Search

Found 5,040 results in 830ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2025-4087 high 8.0 FIX rhel rockydebian debian 1y ago A vulnerability was identified in Thunderbird where XPath parsing could trigger undefined behavior due to missing null checks during attribute access. This could lead to out-of-bounds read access and…
CVE-2025-4083 high 8.0 FIX rhel rockydebian debian 1y ago A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level document's process instead of the intended f…
CVE-2025-2817 high 8.0 FIX rhel rockydebian debian 1y ago Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking behavior. By injecting code into the user-privileged…
CVE-2023-53064 high 8.0 FIX rhel slesdebian debian 1y ago In the Linux kernel, the following vulnerability has been resolved: iavf: fix hang on reboot with ice When a system with E810 with existing VFs gets rebooted the following hang may be observed. P…
CVE-2025-21927 high 8.0 FIX rhel sles rocky 1y ago Important: kernel security update
CVE-2024-42322 high 8.0 FIX rhel rocky sles 1y ago In the Linux kernel, the following vulnerability has been resolved: ipvs: properly dereference pe in ip_vs_add_service Use pe directly to resolve sparse warning: net/netfilter/ipvs/ip_vs_ctl.c:1…
CVE-2024-42292 high 7.1 7.1 FIX rhel rocky sles 1y ago In the Linux kernel, the following vulnerability has been resolved: kobject_uevent: Fix OOB access within zap_modalias_env() zap_modalias_env() wrongly calculates size of memory block to move, so w…
CVE-2025-3523 high 8.0 FIX rhel sles rocky 1y ago RHSA-2025:4649: thunderbird security update (Important)
CVE-2025-3522 high 8.0 FIX rhel sles rocky 1y ago RHSA-2025:4649: thunderbird security update (Important)
CVE-2025-2830 high 8.0 FIX rhel sles rocky 1y ago RHSA-2025:4649: thunderbird security update (Important)
CVE-2024-55549 high 8.0 FIX rhel rocky sles 1y ago RHSA-2025:3615: libxslt security update (Important)
CVE-2025-22866 high 8.0 FIX rheldebian debian sles google 1y ago Important: delve and golang security update
CVE-2025-30427 high 8.0 FIX rhel rocky sles 1y ago A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS…
CVE-2025-24216 high 8.0 FIX rhel rocky sles 1y ago The issue was addressed with improved memory handling. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processi…
CVE-2025-24209 high 8.0 FIX rhel rocky sles 1y ago A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, watchOS 11.4. Processi…
CVE-2025-24208 high 8.0 FIX rhel rocky sles 1y ago A permissions issue was addressed with additional restrictions. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4. Loading a malicious iframe may lead to a cross-site scripting attack.
CVE-2025-24189 high 8.0 FIX rhel slesdebian debian 1y ago The issue was addressed with improved checks. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. Processing maliciously crafted w…
CVE-2024-54551 high 8.0 FIX rhel rocky sles 1y ago The issue was addressed with improved memory handling. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing web content m…
CVE-2024-54467 high 8.0 FIX rhel rocky sles 1y ago A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. A malicious website …
CVE-2024-44192 high 8.0 FIX rhel rocky sles 1y ago The issue was addressed with improved checks. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. Processing maliciously crafted web content may…
CVE-2025-3030 high 8.0 FIX rhel rockydebian debian 1y ago Memory safety bugs present in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort so…
CVE-2025-3029 high 8.0 FIX rhel rockydebian debian 1y ago A crafted URL containing specific Unicode characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability was fixed in Firefox 137, Firefox ESR …
CVE-2025-3028 high 8.0 FIX rhel rockydebian debian 1y ago JavaScript code running while transforming a document with the XSLTProcessor could lead to a use-after-free. This vulnerability was fixed in Firefox 137, Firefox ESR 115.22, Firefox ESR 128.9, Thunde…
CVE-2025-27363 high 9.5 KEVFIX rhel rockyarch arch 1y ago FreeType contains an out-of-bounds write vulnerability when attempting to parse font subglyph structures related to TrueType GX and variable font files that may allow for arbitrary code execution.
CVE-2025-1080 high 8.0 FIX rhel rocky sles 1y ago LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In th…
CVE-2023-53012 high 8.0 FIX rhel slesdebian debian 1y ago In the Linux kernel, the following vulnerability has been resolved: thermal: core: call put_device() only after device_register() fails put_device() shouldn't be called before a prior call to devic…
CVE-2025-30204 high 8.0 FIX rheldebian debian sles 1y ago RHSA-2025:7967: osbuild-composer security update (Important)
CVE-2025-29786 high 8.0 rheldebian debian sles 1y ago Expr is an expression language and expression evaluation for Go. Prior to version 1.17.0, if the Expr expression parser is given an unbounded input string, it will attempt to compile the entire strin…
CVE-2025-22869 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:3210: container-tools:rhel8 security update (Important)
CVE-2025-22868 high 8.0 FIX rheldebian debian sles 1y ago An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.
CVE-2025-21785 high 8.0 FIX rhel rocky sles 1y ago In the Linux kernel, the following vulnerability has been resolved: arm64: cacheinfo: Avoid out-of-bounds write to cacheinfo array The loop that detects/populates cache information already has a bo…
CVE-2025-27516 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:3388: python-jinja2 security update (Important)
CVE-2025-24855 high 8.0 FIX rhel rocky sles 1y ago RHSA-2025:3615: libxslt security update (Important)
CVE-2024-36293 high 8.0 FIX rocky slesdebian debian 1y ago RHEA-2025:3114: microcode_ctl bug fix and enhancement update (Important)
CVE-2024-31068 high 8.0 FIX rocky slesdebian debian 1y ago RHEA-2025:3114: microcode_ctl bug fix and enhancement update (Important)
CVE-2024-29214 high 8.0 FIX rocky rheldebian debian 1y ago RHEA-2025:3114: microcode_ctl bug fix and enhancement update (Important)
CVE-2024-28127 high 8.0 FIX rocky rheldebian debian 1y ago RHEA-2025:3114: microcode_ctl bug fix and enhancement update (Important)
CVE-2024-24582 high 8.0 FIX rocky rheldebian debian 1y ago RHEA-2025:3114: microcode_ctl bug fix and enhancement update (Important)
CVE-2023-43758 high 8.0 FIX rocky rheldebian debian 1y ago RHEA-2025:3114: microcode_ctl bug fix and enhancement update (Important)
CVE-2023-34440 high 8.0 FIX rocky rheldebian debian 1y ago RHEA-2025:3114: microcode_ctl bug fix and enhancement update (Important)
CVE-2025-24201 high 9.5 KEVFIX rhel rockydebian debian 1y ago Apple iOS, iPadOS, macOS, and other Apple products contain an out-of-bounds write vulnerability in WebKit that may allow maliciously crafted web content to break out of Web Content sandbox. This vuln…
CVE-2025-0624 high 8.0 FIX rheldebian debian sles 1y ago Important: grub2 security update
CVE-2025-24928 high 8.0 FIX rhel rocky sles 1y ago libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted …
CVE-2024-56171 high 8.0 FIX rhel rocky sles 1y ago libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be va…
CVE-2025-24070 high 8.0 rhel rocky 1y ago RHSA-2025:2670: .NET 8.0 security, bug fix, and enhancement update (Important)
CVE-2024-53197 high 9.5 KEVFIX rhel rocky sles 1y ago Important: kernel security update
CVE-2024-53113 high 8.0 FIX rhel slesdebian debian 1y ago Important: kernel security update
CVE-2024-50264 high 8.0 FIX rhel rocky sles 1y ago Important: kernel security update
CVE-2023-52922 high 8.0 FIX rhel rocky sles 1y ago Important: kernel security update
CVE-2023-52605 high 8.0 FIX rhel rocky sles 1y ago Important: kernel security update
CVE-2025-26601 high 8.0 FIX rhel rocky sles 1y ago Important: tigervnc security update
CVE-2025-26600 high 8.0 FIX rhel rocky sles 1y ago Important: tigervnc security update
CVE-2025-26599 high 8.0 FIX rhel rocky sles 1y ago Important: tigervnc security update
CVE-2025-26598 high 8.0 FIX rhel rocky sles 1y ago Important: tigervnc security update
CVE-2025-26597 high 7.8 7.8 FIX rhel rocky sles tigervncx.org 1y ago Important: tigervnc security update
CVE-2025-26596 high 8.0 FIX rhel rocky sles 1y ago Important: tigervnc security update
CVE-2025-26595 high 8.0 FIX rhel rocky sles 1y ago Important: tigervnc security update
CVE-2025-26594 high 8.0 FIX rhel rocky sles 1y ago Important: tigervnc security update
CVE-2024-57807 high 8.0 FIX rocky slesdebian debian 1y ago In the Linux kernel, the following vulnerability has been resolved: scsi: megaraid_sas: Fix for a potential deadlock This fixes a 'possible circular locking dependency detected' warning CPU0 …
CVE-2025-1938 high 8.0 FIX rhel rockydebian debian 1y ago Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort so…
CVE-2025-1937 high 8.0 FIX rhel rockydebian debian 1y ago Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 115.20, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of memory corruption and we presume that w…
CVE-2025-1936 high 8.0 FIX rhel rockydebian debian 1y ago jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when retrieving the content from the archive, but the fake extension after the null was u…
CVE-2025-1935 high 8.0 FIX rhel rockydebian debian 1y ago A web page could trick a user into setting that site as the default handler for a custom URL protocol. This vulnerability was fixed in Firefox 136, Firefox ESR 128.8, Thunderbird 136, and Thunderbird…
CVE-2025-1934 high 8.0 FIX rhel rockydebian debian 1y ago It was possible to interrupt the processing of a RegExp bailout and run additional JavaScript, potentially triggering garbage collection when the engine was not expecting it. This vulnerability was f…
CVE-2025-1933 high 8.0 FIX rhel rockydebian debian 1y ago On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over memory. This can potentially cause them to be treated as a different type. This vulnerability was fix…
CVE-2025-1932 high 8.0 FIX rhel rockydebian debian 1y ago An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Only affected version 122 and later. This vulnerability was fixed in Firefox 136, …
CVE-2025-1931 high 8.0 FIX rhel rockydebian debian 1y ago It was possible to cause a use-after-free in the content process side of a WebTransport connection, leading to a potentially exploitable crash. This vulnerability was fixed in Firefox 136, Firefox ES…
CVE-2025-1930 high 8.0 FIX rhel rockydebian debian 1y ago On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a use-after-free in the Browser process. This could have led to a sandbox escape. This vulnerability w…
CVE-2025-24162 high 8.0 FIX rhel rocky sles 1y ago This issue was addressed through improved state management. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. Processing malicio…
CVE-2025-24150 high 8.0 FIX rocky slesdebian debian 1y ago A privacy issue was addressed with improved handling of files. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3. Copying a URL from Web Inspector may lead to command i…
CVE-2025-24143 high 8.0 FIX rocky slesdebian debian 1y ago The issue was addressed with improved access restrictions to the file system. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, visionOS 2.3. A maliciously crafted web…
CVE-2024-54543 high 8.0 FIX rhel rocky sles 1y ago The issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.6, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processi…
CVE-2024-57979 high 7.8 7.8 FIX rocky slesdebian debian 1y ago In the Linux kernel, the following vulnerability has been resolved: pps: Fix a use-after-free On a board running ntpd and gpsd, I'm seeing a consistent use-after-free in sys_exit() from gpsd when r…
CVE-2025-1244 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:1917: emacs security update (Important)
CVE-2025-1094 high 9.0 EXPFIX rhel rocky sles 1y ago RHSA-2025:3082: postgresql:12 security update (Important)
CVE-2025-21559 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:1673: mysql:8.0 security update (Important)
CVE-2025-21555 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:1673: mysql:8.0 security update (Important)
CVE-2025-21546 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:1673: mysql:8.0 security update (Important)
CVE-2025-21543 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:1673: mysql:8.0 security update (Important)
CVE-2025-21540 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:1673: mysql:8.0 security update (Important)
CVE-2025-21536 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:1673: mysql:8.0 security update (Important)
CVE-2025-21534 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:1673: mysql:8.0 security update (Important)
CVE-2025-21531 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:1673: mysql:8.0 security update (Important)
CVE-2025-21529 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:1673: mysql:8.0 security update (Important)
CVE-2025-21525 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:1673: mysql:8.0 security update (Important)
CVE-2025-21523 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:1673: mysql:8.0 security update (Important)
CVE-2025-21522 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:1673: mysql:8.0 security update (Important)
CVE-2025-21521 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:1673: mysql:8.0 security update (Important)
CVE-2025-21520 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:1673: mysql:8.0 security update (Important)
CVE-2025-21519 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:1673: mysql:8.0 security update (Important)
CVE-2025-21518 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:1673: mysql:8.0 security update (Important)
CVE-2025-21505 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:1673: mysql:8.0 security update (Important)
CVE-2025-21504 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:1673: mysql:8.0 security update (Important)
CVE-2025-21503 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:1673: mysql:8.0 security update (Important)
CVE-2025-21501 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:1673: mysql:8.0 security update (Important)
CVE-2025-21500 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:1673: mysql:8.0 security update (Important)
CVE-2025-21497 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:1673: mysql:8.0 security update (Important)
CVE-2025-21494 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:1673: mysql:8.0 security update (Important)
CVE-2025-21491 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:1673: mysql:8.0 security update (Important)
CVE-2024-7264 high 8.0 FIX rhel rockydebian debian 1y ago libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the parser might end up using -1 for the length…