Conflicts

1118 open. Two or more sources say different things after the tracker's map. Where only the words differ and no map says what they mean together, it is counted as wording and not listed here.

every property Cvss 1019 Severity 99 · open new seen muted all

ThingPropertyWhat each source saysSince
yaml-cpp: yaml-cpp: Sensitive information disclosure via scanner component
CVE-2026-75432
Cvss
NVD 5.1
Red Hat 6.5
2026-10-03
kernel: net: preserve skb_end_offset() in skb_unclone_keeptruesize()
CVE-2022-49142
Cvss
NVD 7.5
Red Hat 5.5
2026-10-03
kernel: iomap: iomap: fix memory corruption when recording errors during writeback
CVE-2022-50406
Cvss
NVD 7.8
Red Hat 6.5
2026-10-03
kernel: btrfs: don't check PageError in __extent_writepage
CVE-2023-53429
Cvss
NVD 7.8
Red Hat 5.5
2026-10-03
kernel: start_kernel: Add __no_stack_protector function attribute
CVE-2023-53491
Cvss
NVD 7.5
Red Hat 4.1
2026-10-03
kernel: wifi: rtw88: delete timer and free skb queue when unloading
CVE-2023-53574
Cvss
NVD 5.5
Red Hat 4.4
2026-10-03
kernel: scsi: hisi_sas: Grab sas_dev lock when traversing the members of sas_dev.list
CVE-2023-53627
Cvss
NVD 7.8
Red Hat 6.4
2026-10-03
kernel: Linux kernel Bluetooth: Denial of Service due to use-after-free in connection handling
CVE-2023-53762
Cvss
NVD 8.8
Red Hat 7
2026-10-03
kernel: blk-mq: fix tags leak when shrink nr_hw_queues
CVE-2023-54227
Cvss
NVD 7.5
Red Hat 3.3
2026-10-03
kernel: net/smc: check smcd_v2_ext_offset when receiving proposal msg
CVE-2024-47408
Cvss
NVD 9.8
Red Hat 5.5
2026-10-03
kernel: net/smc: check v2_ext_offset/eid_cnt/ism_gid_cnt when receiving proposal msg
CVE-2024-49568
Cvss
NVD 9.8
Red Hat 5.5
2026-10-03
kernel: ipv6: mcast: extend RCU protection in igmp6_send()
CVE-2025-21759
Cvss
NVD 7.8
Red Hat 6.6
2026-10-03
kernel: Linux kernel use-after-free in eventpoll
CVE-2025-38349
Cvss
NVD 7.8
Red Hat 7
2026-10-03
kernel: landlock: Fix handling of disconnected directories
CVE-2025-68736
Cvss
NVD 8.8
Red Hat 6.1
2026-10-03
kernel: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN
CVE-2026-46113
Cvss
NVD 8.8
Red Hat 5.8
2026-10-03
kernel: eventpoll: fix ep_remove struct eventpoll / struct file UAF
CVE-2026-46242
Cvss
NVD 7.8
Red Hat 7
2026-10-03
kernel: netfilter: nf_tables: join hook list via splice_list_rcu() in commit phase
CVE-2026-52988
Cvss
NVD 7.1
Red Hat 5.5
2026-10-03
kernel: af_unix: Drop all SCM attributes for SOCKMAP
CVE-2026-53005
Cvss
NVD 7.8
Red Hat 7
2026-10-03
kernel: KVM: x86: Fix shadow paging use-after-free due to unexpected role
CVE-2026-53359
Cvss
NVD 8.8
Red Hat 7.8
2026-10-03
kernel: Linux kernel (libceph): Denial of Service due to malformed monitor maps
CVE-2026-68155
Cvss
NVD 7.5
Red Hat 7.1
2026-10-03
kernel: sctp: close UDP tunnel sockets during netns teardown
CVE-2026-68161
Cvss
NVD 9.8
Red Hat 7
2026-10-03
kernel: drm/amd/display: set new_stream to NULL after release
CVE-2026-68236
Cvss
NVD 7.8
Red Hat 7
2026-10-03
kernel: Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds
CVE-2026-68391
Cvss
NVD 7.8
Red Hat 7
2026-10-03
kernel: macvlan: inherit needed_headroom and needed_tailroom from lowerdev
CVE-2026-74743
Cvss
NVD 9.8
Red Hat 7
2026-10-03
kernel: KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page
CVE-2026-80726
Cvss
NVD 9.3
Red Hat 8.8
2026-10-03
org.apache.directory.api/api-asn1-ber: Apache Directory LDAP API: Denial of Service via excessive memory allocation
CVE-2026-102731
Severity
GitHub advisories unknown
Red Hat high
2026-10-03
org.apache.directory.api/api-ldap-codec-core: Apache Directory LDAP API: Denial of Service via deeply nested search filter
CVE-2026-103552
Cvss
GitHub advisories 7.3
NVD 7.3
Red Hat 7.5
2026-10-03
org.apache.directory.api/api-ldap-client-api: Apache Directory LDAP API: Remote code execution via untrusted Java object deserialization
CVE-2026-103877
Severity
GitHub advisories unknown
Red Hat high
2026-10-03
org.apache.directory.api/api-ldap-model: Apache Directory LDAP API: Denial of Service via crafted telephone numbers
CVE-2026-103885
Severity
GitHub advisories unknown
Red Hat high
2026-10-03
wasmtime: wasmtime: Memory corruption via preemption checks during bulk operations
CVE-2026-104855
Severity
GitHub advisories low
Red Hat medium
2026-10-03
freetype: Integer overflow in FreeType tt_face_colr_blend_layer() leads to heap buffer overflow during COLR font rendering
CVE-2026-49919
Cvss
NVD 7.8
Red Hat 5.8
2026-10-03
kernel: vsock/virtio: bind uarg before filling zerocopy skb
CVE-2026-63970
Cvss
NVD 7.8
Red Hat 7
2026-10-03
kernel: sctp: fix race between sctp_wait_for_connect and peeloff
CVE-2026-63971
Cvss
NVD 7.8
Red Hat 7
2026-10-03
kernel: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp
CVE-2026-63975
Cvss
NVD 8.8
Red Hat 7
2026-10-03
kernel: vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu()
CVE-2026-63993
Cvss
NVD 9.8
Red Hat 7
2026-10-03
kernel: ethtool: cmis: require exact CDB reply length
CVE-2026-63996
Cvss
NVD 7.8
Red Hat 7
2026-10-03
kernel: ALSA: pcm: oss: Fix setup list UAF on proc write error
CVE-2026-64001
Cvss
NVD 7.8
Red Hat 7
2026-10-03
kernel: accel/rocket: fix UAF via dangling GEM handle in create_bo
CVE-2026-64008
Cvss
NVD 7.8
Red Hat 7
2026-10-03
MLflow Server-Side Request Forgery Vulnerability
CVE-2026-64849
Cvss
NVD 9.3
Red Hat 8.5
2026-10-03
thrift: thrift: Denial of Service via improper handling of compressed data
CVE-2026-66054
Severity
GitHub advisories medium
Red Hat high
2026-10-03
FreeRDP: FreeRDP: Server Identity Verification Bypass via TLS Certificate Validation Weaknesses
CVE-2026-66402
Cvss
NVD 9.8
Red Hat 5.3
2026-10-03
FreeRDP: FreeRDP: HTTP Proxy Request Injection via Redirection
CVE-2026-67289
Cvss
NVD 9.8
Red Hat 5
2026-10-03
thrift: thrift: Information disclosure via improper certificate validation in Perl bindings
CVE-2026-85086
Severity
GitHub advisories medium
Red Hat high
2026-10-03
thrift: thrift: Man-in-the-middle attacks via improper certificate validation
CVE-2026-85088
Severity
GitHub advisories medium
Red Hat high
2026-10-03
kernel: cgroup: Avoid iteration of dying tasks with zero refcount
CVE-2026-98163
Cvss
NVD 7
Red Hat 5.5
2026-10-03
The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the URI scheme. A malicious agent can supply a javascript: URI as the url argument of a Button component's functionCall action. When the user clicks the rendered button, arbitrary JavaScript executes in the victim application's browser origin, constituting a stored/reflected XSS with Critical severity. No non-default configuration is required; the Basic Catalog is enabled by default.
CVE-2026-10032
Cvss
GitHub advisories 9.3
NVD 6.1
2026-10-03
pypdf: pypdf: Denial of Service via crafted Roman page labels
CVE-2026-102993
Cvss
NVD 7.5
Red Hat 6.5
2026-10-02
authlib: authlib: Information disclosure via unvalidated discovery metadata
CVE-2026-104056
Severity
GitHub advisories unknown
Red Hat medium
2026-10-02
Intel Performance Counter Monitor: Intel Performance Counter Monitor: Escalation of Privilege via Untrusted Search Path
CVE-2026-32791
Cvss
NVD 7
Red Hat 6.7
2026-10-02
httpd: httpd: Information disclosure via session cookie leakage during internal redirects
CVE-2026-47360
Cvss
GitHub advisories 7.5
NVD 7.5
Red Hat 3.7
2026-10-02
httpd: httpd: Information disclosure via session cookie leakage during internal redirects
CVE-2026-47360
Severity
GitHub advisories high
Red Hat low
2026-10-02
httpd: httpd: Denial of service via forged Authorization headers in mod_auth_digest
CVE-2026-48005
Cvss
GitHub advisories 7.5
NVD 7.5
Red Hat 3.7
2026-10-02
httpd: httpd: Denial of service via forged Authorization headers in mod_auth_digest
CVE-2026-48005
Severity
GitHub advisories high
Red Hat low
2026-10-02
coreutils: GNU coreutils unexpand: Denial of Service via crafted tab stop values
CVE-2026-56392
Cvss
NVD 6.1
Red Hat 4.4
2026-10-02
httpd: httpd: Denial of Service via crafted HTTP response bodies in mod_proxy_html
CVE-2026-56449
Cvss
GitHub advisories 7.5
NVD 7.5
Red Hat 3.7
2026-10-02
httpd: httpd: Denial of Service via crafted HTTP response bodies in mod_proxy_html
CVE-2026-56449
Severity
GitHub advisories high
Red Hat low
2026-10-02
httpd: httpd: unauthorized connection to arbitrary hosts via crafted FTP PASV response
CVE-2026-63045
Cvss
GitHub advisories 7.5
NVD 7.5
Red Hat 5.3
2026-10-02
httpd: httpd: unauthorized connection to arbitrary hosts via crafted FTP PASV response
CVE-2026-63045
Severity
GitHub advisories high
Red Hat medium
2026-10-02
httpd: httpd: Arbitrary code execution via oversized Host header in mod_vhost_alias
CVE-2026-63292
Cvss
GitHub advisories 7.5
NVD 7.5
Red Hat 8.1
2026-10-02
httpd: httpd: Authentication state corruption via concurrent Digest authentication requests
CVE-2026-73637
Cvss
GitHub advisories 7.3
NVD 7.3
Red Hat 5.6
2026-10-02
httpd: httpd: Authentication state corruption via concurrent Digest authentication requests
CVE-2026-73637
Severity
GitHub advisories high
Red Hat medium
2026-10-02
firefox: firefox: Sandbox escape via use-after-free in Graphics component
CVE-2026-100786
Severity
GitHub advisories critical
Red Hat high
2026-10-02
firefox: firefox: Sandbox escape via use-after-free in DOM component
CVE-2026-100811
Severity
GitHub advisories critical
Red Hat high
2026-10-02
oc-mirror: oc-mirror: Path traversal / arbitrary file write in operator catalog image extraction
CVE-2026-101295
Severity
GitHub advisories high
Red Hat medium
2026-10-02
chromium-browser: chromium-browser: Uninitialized resource in WebGPU
CVE-2026-102300
Cvss
GitHub advisories 4.3
NVD 4.3
Red Hat 6.5
2026-10-02
chromium-browser: chromium-browser: Uninitialized resource in GPU
CVE-2026-102303
Cvss
GitHub advisories 4.3
NVD 4.3
Red Hat 6.5
2026-10-02
chromium-browser: chromium-browser: Use after free in Passwords
CVE-2026-102304
Cvss
GitHub advisories 9.6
NVD 9.6
Red Hat 8.8
2026-10-02
chromium-browser: chromium-browser: Use after free in Passwords
CVE-2026-102304
Severity
GitHub advisories critical
Red Hat high
2026-10-02
chromium-browser: chromium-browser: Use after free in FullScreen
CVE-2026-102309
Cvss
GitHub advisories 9.6
NVD 9.6
Red Hat 8.8
2026-10-02
chromium-browser: chromium-browser: Use after free in FullScreen
CVE-2026-102309
Severity
GitHub advisories critical
Red Hat high
2026-10-02
chromium-browser: chromium-browser: Missing authorization in Payments
CVE-2026-102310
Cvss
GitHub advisories 6.5
NVD 6.5
Red Hat 4.2
2026-10-02
chromium-browser: chromium-browser: Uninitialized resource in GPU
CVE-2026-102311
Cvss
GitHub advisories 3.4
NVD 3.4
Red Hat 7.4
2026-10-02
chromium-browser: chromium-browser: Uninitialized resource in GPU
CVE-2026-102311
Severity
GitHub advisories low
Red Hat high
2026-10-02
chromium-browser: chromium-browser: Out of bounds read in WebGL
CVE-2026-102318
Cvss
GitHub advisories 4.7
NVD 4.7
Red Hat 7.4
2026-10-02
chromium-browser: chromium-browser: Out of bounds read in WebGL
CVE-2026-102318
Severity
GitHub advisories medium
Red Hat high
2026-10-02
chromium-browser: chromium-browser: Use after free in PictureInPicture
CVE-2026-102324
Cvss
GitHub advisories 8.3
NVD 8.3
Red Hat 8.8
2026-10-02
chromium-browser: chromium-browser: Incorrect authorization in WebView
CVE-2026-102327
Cvss
GitHub advisories 7.5
NVD 7.5
Red Hat 8.3
2026-10-02
chromium-browser: chromium-browser: Cross-site scripting in WebUI
CVE-2026-102329
Cvss
GitHub advisories 6.1
NVD 6.1
Red Hat 8.8
2026-10-02
chromium-browser: chromium-browser: Cross-site scripting in WebUI
CVE-2026-102329
Severity
GitHub advisories medium
Red Hat high
2026-10-02
chromium-browser: chromium-browser: Incorrect authorization in SiteIsolation
CVE-2026-102330
Cvss
GitHub advisories 6.5
NVD 6.5
Red Hat 3.1
2026-10-02
chromium-browser: chromium-browser: Incorrect authorization in SiteIsolation
CVE-2026-102330
Severity
GitHub advisories medium
Red Hat low
2026-10-02
poppler: poppler: Data corruption via integer overflow in FoFiTrueType::cvtSfnts
CVE-2026-102620
Severity
GitHub advisories low
Red Hat medium
2026-10-02
expat: expat: Denial of Service via integer overflow in expat_realloc
CVE-2026-102633
Severity
GitHub advisories high
Red Hat medium
2026-10-02
ImageMagick: ImageMagick: Information disclosure via crafted GIF file
CVE-2026-102635
Severity
GitHub advisories medium
Red Hat low
2026-10-02
pageant: pageant: Denial of Service via untrusted response length in shared memory
CVE-2026-102820
Cvss
GitHub advisories 6.2
NVD 6.2
Red Hat 5.5
2026-10-02
pypdf: pypdf: Denial of Service via crafted Roman page labels
CVE-2026-102993
Severity
GitHub advisories high
Red Hat medium
2026-10-02
pypdf: pypdf: Denial of Service via excessive memory consumption in font mapping
CVE-2026-102995
Severity
GitHub advisories high
Red Hat medium
2026-10-02
ghostscript: ghostscript: stack-based buffer overflow in pdfwrite via crafted font data
CVE-2026-103226
Cvss
GitHub advisories 6.3
NVD 6.3
Red Hat 7.8
2026-10-02
ghostscript: ghostscript: stack-based buffer overflow in pdfwrite via crafted font data
CVE-2026-103226
Severity
GitHub advisories low
Red Hat high
2026-10-02
rpm: Heap-based buffer overflow write in hex2binv() via a mistyped RPMTAG_FILESIGNATURES header tag
CVE-2026-103242
Severity
GitHub advisories high
Red Hat medium
2026-10-02
tornado: Tornado: Information disclosure via symlink path traversal in StaticFileHandler
CVE-2026-103263
Severity
GitHub advisories high
Red Hat medium
2026-10-02
uri-js: uri-js: Denial of Service via crafted mailto URI
CVE-2026-103387
Severity
GitHub advisories low
Red Hat medium
2026-10-02
thunderbird: thunderbird: Heap buffer overflow via opening large emails
CVE-2026-103500
Severity
GitHub advisories unknown
Red Hat high
2026-10-02
opensc: opensc: Arbitrary code execution via stack-based buffer overflow in card-setcos
CVE-2026-103531
Cvss
GitHub advisories 5.5
NVD 5.5
Red Hat 6.8
2026-10-02
openssl: openssl: Denial of Service via excessive memory allocation in CRL distribution point processing
CVE-2026-35189
Cvss
GitHub advisories 5.3
NVD 5.3
Red Hat 3.7
2026-10-02
openssl: openssl: Denial of Service via excessive memory allocation in CRL distribution point processing
CVE-2026-35189
Severity
GitHub advisories medium
Red Hat low
2026-10-02
nvidia-driver: nvidia-driver: arbitrary code execution via use-after-free in kernel mode driver
CVE-2026-47579
Cvss
GitHub advisories 7.8
NVD 7.8
Red Hat 7
2026-10-02
nvidia-driver: nvidia-driver: arbitrary code execution via use-after-free in kernel mode driver
CVE-2026-47579
Severity
GitHub advisories high
Red Hat medium
2026-10-02
nvidia-driver: nvidia-driver: Code execution via out-of-bounds write in kernel module
CVE-2026-47582
Severity
GitHub advisories high
Red Hat medium
2026-10-02
nvidia-driver: nvidia-driver: Privilege escalation via unpreserved memory permissions
CVE-2026-47596
Cvss
GitHub advisories 7
NVD 7
Red Hat 7.8
2026-10-02
nvidia-driver: xorg-x11-drv-nvidia: nvidia-driver: Arbitrary code execution via use-after-free in event delivery path
CVE-2026-47598
Severity
GitHub advisories high
Red Hat medium
2026-10-02
openssl: OpenSSL: Private key recovery via timing side-channel in generic elliptic curve operations
CVE-2026-54872
Cvss
GitHub advisories 3.7
NVD 3.7
Red Hat 5.9
2026-10-02
openssl: OpenSSL: Private key recovery via timing side-channel in generic elliptic curve operations
CVE-2026-54872
Severity
GitHub advisories low
Red Hat medium
2026-10-02
openssl: openssl: Denial of Service via excessive QUIC packet buffer retention
CVE-2026-54873
Cvss
GitHub advisories 7.5
NVD 7.5
Red Hat 5.3
2026-10-02
openssl: openssl: Denial of Service via excessive QUIC packet buffer retention
CVE-2026-54873
Severity
GitHub advisories high
Red Hat medium
2026-10-02
openssl: openssl: information disclosure via non-constant-time SM2 scalar multiplication on ARM64 and RISC-V
CVE-2026-54875
Cvss
GitHub advisories 3.7
NVD 3.7
Red Hat 4.7
2026-10-02
openssl: openssl: information disclosure via non-constant-time SM2 scalar multiplication on ARM64 and RISC-V
CVE-2026-54875
Severity
GitHub advisories low
Red Hat medium
2026-10-02
openssl: openssl: Denial of Service via out-of-bounds write during TLS context switch
CVE-2026-72897
Cvss
GitHub advisories 7.5
NVD 7.5
Red Hat 5.9
2026-10-02
openssl: openssl: Denial of Service via out-of-bounds write during TLS context switch
CVE-2026-72897
Severity
GitHub advisories high
Red Hat medium
2026-10-02
openssl: OpenSSL: Denial of Service via unenforced QUIC connection flow control
CVE-2026-75804
Cvss
GitHub advisories 5.3
NVD 5.3
Red Hat 7.5
2026-10-02
openssl: OpenSSL: Denial of Service via unenforced QUIC connection flow control
CVE-2026-75804
Severity
GitHub advisories medium
Red Hat high
2026-10-02
openssl: openssl: Denial of Service via crafted CMP certificate revocation response
CVE-2026-75805
Cvss
GitHub advisories 5.3
NVD 5.3
Red Hat 5.9
2026-10-02
openssl: OpenSSL: Private key recovery via SM2 timing side-channel
CVE-2026-77696
Cvss
GitHub advisories 3.7
NVD 3.7
Red Hat 5.9
2026-10-02
openssl: OpenSSL: Private key recovery via SM2 timing side-channel
CVE-2026-77696
Severity
GitHub advisories low
Red Hat medium
2026-10-02
openssl: compat-openssl: openssl: Information disclosure via DTLS handshake retransmission
CVE-2026-84782
Cvss
GitHub advisories 8.2
NVD 8.2
Red Hat 7.4
2026-10-02
openssl: openssl: Denial of Service via race condition in certificate extension caching
CVE-2026-84783
Cvss
GitHub advisories 7.5
NVD 7.5
Red Hat 5.9
2026-10-02
openssl: openssl: Denial of Service via race condition in certificate extension caching
CVE-2026-84783
Severity
GitHub advisories high
Red Hat medium
2026-10-02
openssl: OpenSSL: Denial of Service via unbounded QUIC connection identifier backlog
CVE-2026-84784
Cvss
GitHub advisories 7.5
NVD 7.5
Red Hat 5.3
2026-10-02
openssl: OpenSSL: Denial of Service via unbounded QUIC connection identifier backlog
CVE-2026-84784
Severity
GitHub advisories high
Red Hat medium
2026-10-02
389-ds-base: 389-ds-base: StartTLS plaintext-buffer retention allows on-path attacker to forge an LDAP client's authentication result
CVE-2026-86345
Severity
GitHub advisories critical
Red Hat medium
2026-10-02
org.apache.wss4j/wss4j-ws-security-dom: Apache WSS4J: Authentication bypass via unsigned SAML sender-vouches assertion
CVE-2026-88920
Cvss
NVD 9.8
Red Hat 7.4
2026-10-02
org.apache.wss4j/wss4j-ws-security-dom: Apache WSS4J: Authentication bypass via unsigned SAML sender-vouches assertion
CVE-2026-88920
Severity
GitHub advisories unknown
Red Hat high
2026-10-02
org.apache.karaf.config/org.apache.karaf.config.core: Apache Karaf: Privilege escalation via path traversal in configuration service
CVE-2026-91012
Cvss
NVD 9.8
Red Hat 8.8
2026-10-02
org.apache.karaf.config/org.apache.karaf.config.core: Apache Karaf: Privilege escalation via path traversal in configuration service
CVE-2026-91012
Severity
GitHub advisories unknown
Red Hat high
2026-10-02
pgpool-II: pgpool-II: Denial of Service via out-of-bounds write
CVE-2026-92869
Severity
GitHub advisories high
Red Hat medium
2026-10-02
httpd: httpd: Denial of Service via integer overflow in mod_dav_fs
CVE-2026-93546
Cvss
GitHub advisories 8.8
NVD 8.8
Red Hat 5.4
2026-10-02
httpd: httpd: Denial of Service via integer overflow in mod_dav_fs
CVE-2026-93546
Severity
GitHub advisories high
Red Hat medium
2026-10-02
chromium-browser: chromium-browser: Improper output encoding in DevTools
CVE-2026-95274
Cvss
GitHub advisories 8.3
NVD 8.3
Red Hat 9.6
2026-10-02
chromium-browser: chromium-browser: UI misrepresentation in SecurityIndicators
CVE-2026-95291
Cvss
GitHub advisories 5.4
NVD 5.4
Red Hat 4.3
2026-10-02
chromium-browser: chromium-browser: Uninitialized resource in GPU
CVE-2026-95293
Cvss
GitHub advisories 4.7
NVD 4.7
Red Hat 7.4
2026-10-02
chromium-browser: chromium-browser: Uninitialized resource in GPU
CVE-2026-95293
Severity
GitHub advisories medium
Red Hat high
2026-10-02
chromium-browser: chromium-browser: Use after free in AdFilter
CVE-2026-95310
Severity
GitHub advisories critical
Red Hat high
2026-10-02
chromium-browser: chromium-browser: Use after free in Aura
CVE-2026-95315
Cvss
GitHub advisories 7.8
NVD 7.8
Red Hat 7.3
2026-10-02
chromium-browser: chromium-browser: Unchecked return value in Performance
CVE-2026-95316
Cvss
GitHub advisories 2.9
NVD 2.9
Red Hat 3.3
2026-10-02
chromium-browser: chromium-browser: Incorrect authorization in MediaCapture
CVE-2026-95317
Cvss
GitHub advisories 3.1
NVD 3.1
Red Hat 4.3
2026-10-02
chromium-browser: chromium-browser: Incorrect authorization in MediaCapture
CVE-2026-95317
Severity
GitHub advisories low
Red Hat medium
2026-10-02
chromium-browser: chromium-browser: Uninitialized resource in GPU
CVE-2026-95324
Cvss
GitHub advisories 3.4
NVD 3.4
Red Hat 7.4
2026-10-02
chromium-browser: chromium-browser: Uninitialized resource in GPU
CVE-2026-95324
Severity
GitHub advisories low
Red Hat high
2026-10-02
chromium-browser: chromium-browser: Out of bounds write in WebGL
CVE-2026-95329
Severity
GitHub advisories critical
Red Hat high
2026-10-02
chromium-browser: chromium-browser: Use of uninitialized variable in Tint
CVE-2026-95332
Cvss
GitHub advisories 4.7
NVD 4.7
Red Hat 6.5
2026-10-02
chromium-browser: chromium-browser: Use after free in Updater
CVE-2026-95347
Cvss
GitHub advisories 9.6
NVD 9.6
Red Hat 8.1
2026-10-02
chromium-browser: chromium-browser: Use after free in Updater
CVE-2026-95347
Severity
GitHub advisories critical
Red Hat high
2026-10-02
chromium-browser: chromium-browser: Use after free in Views
CVE-2026-95351
Cvss
GitHub advisories 8.3
NVD 8.3
Red Hat 8.8
2026-10-02
chromium-browser: chromium-browser: Use after free in Verifier
CVE-2026-95354
Cvss
GitHub advisories 8.3
NVD 8.3
Red Hat 7.5
2026-10-02
chromium-browser: chromium-browser: Incorrect authorization in Navigation
CVE-2026-95355
Cvss
GitHub advisories 8.3
NVD 8.3
Red Hat 8.8
2026-10-02
chromium-browser: chromium-browser: Out of bounds write in GPU
CVE-2026-95357
Severity
GitHub advisories critical
Red Hat high
2026-10-02
chromium-browser: chromium-browser: Uninitialized resource in GPU
CVE-2026-95359
Cvss
GitHub advisories 3.4
NVD 3.4
Red Hat 4.7
2026-10-02
chromium-browser: chromium-browser: Uninitialized resource in GPU
CVE-2026-95359
Severity
GitHub advisories low
Red Hat medium
2026-10-02
chromium-browser: chromium-browser: Improper input validation in Auth
CVE-2026-95382
Cvss
GitHub advisories 6.5
NVD 6.5
Red Hat 5.3
2026-10-02
wireshark: wireshark: Denial of Service via heap-based buffer overflow in sharkd
CVE-2026-95388
Cvss
GitHub advisories 5.5
NVD 5.5
Red Hat 5.3
2026-10-02
wireshark: Heap-based Buffer Overflow in Wireshark
CVE-2026-95389
Cvss
GitHub advisories 8.1
NVD 8.1
Red Hat 7.8
2026-10-02
wireshark: Heap-based Buffer Overflow in Wireshark
CVE-2026-95393
Cvss
GitHub advisories 4.7
NVD 4.7
Red Hat 5.3
2026-10-02
rpm: rpm: integer overflow in iterReadArchiveNext() leads to heap-based buffer overflow when parsing untrusted RPM packages
CVE-2026-95520
Severity
GitHub advisories high
Red Hat medium
2026-10-02
wireshark: Wireshark: Denial of Service via infinite loop in TIFF protocol dissector
CVE-2026-96418
Cvss
GitHub advisories 5.5
NVD 5.5
Red Hat 6.5
2026-10-02
wireshark: Buffer Over-read in Wireshark
CVE-2026-96420
Cvss
GitHub advisories 4.7
NVD 4.7
Red Hat 5.5
2026-10-02
foreman: Excessive Permissions for Viewer Role on Preview
CVE-2026-96659
Severity
GitHub advisories critical
Red Hat high
2026-10-02
serialize-javascript: serialize-javascript: Cross-Site Scripting via unescaped script-closing tags in serialized functions
CVE-2026-97711
Severity
GitHub advisories low
Red Hat medium
2026-10-02
kernel: KVM: x86/mmu: Check write tracking in all address spaces
CVE-2026-98164
Severity
GitHub advisories unknown
Red Hat medium
2026-10-02
chromium-browser: Inappropriate implementation in Fullscreen
CVE-2024-13178
Cvss
NVD 4.3
Red Hat 6.5
2026-10-02
github.com/opentofu/opentofu: OpenTofu: Sensitive information disclosure via static evaluation
CVE-2024-58375
Cvss
NVD 7.5
Red Hat 5.9
2026-10-02
renovate: Renovate 37.158.0 before 37.199.0 Command Injection via helmv3
CVE-2024-58376
Cvss
NVD 6.7
Red Hat 7.2
2026-10-02
chromium-browser: Inappropriate implementation in DevTools
CVE-2024-7017
Cvss
NVD 7.5
Red Hat 8.8
2026-10-02
firefox: thunderbird: WebChannel APIs susceptible to confused deputy attack
CVE-2025-0237
Cvss
NVD 5.4
Red Hat 6.8
2026-10-02
firefox: thunderbird: Use-after-free when breaking lines in text
CVE-2025-0238
Cvss
NVD 5.3
Red Hat 6.5
2026-10-02
firefox: Alt-Svc ALPN validation failure when redirected
CVE-2025-0239
Cvss
NVD 4
Red Hat 5.4
2026-10-02
firefox: Compartment mismatch when parsing JavaScript JSON module
CVE-2025-0240
Cvss
NVD 4
Red Hat 6.5
2026-10-02
firefox: Memory corruption when using JavaScript Text Segmentation
CVE-2025-0241
Cvss
NVD 7.7
Red Hat 6.5
2026-10-02
firefox: thunderbird: Memory safety bugs fixed in Firefox 134, Thunderbird 134, Firefox ESR 115.19, Firefox ESR 128.6, Thunderbird 115.19, and Thunderbird 128.6
CVE-2025-0242
Cvss
NVD 6.5
Red Hat 8.8
2026-10-02
firefox: thunderbird: Memory safety bugs fixed in Firefox 134, Thunderbird 134, Firefox ESR 128.6, and Thunderbird 128.6
CVE-2025-0243
Cvss
NVD 5.1
Red Hat 7.5
2026-10-02
firefox: Address bar spoofing using an invalid protocol scheme on Firefox for Android
CVE-2025-0244
Cvss
NVD 5.3
Red Hat 8.1
2026-10-02
firefox: Lock screen setting bypass in Firefox Focus for Android
CVE-2025-0245
Cvss
NVD 3.3
Red Hat 5.9
2026-10-02
firefox: Address bar spoofing using an invalid protocol scheme on Firefox for Android
CVE-2025-0246
Cvss
NVD 6.5
Red Hat 5.4
2026-10-02
firefox: thunderbird: Memory safety bugs fixed in Firefox 134 and Thunderbird 134
CVE-2025-0247
Cvss
NVD 9.8
Red Hat 8.8
2026-10-02
firefox: thunderbird: Use-after-free during concurrent delazification
CVE-2025-1012
Cvss
NVD 7.5
Red Hat 7.6
2026-10-02
firefox: thunderbird: Potential opening of private browsing tabs in normal browsing windows
CVE-2025-1013
Cvss
NVD 6.5
Red Hat 4.3
2026-10-02
firefox: thunderbird: Certificate length was not properly checked
CVE-2025-1014
Cvss
NVD 8.8
Red Hat 5.3
2026-10-02
firefox: thunderbird: Memory safety bugs fixed in Firefox 135, Thunderbird 135, Firefox ESR 115.20, Firefox ESR 128.7, Thunderbird 115.20, and Thunderbird 128.7
CVE-2025-1016
Cvss
NVD 9.8
Red Hat 8.8
2026-10-02
firefox: thunderbird: Memory safety bugs fixed in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7
CVE-2025-1017
Cvss
NVD 9.8
Red Hat 8.8
2026-10-02
firefox: thunderbird: Fullscreen notification is not displayed when fullscreen is re-requested
CVE-2025-1018
Cvss
NVD 5.3
Red Hat 5.4
2026-10-02
firefox: thunderbird: Fullscreen notification not properly displayed
CVE-2025-1019
Cvss
NVD 4.3
Red Hat 5.4
2026-10-02
firefox: thunderbird: Memory safety bugs fixed in Firefox 135 and Thunderbird 135
CVE-2025-1020
Cvss
NVD 9.8
Red Hat 8.8
2026-10-02
firefox: Information disclosure, mitigation bypass in the Privacy component in Firefox for Android
CVE-2025-10535
Cvss
NVD 7.5
Red Hat 3.4
2026-10-02
binutils: GNU Binutils out-of-bounds read
CVE-2025-11081
Cvss
NVD 3.3
Red Hat 5.3
2026-10-02
chromium-browser: Out of bounds read in Media
CVE-2025-11211
Cvss
NVD 7.5
Red Hat 6.5
2026-10-02
chromium-browser: Off by one error in V8
CVE-2025-11215
Cvss
NVD 4.3
Red Hat 6.5
2026-10-02
chromium-browser: Use after free in V8
CVE-2025-11219
Cvss
NVD 3.1
Red Hat 4.3
2026-10-02
chromium-browser: Heap buffer overflow in Sync
CVE-2025-11458
Cvss
NVD 8.1
Red Hat 8.8
2026-10-02
Grafana: Grafana: Information disclosure of secure settings via contact point modification
CVE-2025-12141
Cvss
NVD 6.5
Red Hat 5
2026-10-02
chromium-browser: Object lifecycle issue in Media
CVE-2025-12430
Cvss
NVD 7.5
Red Hat 8.8
2026-10-02
chromium-browser: Inappropriate implementation in Extensions
CVE-2025-12431
Cvss
NVD 6.5
Red Hat 8.8
2026-10-02
chromium-browser: Inappropriate implementation in V8
CVE-2025-12433
Cvss
NVD 4.3
Red Hat 8.8
2026-10-02
chromium-browser: Policy bypass in Extensions
CVE-2025-12436
Cvss
NVD 5.9
Red Hat 6.5
2026-10-02
chromium-browser: Use after free in PageInfo
CVE-2025-12437
Cvss
NVD 7.5
Red Hat 6.5
2026-10-02
chromium-browser: Inappropriate implementation in App-Bound Encryption
CVE-2025-12439
Cvss
NVD 5.5
Red Hat 6.5
2026-10-02
chromium-browser: Inappropriate implementation in Autofill
CVE-2025-12440
Cvss
NVD 5.3
Red Hat 4.3
2026-10-02
chromium-browser: Out of bounds read in V8
CVE-2025-12441
Cvss
NVD 4.3
Red Hat 6.5
2026-10-02
chromium-browser: Out of bounds read in WebXR
CVE-2025-12443
Cvss
NVD 4.3
Red Hat 6.5
2026-10-02
chromium-browser: Incorrect security UI in Fullscreen UI
CVE-2025-12444
Cvss
NVD 4.2
Red Hat 4.3
2026-10-02
chromium-browser: Policy bypass in Extensions
CVE-2025-12445
Cvss
NVD 6.5
Red Hat 4.3
2026-10-02
chromium-browser: Incorrect security UI in SplitView
CVE-2025-12446
Cvss
NVD 4.2
Red Hat 4.3
2026-10-02
chromium-browser: Inappropriate implementation in DevTools
CVE-2025-13097
Cvss
NVD 5.4
Red Hat 6.5
2026-10-02
firefox: Memory safety bugs fixed in Firefox 135.0.1
CVE-2025-1414
Cvss
NVD 6.5
Red Hat 8.8
2026-10-02
firefox: thunderbird: Use-after-free in the WebRTC: Signaling component
CVE-2025-14321
Cvss
NVD 9.8
Red Hat 7.5
2026-10-02
firefox: thunderbird: Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component
CVE-2025-14322
Cvss
NVD 8
Red Hat 7.5
2026-10-02
firefox: thunderbird: Privilege escalation in the DOM: Notifications component
CVE-2025-14323
Cvss
NVD 8.8
Red Hat 7.5
2026-10-02
firefox: thunderbird: JIT miscompilation in the JavaScript Engine: JIT component
CVE-2025-14324
Cvss
NVD 9.8
Red Hat 7.5
2026-10-02
firefox: thunderbird: JIT miscompilation in the JavaScript Engine: JIT component
CVE-2025-14325
Cvss
NVD 7.3
Red Hat 7.5
2026-10-02
firefox: Use-after-free in the Audio/Video: GMP component
CVE-2025-14326
Cvss
NVD 9.8
Red Hat 6.1
2026-10-02
firefox: Spoofing issue in the Downloads Panel component
CVE-2025-14327
Cvss
NVD 7.5
Red Hat 7.1
2026-10-02
firefox: thunderbird: Privilege escalation in the Netmonitor component
CVE-2025-14328
Cvss
NVD 8.8
Red Hat 6.1
2026-10-02
firefox: thunderbird: Privilege escalation in the Netmonitor component
CVE-2025-14329
Cvss
NVD 8.8
Red Hat 6.1
2026-10-02
firefox: thunderbird: JIT miscompilation in the JavaScript Engine: JIT component
CVE-2025-14330
Cvss
NVD 9.8
Red Hat 6.1
2026-10-02
firefox: thunderbird: Same-origin policy bypass in the Request Handling component
CVE-2025-14331
Cvss
NVD 6.5
Red Hat 6.1
2026-10-02
firefox: Memory safety bugs fixed in Firefox 146 and Thunderbird 146
CVE-2025-14332
Cvss
NVD 7.3
Red Hat 6.1
2026-10-02
firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146
CVE-2025-14333
Cvss
NVD 8.1
Red Hat 6.1
2026-10-02
wabt: WebAssembly wabt: Memory corruption vulnerability in wasm-decompile component
CVE-2025-15411
Cvss
NVD 5.3
Red Hat 7.1
2026-10-02
wabt: wabt: Arbitrary code execution, information disclosure, and denial of service via out-of-bounds read
CVE-2025-15412
Cvss
NVD 5.3
Red Hat 7.1
2026-10-02
libsodium: libsodium: Cryptographic bypass via improper elliptic curve point validation
CVE-2025-15444
Cvss
NVD 9.8
Red Hat 6.8
2026-10-02
assimp: Assimp: Heap-based buffer overflow via crafted model file
CVE-2025-15666
Cvss
NVD 5.3
Red Hat 6.1
2026-10-02
firefox: AudioIPC StreamData could trigger a use-after-free in the Browser process
CVE-2025-1930
Cvss
NVD 8.8
Red Hat 8.3
2026-10-02
firefox: Use-after-free in WebTransportChild
CVE-2025-1931
Cvss
NVD 7.5
Red Hat 7.6
2026-10-02
firefox: Inconsistent comparator in XSLT sorting led to out-of-bounds access
CVE-2025-1932
Cvss
NVD 8.1
Red Hat 8.3
2026-10-02
firefox: Adding %00 and a fake extension to a jar: URL changed the interpretation of the contents
CVE-2025-1936
Cvss
NVD 7.3
Red Hat 5.4
2026-10-02
firefox: thunderbird: Memory safety bugs fixed in Firefox 136, Thunderbird 136, Firefox ESR 115.21, Firefox ESR 128.8, and Thunderbird 128.8
CVE-2025-1937
Cvss
NVD 7.5
Red Hat 8.8
2026-10-02
firefox: thunderbird: Memory safety bugs fixed in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.8
CVE-2025-1938
Cvss
NVD 6.5
Red Hat 8.8
2026-10-02
firefox: Tapjacking in Android Custom Tabs using transition animations
CVE-2025-1939
Cvss
NVD 3.9
Red Hat 7.1
2026-10-02
firefox: Android Intent confirmation prompt tapjacking using Select options
CVE-2025-1940
Cvss
NVD 7.1
Red Hat 5.4
2026-10-02
firefox: Lock screen setting bypass in Firefox Focus for Android
CVE-2025-1941
Cvss
NVD 9.1
Red Hat 5.4
2026-10-02
firefox: Disclosure of uninitialized memory when .toUpperCase() causes string to get longer
CVE-2025-1942
Cvss
NVD 9.8
Red Hat 6.3
2026-10-02
firefox: thunderbird: Privilege escalation in Firefox Updater
CVE-2025-2817
Cvss
NVD 8.8
Red Hat 8.5
2026-10-02
firefox: thunderbird: Use-after-free triggered by XSLTProcessor
CVE-2025-3028
Cvss
NVD 6.5
Red Hat 7.6
2026-10-02
firefox: thunderbird: URL Bar Spoofing via non-BMP Unicode characters
CVE-2025-3029
Cvss
NVD 7.3
Red Hat 5.4
2026-10-02
firefox: thunderbird: Memory safety bugs fixed in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9
CVE-2025-3030
Cvss
NVD 8.1
Red Hat 8.8
2026-10-02
firefox: thunderbird: JIT optimization bug with different stack slot sizes
CVE-2025-3031
Cvss
NVD 6.5
Red Hat 5.5
2026-10-02
thunderbird: firefox: Leaking file descriptors from the fork server
CVE-2025-3032
Cvss
NVD 7.4
Red Hat 6.3
2026-10-02
OpenVPN Access Server: OpenVPN Access Server: HTTP request smuggling via bare line-feed sequences in HTTP headers
CVE-2025-3110
Cvss
NVD 7.5
Red Hat 5.3
2026-10-02
firefox: Race condition in nsHttpTransaction could lead to memory corruption
CVE-2025-3608
Cvss
NVD 6.5
Red Hat 7.5
2026-10-02
firefox: thunderbird: WebGL shader attribute memory corruption in Firefox for macOS
CVE-2025-4082
Cvss
NVD 5.9
Red Hat 7.6
2026-10-02
firefox: thunderbird: Process isolation bypass using "javascript:" URI links in cross-origin frames
CVE-2025-4083
Cvss
NVD 9.1
Red Hat 8.3
2026-10-02
firefox: thunderbird: Potential local code execution in "copy as cURL" command
CVE-2025-4084
Cvss
NVD 5.7
Red Hat 6.3
2026-10-02
firefox: thunderbird: Potential information leakage and privilege escalation in UITour actor
CVE-2025-4085
Cvss
NVD 7.1
Red Hat 6.8
2026-10-02
firefox: thunderbird: Specially crafted filename could be used to obscure download type
CVE-2025-4086
Cvss
NVD 6.5
Red Hat 5.4
2026-10-02
firefox: thunderbird: Unsafe attribute access during XPath parsing
CVE-2025-4087
Cvss
NVD 4.8
Red Hat 7.6
2026-10-02
firefox: thunderbird: Cross-site request forgery via storage access API redirects
CVE-2025-4088
Cvss
NVD 6.5
Red Hat 5.4
2026-10-02
firefox: thunderbird: Potential local code execution in "copy as cURL" command
CVE-2025-4089
Cvss
NVD 5.1
Red Hat 6.3
2026-10-02
firefox: thunderbird: Leaked library paths in Firefox for Android
CVE-2025-4090
Cvss
NVD 5.3
Red Hat 3.3
2026-10-02
firefox: thunderbird: Memory safety bugs fixed in Firefox 138, Thunderbird 138, Firefox ESR 128.10, and Thunderbird 128.10
CVE-2025-4091
Cvss
NVD 8.1
Red Hat 7.5
2026-10-02
firefox: thunderbird: Memory safety bugs fixed in Firefox 138 and Thunderbird 138
CVE-2025-4092
Cvss
NVD 6.5
Red Hat 8.8
2026-10-02
firefox: thunderbird: Memory safety bug fixed in Firefox ESR 128.10 and Thunderbird 128.10
CVE-2025-4093
Cvss
NVD 8.1
Red Hat 8.8
2026-10-02
pyroscope: sensitive COS SecretKey exposed in plaintext via configuration API due to missing type protection
CVE-2025-41118
Cvss
NVD 9.1
Red Hat 7.5
2026-10-02
webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash
CVE-2025-43501
Cvss
NVD 4.3
Red Hat 8.8
2026-10-02
webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash
CVE-2025-43511
Cvss
NVD 6.5
Red Hat 8.8
2026-10-02
webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash
CVE-2025-43531
Cvss
NVD 3.1
Red Hat 8.8
2026-10-02
webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash
CVE-2025-43535
Cvss
NVD 4.3
Red Hat 8.8
2026-10-02
webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
CVE-2025-43541
Cvss
NVD 4.3
Red Hat 8.8
2026-10-02
poppler: Poppler stack overflow
CVE-2025-43718
Cvss
NVD 2.9
Red Hat 4
2026-10-02
firefox: thunderbird: Out-of-bounds access when resolving Promise objects
CVE-2025-4918
Cvss
NVD 9.8
Red Hat 8.8
2026-10-02
matio: matio: Memory corruption allows arbitrary code execution or denial of service
CVE-2025-50343
Cvss
NVD 9.8
Red Hat 7.3
2026-10-02
firefox: thunderbird: Error handling for script execution was incorrectly isolated from web content
CVE-2025-5263
Cvss
NVD 4.3
Red Hat 6.1
2026-10-02
firefox: thunderbird: Potential local code execution in “Copy as cURL” command
CVE-2025-5264
Cvss
NVD 4.8
Red Hat 6.1
2026-10-02
firefox: thunderbird: Potential local code execution in “Copy as cURL” command
CVE-2025-5265
Cvss
NVD 4.8
Red Hat 6.1
2026-10-02
firefox: thunderbird: Script element events leaked cross-origin resource status
CVE-2025-5266
Cvss
NVD 4.3
Red Hat 6.1
2026-10-02
firefox: thunderbird: Clickjacking vulnerability could have led to leaking saved payment card details
CVE-2025-5267
Cvss
NVD 5.4
Red Hat 3.4
2026-10-02
firefox: thunderbird: Memory safety bugs
CVE-2025-5268
Cvss
NVD 8.1
Red Hat 6.1
2026-10-02
firefox: thunderbird: Memory safety bug
CVE-2025-5269
Cvss
NVD 8.1
Red Hat 6.1
2026-10-02
firefox: SNI was sometimes unencrypted
CVE-2025-5270
Cvss
NVD 7.5
Red Hat 3.4
2026-10-02
firefox: Devtools' preview ignored CSP headers
CVE-2025-5271
Cvss
NVD 6.5
Red Hat 3.4
2026-10-02
firefox: Memory safety bugs
CVE-2025-5272
Cvss
NVD 7.3
Red Hat 6.1
2026-10-02
vite: Vite's `server.fs` settings were not applied to HTML files
CVE-2025-58752
Cvss
NVD 5.3
Red Hat 3.7
2026-10-02
python: Quadratic complexity in os.path.expandvars() with user-controlled template
CVE-2025-6075
Cvss
NVD 5.5
Red Hat 4
2026-10-02
wasmtime: Wasmtime vulnerable to segfault when using component resources
CVE-2025-62711
Cvss
NVD 3.1
Red Hat 3.7
2026-10-02
firefox: thunderbird: Use-after-free in FontFaceSet
CVE-2025-6424
Cvss
NVD 9.8
Red Hat 7.5
2026-10-02
firefox: thunderbird: The WebCompat WebExtension shipped with Firefox exposed a persistent UUID
CVE-2025-6425
Cvss
NVD 4.3
Red Hat 6.1
2026-10-02
firefox: thunderbird: No warning when opening executable terminal files on macOS
CVE-2025-6426
Cvss
NVD 8.8
Red Hat 6.1
2026-10-02
firefox: connect-src Content Security Policy restriction could be bypassed
CVE-2025-6427
Cvss
NVD 9.1
Red Hat 6.1
2026-10-02
firefox: Firefox for Android opened URLs specified in a link querystring parameter
CVE-2025-6428
Cvss
NVD 4.3
Red Hat 6.1
2026-10-02
firefox: thunderbird: Incorrect parsing of URLs could have allowed embedding of youtube.com
CVE-2025-6429
Cvss
NVD 6.5
Red Hat 6.1
2026-10-02
firefox: The prompt in Firefox for Android that asks before opening a link in an external application could be bypassed
CVE-2025-6431
Cvss
NVD 6.5
Red Hat 3.4
2026-10-02
firefox: DNS Requests leaked outside of a configured SOCKS proxy
CVE-2025-6432
Cvss
NVD 8.6
Red Hat 3.4
2026-10-02
firefox: WebAuthn would allow a user to sign a challenge on a webpage with an invalid TLS certificate
CVE-2025-6433
Cvss
NVD 9.8
Red Hat 3.4
2026-10-02
firefox: HTTPS-Only exception screen lacked anti-clickjacking delay
CVE-2025-6434
Cvss
NVD 4.3
Red Hat 3.4
2026-10-02
firefox: Save as in Devtools could download files without sanitizing the extension
CVE-2025-6435
Cvss
NVD 8.1
Red Hat 3.4
2026-10-02
firefox: Memory safety bugs fixed in Firefox 140 and Thunderbird 140
CVE-2025-6436
Cvss
NVD 8.1
Red Hat 7.5
2026-10-02
jspdf: jsPDF Local File Inclusion/Path Traversal vulnerability
CVE-2025-68428
Cvss
NVD 7.5
Red Hat 8.6
2026-10-02
aiohttp: aiohttp: Request smuggling via non-ASCII characters in HTTP parser
CVE-2025-69224
Cvss
NVD 6.5
Red Hat 5.4
2026-10-02
aiohttp: aiohttp: Request smuggling vulnerability via non-ASCII decimals in Range header
CVE-2025-69225
Cvss
NVD 5.3
Red Hat 5.4
2026-10-02
aiohttp: aiohttp: Denial of Service via memory exhaustion from crafted POST request
CVE-2025-69228
Cvss
NVD 7.5
Red Hat 6.8
2026-10-02
aiohttp: AIOHTTP: Denial of Service via excessive CPU usage in chunked message handling
CVE-2025-69229
Cvss
NVD 5.3
Red Hat 5.8
2026-10-02
nltk: NLTK: Arbitrary Code Execution via Eval Injection in Collocations Module
CVE-2025-71408
Cvss
NVD 7.8
Red Hat 7
2026-10-02
firefox: thunderbird: JavaScript engine only wrote partial return value to stack
CVE-2025-8027
Cvss
NVD 6.5
Red Hat 7.5
2026-10-02
firefox: thunderbird: Large branch table could lead to truncated instruction
CVE-2025-8028
Cvss
NVD 9.8
Red Hat 7.5
2026-10-02
firefox: thunderbird: javascript: URLs executed on object and embed tags
CVE-2025-8029
Cvss
NVD 8.1
Red Hat 6.1
2026-10-02
firefox: thunderbird: Potential user-assisted code execution in “Copy as cURL” command
CVE-2025-8030
Cvss
NVD 8.1
Red Hat 6.1
2026-10-02
firefox: thunderbird: Incorrect URL stripping in CSP reports
CVE-2025-8031
Cvss
NVD 9.8
Red Hat 6.1
2026-10-02
firefox: thunderbird: XSLT documents could bypass CSP
CVE-2025-8032
Cvss
NVD 8.1
Red Hat 6.1
2026-10-02
firefox: thunderbird: Incorrect JavaScript state machine for generators
CVE-2025-8033
Cvss
NVD 6.5
Red Hat 3.4
2026-10-02
firefox: thunderbird: Memory safety bugs
CVE-2025-8034
Cvss
NVD 8.8
Red Hat 7.5
2026-10-02
firefox: thunderbird: Memory safety bugs
CVE-2025-8035
Cvss
NVD 8.8
Red Hat 7.5
2026-10-02
firefox: thunderbird: DNS rebinding circumvents CORS
CVE-2025-8036
Cvss
NVD 8.1
Red Hat 6.1
2026-10-02
firefox: thunderbird: Nameless cookies shadow secure cookies
CVE-2025-8037
Cvss
NVD 9.1
Red Hat 6.1
2026-10-02
firefox: thunderbird: CSP frame-src was not correctly enforced for paths
CVE-2025-8038
Cvss
NVD 9.8
Red Hat 3.4
2026-10-02
firefox: Search terms persisted in URL bar
CVE-2025-8039
Cvss
NVD 8.1
Red Hat 3.4
2026-10-02
firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141
CVE-2025-8040
Cvss
NVD 8.8
Red Hat 7.5
2026-10-02
firefox: thunderbird: Incorrect URL truncation
CVE-2025-8043
Cvss
NVD 9.8
Red Hat 6.1
2026-10-02
firefox: thunderbird: Memory safety bugs fixed in Firefox 141 and Thunderbird 141
CVE-2025-8044
Cvss
NVD 9.8
Red Hat 7.5
2026-10-02
thunderbird: firefox: Sandbox escape due to invalid pointer in the Audio/Video: GMP component
CVE-2025-9179
Cvss
NVD 9.8
Red Hat 7.5
2026-10-02
thunderbird: firefox: Same-origin policy bypass in the Graphics: Canvas2D component
CVE-2025-9180
Cvss
NVD 8.1
Red Hat 7.5
2026-10-02
thunderbird: firefox: Uninitialized memory in the JavaScript Engine component
CVE-2025-9181
Cvss
NVD 6.5
Red Hat 6.1
2026-10-02
firefox: thunderbird: Denial-of-service due to out-of-memory in the Graphics: WebRender component
CVE-2025-9182
Cvss
NVD 7.5
Red Hat 3.4
2026-10-02
firefox: Spoofing issue in the Address Bar component
CVE-2025-9183
Cvss
NVD 6.5
Red Hat 3.4
2026-10-02
thunderbird: firefox: Memory safety bugs fixed in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142
CVE-2025-9184
Cvss
NVD 8.1
Red Hat 7.5
2026-10-02
thunderbird: firefox: Memory safety bugs fixed in Firefox ESR 115.27, Firefox ESR 128.14, Thunderbird ESR 128.14, Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142
CVE-2025-9185
Cvss
NVD 8.1
Red Hat 7.5
2026-10-02
firefox: thunderbird: Memory safety bugs fixed in Firefox 142 and Thunderbird 142
CVE-2025-9187
Cvss
NVD 9.8
Red Hat 7.5
2026-10-02
chromium-browser: Out of bounds read in V8
CVE-2025-9479
Cvss
NVD 4.3
Red Hat 6.5
2026-10-02
spring-cloud-gateway: Spring Cloud Gateway Server: Security bypass due to untrusted header forwarding
CVE-2026-47825
Cvss
NVD 8.6
Red Hat 7.5
2026-10-02
nanoid: nanoid: Denial of Service via negative size input in non-secure module functions
CVE-2026-67214
Cvss
NVD 5.9
Red Hat 7.5
2026-10-02
python: Python/Expat: Denial of Service via crafted XML document
CVE-2026-7210
Cvss
NVD 7.5
Red Hat 5.3
2026-10-02
go.mongodb.org/mongo-driver: MongoDB Go Driver: Write redirection via unvalidated database name in Client.BulkWrite
CVE-2026-81521
Cvss
NVD 6.5
Red Hat 7.5
2026-10-02
oauth-proxy: Open Redirect via /\ and /\t Bypass in Post-Login Redirect
CVE-2026-83589
Severity
GitHub advisories medium
Red Hat high
2026-10-02
undici: Undici: Response truncation and connection termination
CVE-2026-84947
Severity
GitHub advisories low
Red Hat medium
2026-10-02
@angular/core: @angular/compiler: Angular: Arbitrary code execution via sanitization bypass in host bindings
CVE-2026-88057
Cvss
NVD 6.1
Red Hat 5.4
2026-10-02
copyparty contains a volume restriction bypass vulnerability in its SFTP front end that allows authenticated SFTP users to create, remove, and truncate arbitrary paths outside permitted volume boundaries by exploiting three handlers that bypass the xvol volflag enforcement. The _mkdir, _rmdir, and _chattr handlers construct destination paths using vfs.get(), vn.canonical(), and os.path.join() without invoking the chk_ap access check, enabling attackers to traverse symlinks leaving a volume's top directory and perform unauthorized file creation, deletion, or truncation via SSH_FXP_SETSTAT operations on paths outside any volume the account is authorized to access.
CVE-2026-93353
Cvss
GitHub advisories 5.3
NVD 3.1
2026-10-02
ca-certificates: ca-certificates: Failure to remove TrustCor root certificates
CVE-2023-32803
Cvss
NVD 7.5
Red Hat 8.1
2026-09-29
openssl: OpenSSL: Out-of-bounds Read Vulnerability
CVE-2023-53159
Cvss
NVD 4.5
Red Hat 5.7
2026-09-29
kernel: net/smc: fix potential panic dues to unprotected smc_llc_srv_add_link()
CVE-2023-54237
Cvss
NVD 9.8
Red Hat 5.5
2026-09-29
curl: predictable WebSocket mask
CVE-2025-10148
Cvss
NVD 5.3
Red Hat 4.8
2026-09-29
curl: Curl missing SFTP host verification with wolfSSH backend
CVE-2025-10966
Cvss
NVD 4.3
Red Hat 5.9
2026-09-29
php: php: Denial of Service via out-of-bounds read in mysqlnd wire protocol parser
CVE-2025-1218
Cvss
NVD 3.4
Red Hat 3.7
2026-09-29
curl: Public key pinning bypass via QUIC and GnuTLS allows server impersonation
CVE-2025-13034
Cvss
NVD 5.9
Red Hat 6.8
2026-09-29
OpenVPN: OpenVPN: Improper validation of source IP addresses leads to denial of service
CVE-2025-13086
Cvss
NVD 7.5
Red Hat 6.5
2026-09-29
lodash: prototype pollution in _.unset and _.omit functions
CVE-2025-13465
Cvss
NVD 5.3
Red Hat 8.2
2026-09-29
chromium-browser: Inappropriate implementation in Downloads
CVE-2025-13635
Cvss
NVD 4.4
Red Hat 4.3
2026-09-29
chromium-browser: Use after free in Media Stream
CVE-2025-13638
Cvss
NVD 8.8
Red Hat 4.3
2026-09-29
chromium-browser: Inappropriate implementation in WebRTC
CVE-2025-13639
Cvss
NVD 8.1
Red Hat 4.3
2026-09-29
chromium-browser: Bad cast in Loader
CVE-2025-13720
Cvss
NVD 8.8
Red Hat 6.5
2026-09-29
chromium-browser: Race in v8
CVE-2025-13721
Cvss
NVD 7.5
Red Hat 6.5
2026-09-29
chromium-browser: Side-channel information leakage in Navigation and Loading
CVE-2025-13992
Cvss
NVD 4.7
Red Hat 6.5
2026-09-29
curl: curl: Security bypass due to global TLS option changes in multi-threaded LDAPS transfers
CVE-2025-14017
Cvss
NVD 6.3
Red Hat 4.8
2026-09-29
curl: Information disclosure via cross-protocol redirect with OAuth2 bearer token
CVE-2025-14524
Cvss
NVD 5.3
Red Hat 6.5
2026-09-29
curl: libcurl: Improper certificate validation due to cached TLS settings reuse
CVE-2025-14819
Cvss
NVD 5.3
Red Hat 6.8
2026-09-29
curl: Host verification bypass during SSH transfers
CVE-2025-15079
Cvss
NVD 5.3
Red Hat 8.1
2026-09-29
curl: libssh key passphrase bypass without agent set
CVE-2025-15224
Cvss
NVD 3.1
Red Hat 4.7
2026-09-29
kernel: md/md-bitmap: fix wrong bitmap_limit for clustermd when write sb
CVE-2025-22124
Cvss
NVD 7.8
Red Hat 6
2026-09-29
kernel: wifi: ath11k: Clear affinity hint before calling ath11k_pcic_free_irq() in error path
CVE-2025-23129
Cvss
NVD 5.5
Red Hat 4.7
2026-09-29
zabbix: Zabbix: Authenticated Super Admin can read arbitrary files via oauth.authorize action
CVE-2025-27232
Cvss
NVD 4.9
Red Hat 6.8
2026-09-29
kernel: ksmbd: fix WARNING "do not call blocking ops when !TASK_RUNNING"
CVE-2025-37802
Cvss
NVD 7.5
Red Hat 5.5
2026-09-29
kernel: espintcp: remove encap socket caching to avoid reference leak
CVE-2025-38097
Cvss
NVD 7.8
Red Hat 3.3
2026-09-29
kernel: Linux kernel: Denial of Service in BPF due to improper context access
CVE-2025-38591
Cvss
NVD 5.5
Red Hat 4.4
2026-09-29
kernel: [ceph] parse_longname(): strrchr() expects NUL-terminated string
CVE-2025-38660
Cvss
NVD 9.8
Red Hat 5.9
2026-09-29
Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability
CVE-2025-39682
Cvss
NVD 9.8
Red Hat 7
2026-09-29
kernel: wifi: mt76: mt7915: fix list corruption after hardware restart
CVE-2025-39862
Cvss
NVD 8.8
Red Hat 5.5
2026-09-29
kernel: Bluetooth: l2cap: Check encryption key size on incoming connection
CVE-2025-39889
Cvss
NVD 8.1
Red Hat 5.4
2026-09-29
kernel: Linux kernel ath12k Wi-Fi memory leak
CVE-2025-39890
Cvss
NVD 5.5
Red Hat 4.7
2026-09-29
Linux Kernel Race Condition Vulnerability
CVE-2025-39964
Cvss
NVD 7.8
Red Hat 7.3
2026-09-29
kernel: ipv4: start using dst_dev_rcu()
CVE-2025-40074
Cvss
NVD 9.8
Red Hat 6.4
2026-09-29
kernel: bpf: Enforce expected_attach_type for tailcall compatibility
CVE-2025-40123
Cvss
NVD 7.8
Red Hat 4.4
2026-09-29
webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash
CVE-2025-43429
Cvss
NVD 4.3
Red Hat 8.8
2026-09-29
webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
CVE-2025-43434
Cvss
NVD 4.3
Red Hat 8.8
2026-09-29
webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
CVE-2025-43438
Cvss
NVD 4.3
Red Hat 8.8
2026-09-29
webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash
CVE-2025-43443
Cvss
NVD 4.3
Red Hat 8.8
2026-09-29
webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash
CVE-2025-43458
Cvss
NVD 4.3
Red Hat 8.8
2026-09-29
apr-util: Apache Portable Runtime Utility: Information disclosure via timing attack in password validation
CVE-2025-49506
Cvss
NVD 7.5
Red Hat 5.9
2026-09-29
ply: python-ply: Unsafe pickle file handling in Ply
CVE-2025-56005
Cvss
NVD 9.8
Red Hat 7.8
2026-09-29
httpd: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=...
CVE-2025-58098
Cvss
NVD 8.3
Red Hat 7.1
2026-09-29
cmd/go: cmd/go: Arbitrary file write via malicious pkg-config directive
CVE-2025-61731
Cvss
NVD 7.8
Red Hat 8.6
2026-09-29
cmd/cgo: Go cgo: Code smuggling due to comment parsing discrepancy
CVE-2025-61732
Cvss
NVD 8.6
Red Hat 7.4
2026-09-29
github.com/hashicorp/vault: Vault unauthenticated denial of service
CVE-2025-6203
Cvss
NVD 7.5
Red Hat 5.3
2026-09-29
axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization
CVE-2025-62718
Cvss
NVD 9.9
Red Hat 7
2026-09-29
libarchive: libarchive: Denial of Service via heap-based buffer overflow in gzip writer
CVE-2025-64031
Cvss
NVD 2.5
Red Hat 4.7
2026-09-29
org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in extractFile method
CVE-2025-67030
Cvss
NVD 8.8
Red Hat 8.3
2026-09-29
aiohttp: aiohttp: Denial of Service via specially crafted invalid cookies
CVE-2025-69230
Cvss
NVD 5.3
Red Hat 5.4
2026-09-29
python-apt: python-apt: NULL pointer dereference leads to local denial of service
CVE-2025-6966
Cvss
NVD 5.5
Red Hat 4
2026-09-29
ajv: ReDoS via $data reference
CVE-2025-69873
Cvss
NVD 2.9
Red Hat 7.5
2026-09-29
curl: libcurl: Curl out of bounds read for cookie path
CVE-2025-9086
Cvss
NVD 7.5
Red Hat 5.3
2026-09-29
Wireshark: NULL Pointer Dereference in Wireshark
CVE-2025-9817
Cvss
NVD 7.8
Red Hat 5.5
2026-09-29
gix-fs: gix-fs: Arbitrary code execution via symlink manipulation during checkout
CVE-2026-100419
Severity
GitHub advisories high
Red Hat medium
2026-09-29
backend: Capgo backend: Unauthorized role modification via improper role binding validation
CVE-2026-100629
Severity
GitHub advisories high
Red Hat medium
2026-09-29
vllm: vLLM: Denial of service via sampler subclass decoder limit bypass
CVE-2026-100649
Severity
GitHub advisories medium
Red Hat low
2026-09-29
vllm: vLLM: Denial of Service via unbounded media ingestion
CVE-2026-100650
Cvss
GitHub advisories 6.5
NVD 6.5
Red Hat 7.5
2026-09-29
vllm: vLLM: Denial of Service via overlong multimodal inference requests
CVE-2026-100651
Severity
GitHub advisories high
Red Hat medium
2026-09-29
vllm: vLLM: Denial of Service via out-of-bounds stop token IDs
CVE-2026-100652
Cvss
GitHub advisories 5.9
NVD 5.9
Red Hat 7.5
2026-09-29
vllm: vLLM: Supply chain integrity compromise via incomplete model revision pinning
CVE-2026-100653
Severity
GitHub advisories high
Red Hat medium
2026-09-29
vllm: vLLM: Denial of Service via out-of-range stop token identifiers
CVE-2026-100654
Severity
GitHub advisories high
Red Hat medium
2026-09-29
io.netty/netty-codec-http: Netty: Denial of Service via unbounded SPDY concurrent streams
CVE-2026-100655
Severity
GitHub advisories medium
Red Hat high
2026-09-29
GitPython: GitPython: Directory traversal via untrusted submodule path
CVE-2026-100689
Severity
GitHub advisories high
Red Hat medium
2026-09-29
nodemailer: nodemailer: Denial of Service via deeply nested recipient arrays
CVE-2026-100702
Severity
GitHub advisories high
Red Hat medium
2026-09-29
opendmarc: OpenDMARC: Denial of Service via off-by-one error in opendmarc_util_cleanup
CVE-2026-101014
Cvss
GitHub advisories 7.3
NVD 7.3
Red Hat 7.5
2026-09-29
opendmarc: OpenDMARC: Denial of Service via off-by-one error in opendmarc_util_cleanup
CVE-2026-101014
Severity
GitHub advisories medium
Red Hat high
2026-09-29
libcurl: libcurl: Use-after-free vulnerability leading to Denial of Service
CVE-2026-10536
Cvss
NVD 9.8
Red Hat 4.7
2026-09-29
libcurl: libcurl: Certificate validation bypass due to incorrect connection reuse
CVE-2026-11564
Cvss
NVD 9.1
Red Hat 6.5
2026-09-29
curl: curl: Information disclosure via incorrect Digest authentication header reuse
CVE-2026-11856
Cvss
NVD 9.8
Red Hat 6.5
2026-09-29
curl: curl: Authentication bypass in OpenLDAP SASL negotiation via Man-in-the-Middle (MITM) attack
CVE-2026-13608
Cvss
NVD 7.4
Red Hat 3.7
2026-09-29
chromium-browser: angle: chromium-browser: Out of bounds read in ANGLE
CVE-2026-17701
Cvss
NVD 9.6
Red Hat 8.2
2026-09-29
chromium-browser: chromium-browser: Insufficient validation of untrusted input in Accessibility
CVE-2026-17713
Cvss
NVD 9.6
Red Hat 9
2026-09-29
chromium-browser: chromium-browser: Insufficient validation of untrusted input in Isolated Web Apps
CVE-2026-17909
Cvss
NVD 5.3
Red Hat 3.1
2026-09-29
curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections
CVE-2026-18924
Cvss
NVD 9.1
Red Hat 3.7
2026-09-29
glibc: Buffer Overflow in strfmon right-justification padding
CVE-2026-19499
Cvss
NVD 7.7
Red Hat 6.8
2026-09-29
glibc: Fix out-of-bounds array write in tdelete
CVE-2026-19542
Cvss
NVD 5.6
Red Hat 4.2
2026-09-29
quarkus-oidc: Quarkus OIDC: Cross-tenant authentication bypass via shared token-introspection cache
CVE-2026-19625
Cvss
NVD 5.3
Red Hat 8.7
2026-09-29
curl: curl: Authentication bypass due to incorrect connection reuse with Negotiate authentication
CVE-2026-1965
Cvss
NVD 6.5
Red Hat 6.8
2026-09-29
curl: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication
CVE-2026-19931
Cvss
NVD 9.8
Red Hat 6.5
2026-09-29
kernel: ALSA: aloop: Fix racy access at PCM trigger
CVE-2026-23191
Cvss
NVD 7.8
Red Hat 7.1
2026-09-29
kernel: net: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check
CVE-2026-23447
Cvss
NVD 7.8
Red Hat 6.6
2026-09-29
kernel: net: usb: cdc_ncm: add ndpoffset to NDP16 nframes bounds check
CVE-2026-23448
Cvss
NVD 7.8
Red Hat 5.5
2026-09-29
org.apache.pdfbox:pdfbox-examples: Apache PDFBox Example: Path Traversal via specially crafted filenames allows arbitrary file write
CVE-2026-23907
Cvss
NVD 5.3
Red Hat 6.5
2026-09-29
zabbix: Zabbix: Denial of Service via crafted JavaScript scripts
CVE-2026-23938
Cvss
NVD 4.9
Red Hat 2.7
2026-09-29
openstack-nova-compute: Arbitrary Host File Overwrite via Unconstrained qemu-img Format Handling in OpenStack Nova
CVE-2026-24708
Cvss
NVD 8.2
Red Hat 7.1
2026-09-29
fast-xml-parser: fast-xml-parser: Cross-Site Scripting (XSS) due to improper DOCTYPE entity handling
CVE-2026-25896
Cvss
NVD 9.3
Red Hat 7.1
2026-09-29
pillow: Pillow: Out-of-bounds Write via Specially Crafted PSD Image
CVE-2026-25990
Cvss
NVD 7.5
Red Hat 7.3
2026-09-29
cryptography: cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curves
CVE-2026-26007
Cvss
NVD 6.5
Red Hat 7.4
2026-09-29
cmd/go: golang: Go (golang) and cmd/go: Arbitrary Code Execution via malicious SWIG file names
CVE-2026-27140
Cvss
NVD 8.8
Red Hat 9
2026-09-29
crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries
CVE-2026-27145
Cvss
NVD 6.5
Red Hat 7.5
2026-09-29
org.apache.artemis:artemis-server: org.apache.activemq:artemis-server: Apache Artemis, Apache ActiveMQ Artemis: Message injection and exfiltration due to missing authentication
CVE-2026-27446
Cvss
NVD 9.8
Red Hat 9.1
2026-09-29
pyOpenSSL: DTLS cookie callback buffer overflow
CVE-2026-27459
Cvss
NVD 9.8
Red Hat 8.1
2026-09-29
rollup: Rollup: Remote Code Execution via Path Traversal Vulnerability
CVE-2026-27606
Cvss
NVD 9.8
Red Hat 9.1
2026-09-29
firefox: thunderbird: Undefined behavior in the DOM: Core & HTML component
CVE-2026-2771
Cvss
NVD 9.8
Red Hat 7.5
2026-09-29
authlib: Authlib: Authentication bypass via forged OpenID Connect ID Tokens
CVE-2026-28498
Cvss
NVD 7.5
Red Hat 9.1
2026-09-29
Apache HTTP Server: mod_proxy_ajp: Apache HTTP Server mod_proxy_ajp: Arbitrary code execution via heap-based buffer overflow
CVE-2026-28780
Cvss
NVD 9.8
Red Hat 8.1
2026-09-29
authlib: Authlib: Signature verification bypass via malicious JWT allows unauthorized access
CVE-2026-28802
Cvss
NVD 9.8
Red Hat 9.1
2026-09-29
CivetWeb: CivetWeb: Arbitrary code execution via crafted WebSocket frames
CVE-2026-29035
Cvss
NVD 6.5
Red Hat 7.5
2026-09-29
immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution
CVE-2026-29063
Cvss
NVD 9.8
Red Hat 8.8
2026-09-29
kernel: xfrm: hold dev ref until after transport_finish NF_HOOK
CVE-2026-31663
Cvss
NVD 7.8
Red Hat 7
2026-09-29
crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application
CVE-2026-33810
Cvss
NVD 8.2
Red Hat 8.8
2026-09-29
github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability
CVE-2026-33815
Cvss
NVD 9.8
Red Hat 8.3
2026-09-29
github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability
CVE-2026-33816
Cvss
NVD 9.8
Red Hat 8.3
2026-09-29
curl: curl: Information disclosure via OAuth2 bearer token leakage during HTTP(S) redirect
CVE-2026-3783
Cvss
NVD 5.3
Red Hat 5.7
2026-09-29
curl: curl: Arbitrary code execution or Denial of Service via use-after-free in SMB request handling
CVE-2026-3805
Cvss
NVD 7.5
Red Hat 6.3
2026-09-29
jbig2dec: jbig2dec: Denial of Service via crafted input
CVE-2026-38076
Cvss
NVD 7.5
Red Hat 6.5
2026-09-29
golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing
CVE-2026-39821
Cvss
NVD 9.6
Red Hat 8.2
2026-09-29
golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions
CVE-2026-39828
Cvss
NVD 6.3
Red Hat 8.8
2026-09-29
golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses
CVE-2026-39830
Cvss
NVD 9.1
Red Hat 7.5
2026-09-29
golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions
CVE-2026-39832
Cvss
NVD 9.1
Red Hat 8.7
2026-09-29
golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate
CVE-2026-39835
Cvss
NVD 5.3
Red Hat 7.5
2026-09-29
cryptography: Cryptography: Buffer overflow via non-contiguous buffer in API
CVE-2026-39892
Cvss
NVD 9.8
Red Hat 7.3
2026-09-29
ghostscript: ghostscript: Heap buffer overflow via JPEG 2000 output adapter
CVE-2026-39919
Cvss
NVD 9.8
Red Hat 7.8
2026-09-29
axios: Axios: Authentication bypass due to prototype pollution of HTTP error handling
CVE-2026-42041
Cvss
NVD 4.8
Red Hat 8.2
2026-09-29
axios: Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget
CVE-2026-42044
Cvss
NVD 6.5
Red Hat 7.4
2026-09-29
ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input
CVE-2026-42338
Cvss
NVD 6.1
Red Hat 8.1
2026-09-29
golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey
CVE-2026-42508
Cvss
NVD 9.1
Red Hat 7.4
2026-09-29
netty: io.netty/netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers
CVE-2026-42581
Cvss
NVD 5.8
Red Hat 7.2
2026-09-29
erlang: Erlang OTP public_key: Certificate chain forgery via improper trust chain validation
CVE-2026-42789
Cvss
NVD 4.8
Red Hat 8
2026-09-29
erlang: Erlang OTP public_key: Certificate validation bypass allows hostname spoofing
CVE-2026-42790
Cvss
NVD 8.1
Red Hat 7.4
2026-09-29
kernel: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath
CVE-2026-43112
Cvss
NVD 8.8
Red Hat 8.1
2026-09-29
kernel: netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry
CVE-2026-43114
Cvss
NVD 9.4
Red Hat 8.1
2026-09-29
kernel: tcp: fix potential race in tcp_v6_syn_recv_sock()
CVE-2026-43198
Cvss
NVD 9.8
Red Hat 7
2026-09-29
kernel: net/rds: handle zerocopy send cleanup before the message is queued
CVE-2026-43502
Cvss
NVD 7.8
Red Hat 5.5
2026-09-29
webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
CVE-2026-43795
Cvss
NVD 4.3
Red Hat 8.8
2026-09-29
rabbitmq-c: rabbitmq-c: Heap buffer overflow leading to denial of service
CVE-2026-44236
Cvss
NVD 7.1
Red Hat 6.5
2026-09-29
netty: io.netty/netty-codec-mqtt: Netty: Denial of Service due to excessive resource consumption from crafted MQTT 5 header
CVE-2026-44248
Cvss
NVD 5.3
Red Hat 7.5
2026-09-29
libxfonts2: libXfont2: Privilege Escalation via Heap Buffer Overflow in Font Server Client
CVE-2026-44950
Cvss
NVD 9
Red Hat 7.5
2026-09-29
sanitize-html: `sanitize-html`: Stored Cross-Site Scripting via HTML sanitizer bypass
CVE-2026-44990
Cvss
NVD 9.3
Red Hat 8.1
2026-09-29
libexpat: denial of service via crafted XML input
CVE-2026-45186
Cvss
NVD 2.9
Red Hat 7.5
2026-09-29
opentelemetry-java: opentelemetry-api: opentelemetry-extension-trace-propagators: OpenTelemetry Java: Denial of Service due to unbounded memory allocation when parsing oversized baggage
CVE-2026-45292
Cvss
NVD 5.3
Red Hat 7.5
2026-09-29
ruby-jwt: ruby-jwt: Authentication bypass due to empty key in HMAC verification
CVE-2026-45363
Cvss
NVD 9.1
Red Hat 7.4
2026-09-29
openssl: Heap Use-After-Free in OpenSSL PKCS7_verify()
CVE-2026-45447
Cvss
NVD 8.8
Red Hat 8.1
2026-09-29
ws: ws: Uninitialized memory disclosure via `websocket.close()` with `TypedArray`
CVE-2026-45736
Cvss
NVD 4.4
Red Hat 7.5
2026-09-29
suricata: Suricata http2: protocol-change type confusion can lead to denial of service
CVE-2026-45764
Cvss
NVD 9.1
Red Hat 7.5
2026-09-29
kernel: rxrpc: Fix potential UAF after skb_unshare() failure
CVE-2026-45998
Cvss
NVD 7.8
Red Hat 7
2026-09-29
jsrsasign: jsrsasign: Cryptographic signature forgery via malicious DSA domain parameters
CVE-2026-4600
Cvss
NVD 7.4
Red Hat 8.2
2026-09-29
kernel: selinux: fix overlayfs mmap() and mprotect() access checks
CVE-2026-46054
Cvss
NVD 7.1
Red Hat 7
2026-09-29
kernel: ALSA: aloop: Fix peer runtime UAF during format-change stop
CVE-2026-46090
Cvss
NVD 7.8
Red Hat 7
2026-09-29
kernel: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete
CVE-2026-46116
Cvss
NVD 7.8
Red Hat 7
2026-09-29
kernel: RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss()
CVE-2026-46117
Cvss
NVD 7.8
Red Hat 7
2026-09-29
kernel: mptcp: pm: ADD_ADDR rtx: always decrease sk refcount
CVE-2026-46158
Cvss
NVD 5.5
Red Hat 7
2026-09-29
kernel: mptcp: pm: ADD_ADDR rtx: free sk if last
CVE-2026-46170
Cvss
NVD 5.5
Red Hat 7
2026-09-29
kernel: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry
CVE-2026-46316
Cvss
NVD 9.3
Red Hat 7
2026-09-29
golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation
CVE-2026-46595
Cvss
NVD 10
Red Hat 7.1
2026-09-29
vim: Vim: Arbitrary Code Execution via crafted directory names
CVE-2026-47162
Cvss
NVD 8.8
Red Hat 7.3
2026-09-29
github.com/open-telemetry/opentelemetry-collector-contrib/exporter/sentryexporter: opentelemetry-collector-contrib: OpenTelemetry Sentry Exporter: Path traversal allows unauthorized access to Sentry API endpoints
CVE-2026-47256
Cvss
NVD 5.3
Red Hat 6.5
2026-09-29
org.springframework/spring-webmvc: org.springframework/spring-webflux: Spring Framework: Open redirect vulnerability in UrlHandlerFilter via broadly matching patterns
CVE-2026-47883
Cvss
NVD 6.1
Red Hat 5.4
2026-09-29
org.springframework/spring-webmvc: Spring Framework: Open redirect vulnerability in UrlFileNameViewController
CVE-2026-47887
Cvss
NVD 6.1
Red Hat 5.4
2026-09-29
netty-codec-http2: netty-codec-http2: Denial of Service due to resource leak
CVE-2026-48043
Cvss
NVD 5.3
Red Hat 7.5
2026-09-29
curl: curl: Information disclosure due to incorrect TLS connection reuse
CVE-2026-4873
Cvss
NVD 5.9
Red Hat 5.3
2026-09-29
erlang: Erlang OTP ssh: Information disclosure via symlink resolution in SFTP
CVE-2026-48855
Cvss
NVD 6.5
Red Hat 4.3
2026-09-29
erlang: Erlang/OTP: Authentication bypass allows arbitrary code execution via improper IP address validation
CVE-2026-48860
Cvss
NVD 6.5
Red Hat 6.8
2026-09-29
onnx: ONNX: Arbitrary file write via symlink following and path traversal
CVE-2026-49114
Cvss
NVD 7.1
Red Hat 7.3
2026-09-29
capstone: Capstone: Denial of service via out-of-bounds read in M68K and RISCV backends
CVE-2026-49282
Cvss
NVD 5.1
Red Hat 6.2
2026-09-29
artemis-server: undertow-core: wildfly-messaging-activemq-subsystem: artemis core protocol permits unauthed queue creation
CVE-2026-49362
Cvss
NVD 7.5
Red Hat 8.2
2026-09-29
artemis-server: artemis-server: Pre-auth topology disclosure via CORE SUBSCRIBE_TOPOLOGY_V2 on channel0
CVE-2026-49363
Cvss
NVD 7.5
Red Hat 5.3
2026-09-29
wildfly-messaging-activemq-subsystem: artemis-server: jgroups: artemis cluster password leak via jgroups spoof
CVE-2026-49364
Cvss
NVD 9.1
Red Hat 8
2026-09-29
github.com/osrg/gobgp: GoBGP: Malformed BGP OPEN message can disrupt BGP sessions
CVE-2026-49837
Cvss
NVD 5.9
Red Hat 7.4
2026-09-29
A Server-Side Request Forgery (SSRF) vulnerability exists in the Image API (v2) of OpenStack Glance. When the show_multiple_locations configuration option is enabled in glance-api.conf, an authenticated attacker can manipulate the locations attribute of an image in the queued state by sending a crafted HTTP PATCH request
CVE-2026-51772
Cvss
GitHub advisories 8.1
NVD 6.5
2026-09-29
glance-store: glance_store: glance_store: Information disclosure via unvalidated external image location URI
CVE-2026-51773
Cvss
GitHub advisories 8.1
NVD 8.1
Red Hat 6.5
2026-09-29
glance-store: glance_store: glance_store: Information disclosure via unvalidated external image location URI
CVE-2026-51773
Severity
GitHub advisories high
Red Hat medium
2026-09-29
ffmpeg: out-of-bounds read due to missing required padding in WMA extradata allocation paths
CVE-2026-52296
Cvss
NVD 2.9
Red Hat 5.5
2026-09-29
ffmpeg: out-of-bounds read due to insufficiently padded extradata in the MOV parsing path
CVE-2026-52297
Cvss
NVD 2.9
Red Hat 5.5
2026-09-29
vim: Vim: Arbitrary code execution through Python omni-completion.
CVE-2026-52860
Cvss
NVD 7.8
Red Hat 8
2026-09-29
kernel: sctp: purge outqueue on stale COOKIE-ECHO handling
CVE-2026-52924
Cvss
NVD 9.8
Red Hat 8.8
2026-09-29
kernel: drm/amdgpu: avoid double drm_exec_fini() in userq validate
CVE-2026-52987
Cvss
NVD 7.8
Red Hat 7
2026-09-29
kernel: netfilter: nat: use kfree_rcu to release ops
CVE-2026-53000
Cvss
NVD 7.8
Red Hat 7
2026-09-29
kernel: netfilter: conntrack: remove sprintf usage
CVE-2026-53002
Cvss
NVD 9.8
Red Hat 7
2026-09-29
kernel: ipv6: fix possible UAF in icmpv6_rcv()
CVE-2026-53006
Cvss
NVD 9.8
Red Hat 7
2026-09-29
kernel: crypto: ccp - copy IV using skcipher ivsize
CVE-2026-53016
Cvss
NVD 7.8
Red Hat 7
2026-09-29
kernel: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp
CVE-2026-53071
Cvss
NVD 8.8
Red Hat 7.5
2026-09-29
kernel: bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops
CVE-2026-53078
Cvss
NVD 7.8
Red Hat 6.4
2026-09-29
kernel: net: pull headers in qdisc_pkt_len_segs_init()
CVE-2026-53091
Cvss
NVD 8.4
Red Hat 7
2026-09-29
kernel: IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN
CVE-2026-53176
Cvss
NVD 9.8
Red Hat 6.5
2026-09-29
kernel: Linux kernel (xsk): Out-of-bounds memory access via TOCTOU race condition
CVE-2026-53250
Cvss
NVD 7.8
Red Hat 7
2026-09-29
Linux Kernel Out-of-Bounds Write Vulnerability
CVE-2026-53266
Cvss
NVD 8.8
Red Hat 7.5
2026-09-29
aiohttp: aiohttp: Information disclosure via DigestAuthMiddleware after cross-origin redirect
CVE-2026-54276
Cvss
NVD 6.1
Red Hat 3.1
2026-09-29

Sign in to mark a conflict seen or mute it. The marks are yours and nobody else sees them.