Search

Found 28,497 results in 2077ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2025-9165 low 2.5 2.5 FIX slesdebian debian libtiff 10mo ago A flaw has been found in LibTIFF 4.7.0. This affects the function _TIFFmallocExt/_TIFFCheckRealloc/TIFFHashSetNew/InitCCITTFax3 of the file tools/tiffcmp.c of the component tiffcmp. Executing manipul…
CVE-2025-9157 medium 5.3 5.3 FIX debian debian 10mo ago A vulnerability was determined in appneta tcpreplay up to 4.5.2-beta2. The impacted element is the function untrunc_packet of the file src/tcpedit/edit_packet.c of the component tcprewrite. Executing…
CVE-2022-24130 medium 5.5 FIX rhel sles rocky 10mo ago Moderate: xterm security update
CVE-2025-41242 unknown debian debian 10mo ago Spring Framework MVC Applications Path Traversal Vulnerability
CVE-2025-47906 medium 5.5 FIX rocky rheldebian debian 10mo ago RHSA-2025:22668: go-toolset:rhel8 security update (Moderate)
CVE-2025-38124 medium 5.5 5.5 FIX rhel slesdebian debian 10mo ago Important: kernel security update
CVE-2025-9019 medium 5.9 5.9 FIX debian debian broadcom 10mo ago A vulnerability has been found in tcpreplay 4.5.1. This vulnerability affects the function mask_cidr6 of the file cidr.c of the component tcpprep. The manipulation leads to heap-based buffer overflow…
CVE-2025-8961 low 3.3 3.3 FIX slesdebian debian libtiff 10mo ago A weakness has been identified in LibTIFF 4.7.0. This affects the function main of the file tiffcrop.c of the component tiffcrop. Executing manipulation can lead to memory corruption. The attack can …
CVE-2025-55163 unknown FIX slesdebian debian 10mo ago Netty affected by MadeYouReset HTTP/2 DDoS vulnerability
CVE-2025-8916 medium 5.5 FIX debian debian sles 10mo ago Bouncy Castle for Java bcpkix, bcprov, bcpkix-fips on All (API modules) allows Excessive Allocation
CVE-2025-8747 unknown FIX debian debian 10mo ago Keras vulnerable to CVE-2025-1550 bypass via reuse of internal functionality
CVE-2025-8885 unknown FIX debian debian sles 10mo ago Bouncy Castle for Java on All (API modules) allows Excessive Allocation
CVE-2025-55159 unknown FIX slesdebian debian 10mo ago slab is a pre-allocated storage for a uniform data type. In version 0.4.10, the get_disjoint_mut method incorrectly checked if indices were within the slab's capacity instead of its length, allowing …
CVE-2025-8844 medium 5.5 5.5 debian debian nasm 10mo ago A vulnerability was determined in NASM Netwide Assember 2.17rc0. This vulnerability affects the function parse_smacro_template of the file preproc.c. The manipulation leads to null pointer dereferenc…
CVE-2025-38292 medium 5.5 FIX rhel sles rocky 10mo ago Moderate: kernel security update
CVE-2021-47670 medium 5.5 FIX rocky slesdebian debian 10mo ago In the Linux kernel, the following vulnerability has been resolved: can: peak_usb: fix use after free bugs After calling peak_usb_netif_rx_ni(skb), dereferencing skb is unsafe. Especially, the can_…
CVE-2025-8746 medium 5.5 5.5 debian debian sles gnu 10mo ago A vulnerability, which was classified as problematic, was found in GNU libopts up to 27.6. Affected is the function __strstr_sse2. The manipulation leads to memory corruption. Local access is require…
CVE-2025-8736 medium 5.3 5.3 debian debian 10mo ago A vulnerability, which was classified as critical, has been found in GNU cflow up to 1.8. Affected by this issue is the function yylex of the file c.c of the component Lexer. The manipulation leads t…
CVE-2025-8735 low 3.3 3.3 debian debian 10mo ago A vulnerability classified as problematic was found in GNU cflow up to 1.8. Affected by this vulnerability is the function yylex of the file c.c of the component Lexer. The manipulation leads to null…
CVE-2025-8732 low 3.3 3.3 debian debian sles 10mo ago A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads…
CVE-2025-54368 unknown FIX slesdebian debian 10mo ago uv is a Python package and project manager written in Rust. In versions 0.8.5 and earlier, remote ZIP archives were handled in a streamwise fashion, and file entries were not reconciled against the a…
CVE-2025-32415 medium 5.5 FIX rhel rocky sles 10mo ago In libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchemaIDCFillNodeTables in xmlschemas.c has a heap-based buffer under-read. To exploit this, a crafted XML document must be validated against an …
CVE-2025-32414 medium 5.5 FIX rhel rocky sles 10mo ago In libxml2 before 2.13.8 and 2.14.x before 2.14.2, out-of-bounds memory access can occur in the Python API (Python bindings) because of an incorrect return value. This occurs in xmlPythonFileRead and…
CVE-2025-54799 unknown FIX debian debian 10mo ago Let's Encrypt client and ACME library written in Go (Lego). In versions 4.25.1 and below, the github.com/go-acme/lego/v4/acme/api package (thus the lego library and the lego cli as well) don't enforc…
CVE-2025-8534 low 2.5 2.5 FIX slesdebian debian libtiff 10mo ago A vulnerability classified as problematic was found in libtiff 4.6.0. This vulnerability affects the function PS_Lvl2page of the file tools/tiff2ps.c of the component tiff2ps. The manipulation leads …
CVE-2025-7345 medium 5.5 FIX rhel rockydebian debian 10mo ago RHSA-2025:13315: gdk-pixbuf2 security update (Moderate)
CVE-2025-48866 medium 5.5 FIX rhel slesdebian debian 10mo ago Moderate: mod_security security update
CVE-2025-3159 medium 5.5 FIX debian debian rhel sles 10mo ago Moderate: qt5-qt3d security update
CVE-2025-3158 medium 5.5 FIX debian debian rhel sles 10mo ago A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. Affected by this issue is the function Assimp::LWO::AnimResolver::UpdateAnimRangeSetup of …
CVE-2024-36350 medium 5.5 FIX debian debian rhel sles 10mo ago Moderate: kernel security update
CVE-2022-29458 low 2.5 FIX rhel sles rocky 10mo ago ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.
CVE-2025-8058 medium 5.5 FIX rhel rockydebian debian 10mo ago RHSA-2025:12980: glibc security update (Moderate)
CVE-2024-47081 medium 5.5 FIX rhel rocky sles 10mo ago RHSA-2025:14999: resource-agents security update (Moderate)
CVE-2025-54410 unknown debian debian sles 10mo ago Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. A firewalld vulne…
CVE-2025-54388 unknown FIX debian debian sles 10mo ago Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. In versions 28.2.…
CVE-2025-5222 medium 5.5 FIX rheldebian debian sles 10mo ago Moderate: icu security update
CVE-2025-49133 medium 5.5 FIX rhel rockydebian debian 10mo ago RHSA-2025:12527: virt:rhel and virt-devel:rhel security update (Moderate)
CVE-2025-8283 low 3.7 3.7 FIX slesdebian debian rhel redhat 10mo ago Netavark Has Possible DNS Resolve Confusion
CVE-2025-38491 medium 5.5 5.5 FIX slesdebian debian linux-kernel 10mo ago In the Linux kernel, the following vulnerability has been resolved: mptcp: make fallback action and fallback decision atomic Syzkaller reported the following splat: WARNING: CPU: 1 PID: 7704 at …
CVE-2025-38477 medium 4.7 4.7 FIX rocky slesdebian debian 10mo ago In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_qfq: Fix race condition on qfq_aggregate A race condition can occur when 'agg' is modified in qfq_change_agg (call…
CVE-2025-38468 medium 5.5 5.5 FIX slesdebian debian linux-kernel 10mo ago In the Linux kernel, the following vulnerability has been resolved: net/sched: Return NULL when htb_lookup_leaf encounters an empty rbtree htb_lookup_leaf has a BUG_ON that can trigger with the fol…
CVE-2025-40909 medium 5.5 FIX arch arch rhel rocky 10mo ago Perl threads have a working directory race condition where file operations may target unintended paths. If a directory handle is open at thread creation, the process-wide current working directory i…
CVE-2025-38110 medium 5.5 FIX rhel sles rocky 10mo ago Moderate: kernel security update
CVE-2025-38086 medium 5.5 FIX rhel rocky sles 10mo ago Moderate: kernel security update
CVE-2025-37958 medium 5.5 FIX rhel sles rocky 10mo ago Moderate: kernel security update
CVE-2025-37797 medium 5.5 FIX rhel rocky sles 10mo ago Moderate: kernel security update
CVE-2025-22121 medium 5.5 FIX rhel sles rocky 10mo ago Moderate: kernel security update
CVE-2025-22113 medium 5.5 FIX rhel sles rocky 10mo ago Moderate: kernel security update
CVE-2025-22091 medium 5.5 FIX rhel sles rocky 10mo ago Moderate: kernel security update
CVE-2025-22085 medium 5.5 FIX rhel sles rocky 10mo ago Moderate: kernel security update
CVE-2025-21905 medium 5.5 FIX rhel rocky sles 10mo ago Moderate: kernel security update
CVE-2024-57980 medium 5.5 FIX rhel rocky sles 10mo ago Moderate: kernel security update
CVE-2025-8225 low 3.3 3.3 FIX debian debian sles gnu 11mo ago A vulnerability was found in GNU Binutils 2.44 and classified as problematic. This issue affects the function process_debug_info of the file binutils/dwarf.c of the component DWARF Section Handler. T…
CVE-2025-8224 medium 5.5 5.5 FIX debian debian sles gnu 11mo ago A vulnerability has been found in GNU Binutils 2.44 and classified as problematic. This vulnerability affects the function bfd_elf_get_str_section of the file bfd/elf.c of the component BFD Library. …
CVE-2025-38466 medium 5.5 5.5 FIX slesdebian debian linux-kernel 11mo ago In the Linux kernel, the following vulnerability has been resolved: perf: Revert to requiring CAP_SYS_ADMIN for uprobes Jann reports that uprobes can be used destructively when used in the middle o…
CVE-2025-38465 medium 5.5 5.5 FIX slesdebian debian linux-kernel 11mo ago In the Linux kernel, the following vulnerability has been resolved: netlink: Fix wraparounds of sk->sk_rmem_alloc. Netlink has this pattern in some places if (atomic_read(&sk->sk_rmem_alloc) > s…
CVE-2025-38457 medium 5.5 5.5 FIX slesdebian debian linux-kernel 11mo ago In the Linux kernel, the following vulnerability has been resolved: net/sched: Abort __tc_modify_qdisc if parent class does not exist Lion's patch [1] revealed an ancient bug in the qdisc API. When…
CVE-2025-38451 medium 5.5 5.5 FIX slesdebian debian linux-kernel 11mo ago In the Linux kernel, the following vulnerability has been resolved: md/md-bitmap: fix GPF in bitmap_get_stats() The commit message of commit 6ec1f0239485 ("md/md-bitmap: fix stats collection for ex…
CVE-2025-38430 medium 5.5 5.5 FIX slesdebian debian linux-kernel 11mo ago In the Linux kernel, the following vulnerability has been resolved: nfsd: nfsd4_spo_must_allow() must check this is a v4 compound request If the request being processed is not a v4 compound request…
CVE-2025-38364 medium 5.5 5.5 FIX slesdebian debian linux-kernel 11mo ago In the Linux kernel, the following vulnerability has been resolved: maple_tree: fix MA_STATE_PREALLOC flag in mas_preallocate() Temporarily clear the preallocation flag when explicitly requesting a…
CVE-2025-53015 unknown FIX debian debian sles 11mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0, infinite lines occur when writing during a specific XMP file conversion co…
CVE-2025-54121 unknown FIX slesdebian debian 11mo ago Starlette is a lightweight ASGI (Asynchronous Server Gateway Interface) framework/toolkit, designed for building async web services in Python. In versions 0.47.1 and below, when parsing a multi-part …
CVE-2025-7962 unknown debian debian sles 11mo ago Jakarta Mail vulnerable to SMTP Injection
CVE-2025-50151 unknown debian debian 11mo ago Apache Jena doesn't validate file access paths in configuration files uploaded by users with administrator access
CVE-2025-49656 unknown debian debian 11mo ago Apache Jena allows users with administrator access to create databases files outside the files area of the Fuseki server
CVE-2024-52615 medium 5.5 debian debian rhel sles 11mo ago Moderate: avahi security update
CVE-2025-49087 low 3.7 3.7 FIX debian debian trustedfirmware 11mo ago In Mbed TLS 3.6.1 through 3.6.3 before 3.6.4, a timing discrepancy in block cipher padding removal allows an attacker to recover the plaintext when PKCS#7 padding mode is used.
CVE-2024-50379 medium 5.5 FIX rhel rocky sles 11mo ago Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (…
CVE-2025-4373 medium 4.8 4.8 FIX rhel rockydebian debian 11mo ago RHSA-2025:11327: glib2 security update (Moderate)
CVE-2019-17543 medium 5.5 FIX rocky slesdebian debian 11mo ago RHSA-2025:11035: lz4 security update (Moderate)
CVE-2025-53643 unknown FIX slesdebian debian 11mo ago AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.12.14, the Python parser is vulnerable to a request smuggling vulnerability due to not parsing trail…
CVE-2025-53689 unknown FIX debian debian 11mo ago Apache Jackrabbit vulnerable to blind XXE attack due to insecure document build
CVE-2025-21991 medium 5.5 FIX rhel rocky sles 11mo ago Moderate: kernel security update
CVE-2025-48924 unknown FIX debian debian sles 11mo ago Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.…
CVE-2025-38347 medium 5.5 5.5 FIX slesdebian debian linux-kernel 11mo ago In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to do sanity check on ino and xnid syzbot reported a f2fs bug as below: INFO: task syz-executor140:5308 blocked for mo…
CVE-2025-38312 medium 5.5 5.5 FIX slesdebian debian linux-kernel 11mo ago In the Linux kernel, the following vulnerability has been resolved: fbdev: core: fbcvt: avoid division by 0 in fb_cvt_hperiod() In fb_find_mode_cvt(), iff mode->refresh somehow happens to be 0x8000…
CVE-2025-38285 medium 5.5 5.5 FIX slesdebian debian linux-kernel 11mo ago In the Linux kernel, the following vulnerability has been resolved: bpf: Fix WARN() in get_bpf_raw_tp_regs syzkaller reported an issue: WARNING: CPU: 3 PID: 5971 at kernel/trace/bpf_trace.c:1861 g…
CVE-2025-7207 medium 5.5 5.5 FIX debian debian mruby 11mo ago A vulnerability, which was classified as problematic, was found in mruby up to 3.4.0-rc2. Affected is the function scope_new of the file mrbgems/mruby-compiler/core/codegen.c of the component nregs H…
CVE-2025-4673 medium 5.5 FIX rhel rockyarch arch 11mo ago RHSA-2025:10672: go-toolset:rhel8 security update (Moderate)
CVE-2025-24294 medium 5.5 FIX rocky rhel sles 11mo ago RHSA-2025:23062: ruby:3.3 security update (Moderate)
CVE-2025-22874 medium 5.5 FIX rhelarch archdebian debian 11mo ago Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rath…
CVE-2025-5024 medium 5.5 FIX rheldebian debian sles 11mo ago A flaw was found in gnome-remote-desktop. Once gnome-remote-desktop listens for RDP connections, an unauthenticated attacker can exhaust system resources and repeatedly crash the process. There may b…
CVE-2025-48060 medium 5.5 FIX rhel rockydebian debian 11mo ago jq is a command-line JSON processor. In versions up to and including 1.7.1, a heap-buffer-overflow is present in function `jv_string_vfmt` in the jq_fuzz_execute harness from oss-fuzz. This crash hap…
CVE-2024-23337 medium 5.5 FIX rhel rocky sles 11mo ago jq is a command-line JSON processor. In versions up to and including 1.7.1, an integer overflow arises when assigning value using an index of 2147483647, the signed integer limit. This causes a denia…
CVE-2024-54661 medium 5.5 FIX rhel rocky sles 11mo ago readline.sh in socat before1.8.0.2 relies on the /tmp/$USER/stderr2 file.
CVE-2025-7069 medium 5.5 5.5 debian debian sles hdfgroup 11mo ago A vulnerability, which was classified as problematic, was found in HDF5 1.14.6. Affected is the function H5FS__sect_link_size of the file src/H5FSsection.c. The manipulation leads to heap-based buffe…
CVE-2025-7068 medium 5.5 5.5 debian debian sles hdfgroup 11mo ago A vulnerability, which was classified as problematic, has been found in HDF5 1.14.6. This issue affects the function H5FL__malloc of the file src/H5FL.c. The manipulation leads to memory leak. Attack…
CVE-2025-7067 medium 5.5 5.5 debian debian sles hdfgroup 11mo ago A vulnerability classified as problematic was found in HDF5 1.14.6. This vulnerability affects the function H5FS__sinfo_serialize_node_cb of the file src/H5FScache.c. The manipulation leads to heap-b…
CVE-2025-49601 medium 6.5 6.5 FIX debian debian trustedfirmware 11mo ago In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_import_public_key does not check that the input buffer is at least 4 bytes before reading a 32-bit field, allowing a possible out-of-bounds read on truncate…
CVE-2025-49600 medium 4.9 4.9 FIX debian debian trustedfirmware 11mo ago In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_verify may accept invalid signatures if hash computation fails and internal errors go unchecked, enabling LMS (Leighton-Micali Signature) forgery in a fault…
CVE-2025-38231 medium 5.5 5.5 FIX slesdebian debian linux-kernel 11mo ago In the Linux kernel, the following vulnerability has been resolved: nfsd: Initialize ssc before laundromat_work to prevent NULL dereference In nfs4_state_start_net(), laundromat_work may access nfs…
CVE-2025-38222 medium 5.5 5.5 FIX slesdebian debian linux-kernel 11mo ago In the Linux kernel, the following vulnerability has been resolved: ext4: inline: fix len overflow in ext4_prepare_inline_data When running the following code on an ext4 filesystem with inline_data…
CVE-2025-38215 medium 5.5 5.5 FIX slesdebian debian linux-kernel 11mo ago In the Linux kernel, the following vulnerability has been resolved: fbdev: Fix do_register_framebuffer to prevent null-ptr-deref in fb_videomode_to_var If fb_add_videomode() in do_register_framebuf…
CVE-2025-38214 medium 5.5 5.5 FIX slesdebian debian linux-kernel 11mo ago In the Linux kernel, the following vulnerability has been resolved: fbdev: Fix fb_set_var to prevent null-ptr-deref in fb_videomode_to_var If fb_add_videomode() in fb_set_var() fails to allocate me…
CVE-2025-38192 medium 5.5 5.5 FIX slesdebian debian linux-kernel 11mo ago In the Linux kernel, the following vulnerability has been resolved: net: clear the dst when changing skb protocol A not-so-careful NAT46 BPF program can crash the kernel if it indiscriminately flip…
CVE-2025-38167 medium 5.5 5.5 FIX slesdebian debian linux-kernel 11mo ago In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: handle hdr_first_de() return value The hdr_first_de() function returns a pointer to a struct NTFS_DE. This pointer may …
CVE-2025-38105 medium 5.5 5.5 FIX slesdebian debian linux-kernel 11mo ago In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Kill timer properly at removal The USB-audio MIDI code initializes the timer, but in a rare case, the driver mig…
CVE-2025-38100 medium 5.5 5.5 FIX slesdebian debian linux-kernel 11mo ago In the Linux kernel, the following vulnerability has been resolved: x86/iopl: Cure TIF_IO_BITMAP inconsistencies io_bitmap_exit() is invoked from exit_thread() when a task exists or when a fork fai…
CVE-2025-6554 unknown 1.5 KEVFIX debian debian 11mo ago Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
CVE-2025-53103 unknown FIX debian debian sles 11mo ago junit-platform-reporting can leak Git credentials through its OpenTestReportGeneratingListener