown FIX slesdebian debian 10mo ago Netty affected by MadeYouReset HTTP/2 DDoS vulnerability
CVE-2025-8916 medium 5.5 FIX debian debian sles 10mo ago Bouncy Castle for Java bcpkix, bcprov, bcpkix-fips on All (API modules) allows Excessive Allocation
CVE-2025-8747 unknown FIX debian debian 10mo ago Keras vulnerable to CVE-2025-1550 bypass via reuse of internal functionality
CVE-2025-8885 unknown FIX debian debian sles 10mo ago Bouncy Castle for Java on All (API modules) allows Excessive Allocation
CVE-2025-55159 unknown FIX slesdebian debian 10mo ago slab is a pre-allocated storage for a uniform data type. In version 0.4.10, the get_disjoint_mut method incorrectly checked if indices were within the slab's capacity instead of its length, allowing …
CVE-2025-8844 medium 5.5 5.5 debian debian nasm 10mo ago A vulnerability was determined in NASM Netwide Assember 2.17rc0. This vulnerability affects the function parse_smacro_template of the file preproc.c. The manipulation leads to null pointer dereferenc…
CVE-2025-38292 medium 5.5 FIX rhel sles rocky 10mo ago Moderate: kernel security update
CVE-2021-47670 medium 5.5 FIX rocky slesdebian debian 10mo ago In the Linux kernel, the following vulnerability has been resolved: can: peak_usb: fix use after free bugs After calling peak_usb_netif_rx_ni(skb), dereferencing skb is unsafe. Especially, the can_…
CVE-2025-8746 medium 5.5 5.5 debian debian sles gnu 10mo ago A vulnerability, which was classified as problematic, was found in GNU libopts up to 27.6. Affected is the function __strstr_sse2. The manipulation leads to memory corruption. Local access is require…
CVE-2025-8736 medium 5.3 5.3 debian debian 10mo ago A vulnerability, which was classified as critical, has been found in GNU cflow up to 1.8. Affected by this issue is the function yylex of the file c.c of the component Lexer. The manipulation leads t…
CVE-2025-54368 unknown FIX slesdebian debian 10mo ago uv is a Python package and project manager written in Rust. In versions 0.8.5 and earlier, remote ZIP archives were handled in a streamwise fashion, and file entries were not reconciled against the a…
CVE-2025-32415 medium 5.5 FIX rhel rocky sles 10mo ago In libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchemaIDCFillNodeTables in xmlschemas.c has a heap-based buffer under-read. To exploit this, a crafted XML document must be validated against an …
CVE-2025-32414 medium 5.5 FIX rhel rocky sles 10mo ago In libxml2 before 2.13.8 and 2.14.x before 2.14.2, out-of-bounds memory access can occur in the Python API (Python bindings) because of an incorrect return value. This occurs in xmlPythonFileRead and…
CVE-2025-54799 unknown FIX debian debian 10mo ago Let's Encrypt client and ACME library written in Go (Lego). In versions 4.25.1 and below, the github.com/go-acme/lego/v4/acme/api package (thus the lego library and the lego cli as well) don't enforc…
CVE-2025-7345 medium 5.5 FIX rhel rockydebian debian 10mo ago RHSA-2025:13315: gdk-pixbuf2 security update (Moderate)
CVE-2025-48866 medium 5.5 FIX rhel slesdebian debian 10mo ago Moderate: mod_security security update
CVE-2025-3159 medium 5.5 FIX debian debian rhel sles 10mo ago Moderate: qt5-qt3d security update
CVE-2025-3158 medium 5.5 FIX debian debian rhel sles 10mo ago A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. Affected by this issue is the function Assimp::LWO::AnimResolver::UpdateAnimRangeSetup of …
CVE-2024-36350 medium 5.5 FIX debian debian rhel sles 10mo ago Moderate: kernel security update
CVE-2025-8058 medium 5.5 FIX rhel rockydebian debian 10mo ago RHSA-2025:12980: glibc security update (Moderate)
CVE-2024-47081 medium 5.5 FIX rhel rocky sles 10mo ago RHSA-2025:14999: resource-agents security update (Moderate)
CVE-2025-54410 unknown debian debian sles 10mo ago Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. A firewalld vulne…
CVE-2025-54388 unknown FIX debian debian sles 10mo ago Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. In versions 28.2.…
CVE-2025-5222 medium 5.5 FIX rheldebian debian sles 10mo ago Moderate: icu security update
CVE-2025-49133 medium 5.5 FIX rhel rockydebian debian 10mo ago RHSA-2025:12527: virt:rhel and virt-devel:rhel security update (Moderate)
CVE-2025-38491 medium 5.5 5.5 FIX slesdebian debian linux-kernel 10mo ago In the Linux kernel, the following vulnerability has been resolved: mptcp: make fallback action and fallback decision atomic Syzkaller reported the following splat: WARNING: CPU: 1 PID: 7704 at …
CVE-2025-38477 medium 4.7 4.7 FIX rocky slesdebian debian 10mo ago In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_qfq: Fix race condition on qfq_aggregate A race condition can occur when 'agg' is modified in qfq_change_agg (call…
CVE-2025-38468 medium 5.5 5.5 FIX slesdebian debian linux-kernel 10mo ago In the Linux kernel, the following vulnerability has been resolved: net/sched: Return NULL when htb_lookup_leaf encounters an empty rbtree htb_lookup_leaf has a BUG_ON that can trigger with the fol…
CVE-2025-40909 medium 5.5 FIX arch arch rhel rocky 10mo ago Perl threads have a working directory race condition where file operations may target unintended paths. If a directory handle is open at thread creation, the process-wide current working directory i…
CVE-2025-38110 medium 5.5 FIX rhel sles rocky 10mo ago Moderate: kernel security update
CVE-2025-38086 medium 5.5 FIX rhel rocky sles 10mo ago Moderate: kernel security update
CVE-2025-37958 medium 5.5 FIX rhel sles rocky 10mo ago Moderate: kernel security update
CVE-2025-37797 medium 5.5 FIX rhel rocky sles 10mo ago Moderate: kernel security update
CVE-2025-22121 medium 5.5 FIX rhel sles rocky 10mo ago Moderate: kernel security update
CVE-2025-22113 medium 5.5 FIX rhel sles rocky 10mo ago Moderate: kernel security update
CVE-2025-22091 medium 5.5 FIX rhel sles rocky 10mo ago Moderate: kernel security update
CVE-2025-22085 medium 5.5 FIX rhel sles rocky 10mo ago Moderate: kernel security update
CVE-2025-21905 medium 5.5 FIX rhel rocky sles 10mo ago Moderate: kernel security update
CVE-2024-57980 medium 5.5 FIX rhel rocky sles 10mo ago Moderate: kernel security update
CVE-2025-8224 medium 5.5 5.5 FIX debian debian sles gnu 11mo ago A vulnerability has been found in GNU Binutils 2.44 and classified as problematic. This vulnerability affects the function bfd_elf_get_str_section of the file bfd/elf.c of the component BFD Library. …
CVE-2025-38466 medium 5.5 5.5 FIX slesdebian debian linux-kernel 11mo ago In the Linux kernel, the following vulnerability has been resolved: perf: Revert to requiring CAP_SYS_ADMIN for uprobes Jann reports that uprobes can be used destructively when used in the middle o…
CVE-2025-38465 medium 5.5 5.5 FIX slesdebian debian linux-kernel 11mo ago In the Linux kernel, the following vulnerability has been resolved: netlink: Fix wraparounds of sk->sk_rmem_alloc. Netlink has this pattern in some places if (atomic_read(&sk->sk_rmem_alloc) > s…
CVE-2025-38457 medium 5.5 5.5 FIX slesdebian debian linux-kernel 11mo ago In the Linux kernel, the following vulnerability has been resolved: net/sched: Abort __tc_modify_qdisc if parent class does not exist Lion's patch [1] revealed an ancient bug in the qdisc API. When…
CVE-2025-38451 medium 5.5 5.5 FIX slesdebian debian linux-kernel 11mo ago In the Linux kernel, the following vulnerability has been resolved: md/md-bitmap: fix GPF in bitmap_get_stats() The commit message of commit 6ec1f0239485 ("md/md-bitmap: fix stats collection for ex…
CVE-2025-38430 medium 5.5 5.5 FIX slesdebian debian linux-kernel 11mo ago In the Linux kernel, the following vulnerability has been resolved: nfsd: nfsd4_spo_must_allow() must check this is a v4 compound request If the request being processed is not a v4 compound request…
CVE-2025-38364 medium 5.5 5.5 FIX slesdebian debian linux-kernel 11mo ago In the Linux kernel, the following vulnerability has been resolved: maple_tree: fix MA_STATE_PREALLOC flag in mas_preallocate() Temporarily clear the preallocation flag when explicitly requesting a…
CVE-2025-53015 unknown FIX debian debian sles 11mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0, infinite lines occur when writing during a specific XMP file conversion co…
CVE-2025-54121 unknown FIX slesdebian debian 11mo ago Starlette is a lightweight ASGI (Asynchronous Server Gateway Interface) framework/toolkit, designed for building async web services in Python. In versions 0.47.1 and below, when parsing a multi-part …
CVE-2025-7962 unknown debian debian sles 11mo ago Jakarta Mail vulnerable to SMTP Injection
CVE-2025-50151 unknown debian debian 11mo ago Apache Jena doesn't validate file access paths in configuration files uploaded by users with administrator access
CVE-2025-49656 unknown debian debian 11mo ago Apache Jena allows users with administrator access to create databases files outside the files area of the Fuseki server
CVE-2024-52615 medium 5.5 debian debian rhel sles 11mo ago Moderate: avahi security update
CVE-2024-50379 medium 5.5 FIX rhel rocky sles 11mo ago Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (…
CVE-2025-4373 medium 4.8 4.8 FIX rhel rockydebian debian 11mo ago RHSA-2025:11327: glib2 security update (Moderate)
CVE-2019-17543 medium 5.5 FIX rocky slesdebian debian 11mo ago RHSA-2025:11035: lz4 security update (Moderate)
CVE-2025-53643 unknown FIX slesdebian debian 11mo ago AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.12.14, the Python parser is vulnerable to a request smuggling vulnerability due to not parsing trail…
CVE-2025-53689 unknown FIX debian debian 11mo ago Apache Jackrabbit vulnerable to blind XXE attack due to insecure document build
CVE-2025-21991 medium 5.5 FIX rhel rocky sles 11mo ago Moderate: kernel security update