product of redhat

enterprise linux

90 thingsrelated by NVD

Being told

Watch: its feed Ask more of it

The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.

Every thing

gstreamer1-plugins-good: gstreamer: out-of-bounds read in avidemux vprp video field descriptor parsing
CVE-2026-73434
Severity medium
gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux FUJIFILM strd parsing leading to out-of-bounds read/write
CVE-2026-73433
Severity medium
ipa: FreeIPA: Unauthenticated DoS in `/ipa/i18n_messages` via Unbounded Request Body Read
CVE-2026-73198
Severity high
ipa: FreeIPA: Unauthenticated DoS in `/ipa/migration/migration.py` via Unbounded Request Body Read
CVE-2026-73197
Severity high
libkcapi: Infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return
CVE-2026-71227
Severity medium
libkcapi: Memory corruption via uncanceled AIO requests on error in libkcapi's one-shot AIO path
CVE-2026-71226
Severity high
libkcapi: IV reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries
CVE-2026-71225
Severity medium
gfs2-utils: gfs2-utils: stack overflow via alloca(i_height) in metadata walk
CVE-2026-71224
Severity medium
gfs2-utils: gfs2-utils: heap out-of-bounds read via unchecked ea_num_ptrs in extended attribute processing
CVE-2026-71222
Severity medium
gfs2-utils: gfs2-utils: stack out-of-bounds write via unchecked height in savemeta
CVE-2026-71221
Severity high
gfs2-utils: gfs2-utils: stack out-of-bounds write via unchecked di_height in gfs2_edit
CVE-2026-71220
Severity high
gfs2-utils: gfs2-utils: stack overflow via alloca(1<<di_depth) in hash table traversal
CVE-2026-71219
Severity medium
gimp: integer overflow in file-fits plugin causes a heap-based buffer overflow on crafted FITS images
CVE-2026-66758
Severity high
libssh: libssh: denial of service via automatic certificate authentication loop
CVE-2026-59849
Severity high
libssh: libssh: information disclosure via short GSSAPI Curve25519 public key
CVE-2026-59842
Severity medium
gimp: GIMP: Arbitrary code execution in PSD plugin due to unsigned underflow
CVE-2026-59090
Severity critical
gimp: gimp: Integer overflow in read_RLE_channel()
CVE-2026-58384
Severity high
gimp: gimp: Double-free in read_layer_block()
CVE-2026-58381
Severity high
gimp: gimp: Stack buffer overflow in pnmscanner_gettoken()
CVE-2026-58380
Severity high
samba: CTDB fails to do integrity checking of received packets
CVE-2026-58224
Severity medium
glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml"
CVE-2026-58016
Severity critical
glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive
CVE-2026-58015
Severity high
glib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list"
CVE-2026-58014
Severity high
glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend"
CVE-2026-58013
Severity high
glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char()
CVE-2026-58012
Severity high
glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid GDateTime
CVE-2026-58011
Severity high
glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal()
CVE-2026-58010
Severity high
openssh: Heap out-of-bounds read in Red Hat Enterprise Linux versions of OpenSSH GSSAPI indicator cleanup due to missing NULL sentinel…
CVE-2026-55654
Severity low
abrt: unsanitized systemd journal content written to dump directory files enables content injection
CVE-2026-54231
Severity medium
abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites
CVE-2026-54230
Severity high
kernel: ipv6: fix possible UAF in icmpv6_rcv()
CVE-2026-53006
Severity critical
kernel: netfilter: conntrack: remove sprintf usage
CVE-2026-53002
Severity critical
kernel: netfilter: nat: use kfree_rcu to release ops
CVE-2026-53000
Severity high
libsolv: Heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data
CVE-2026-48864
Severity high
mariadb: MariaDB server: SQL injection vulnerability via improper handling of big5 character set with mysql_real_escape_string()
CVE-2026-44172
Severity critical
gimp: GIMP APNG loader heap-buffer-overflow when fcTL width exceeds IHDR width (file-png.c)
CVE-2026-42169
Severity high
nginx: NGINX: Arbitrary code execution or Denial of Service via heap-based buffer overflow with crafted HTTP/2 headers
CVE-2026-42055
Severity high
gnutls: gnutls: Authentication Bypass via NUL Character in Username
CVE-2026-42010
Severity critical
gnutls: gnutls: Denial of Service via DTLS packet reordering vulnerability
CVE-2026-42009
Severity high
Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
CVE-2026-34486
Severity high Exploited yes
gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment
CVE-2026-33845
Severity critical
undertow: Undertow: Request Smuggling via Malformed HTTP Request Headers
CVE-2026-28369
Severity critical
undertow: Undertow: Request smuggling via inconsistent header parsing
CVE-2026-28368
Severity critical
rsyslog: A configuration-dependent issue in rsyslog's optional imptcp input module can allow an unauthenticated remote peer to crash…
CVE-2026-19654
Severity high
libdm: lvm2: libdm: Denial of Service via uncontrolled recursion in config parser
CVE-2026-19617
Severity medium
freeipa: ipa: FreeIPA: trust-fetch-domains uses trust-read ACI to gate a privileged AD trust refresh, allowing unauthorized LDAP writes
CVE-2026-19550
Severity high
tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite
CVE-2026-18508
Severity medium
tar: tar: TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape
CVE-2026-18477
Severity medium
libssh: libssh: stack buffer overflow in SFTP server longname construction
CVE-2026-15370
Severity high
p11-kit: Stack exhaustion via unbounded recursion in RPC attribute parsing
CVE-2026-13757
Severity medium
ipa: Privilege escalation via krbCanonicalName manipulation due to realm-unaware uniqueness enforcement in FreeIPA LDAP datastore
CVE-2026-13097
Severity high
FreeIPA: idm: ipa: FreeIPA: Obtaining TGS with impersonating cname through trust relationships
CVE-2026-11861
Severity high
gimp: GIMP: Arbitrary code execution or denial of service via buffer overflow in GIF image processing
CVE-2026-6384
Severity high
tar: tar: Hidden file injection via crafted archives
CVE-2026-5704
Severity medium
libarchive: libarchive: Arbitrary code execution via integer overflow in ISO9660 image processing
CVE-2026-5121
Severity high
firewalld: firewalld: Local unprivileged user can modify firewall state due to D-Bus setter mis-authorization
CVE-2026-4948
Severity medium
polkit: Polkit: Denial of Service via unbounded input processing through standard input
CVE-2026-4897
Severity medium
libcap: libcap: Privilege escalation via TOCTOU race condition in cap_set_file()
CVE-2026-4878
Severity high
libtiff: libtiff: Arbitrary code execution or denial of service via signed integer overflow in TIFF file processing
CVE-2026-4775
Severity high
libarchive: libarchive: Information disclosure via heap out-of-bounds read in RAR archive processing
CVE-2026-4424
Severity high
samba: Remote Code Execution in SAMR
CVE-2026-4408
Severity critical
gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison
CVE-2026-3833
Severity high
gnutls: gnutls: Security bypass allows acceptance of revoked server certificates via crafted OCSP response
CVE-2026-3832
Severity low
samba: group policy certificate enrollment uses http:// without validation
CVE-2026-3012
Severity high
samba: vfs_worm does not block directory modification
CVE-2026-2340
Severity medium
p11-kit: NULL dereference via C_DeriveKey with specific NULL parameters
CVE-2026-2100
Severity high
samba: Missing access check on reparse point operations
CVE-2026-1933
Severity high
Apple Multiple Products Buffer Overflow Vulnerability
CVE-2025-31277
Severity high Exploited yes
glib: Integer Overflow in GLib GIO Attribute Escaping Causes Heap Buffer Overflow
CVE-2025-14512
Severity medium
glib: GLib: Buffer underflow in GVariant parser leads to heap corruption
CVE-2025-14087
Severity critical
undertow: Undertow MadeYouReset HTTP/2 DDoS Vulnerability
CVE-2025-9784
Severity high
libxml2: Stack Buffer Overflow in xmllint Interactive Shell Command Handling
CVE-2025-6170
Severity low
libxml2: Integer Overflow in xmlBuildQName() Leads to Stack Buffer Overflow in libxml2
CVE-2025-6021
Severity high
libarchive: Double free at archive_read_format_rar_seek_data() in archive_read_support_format_rar.c
CVE-2025-5914
Severity high
rsync: Info Leak via Uninitialized Stack Contents
CVE-2024-12085
Severity high
An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API…
CVE-2023-52355
Severity high
A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key…
CVE-2023-50781
Severity high
IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@…
CVE-2023-39417
Severity high
A flaw was found in OpenJPEG. A resource exhaustion can occur in the opj_t1_decode_cblks function in tcd.c through a crafted image file…
CVE-2023-39329
Severity medium
A flaw was found in OpenJPEG. Maliciously constructed pictures can cause the program to enter a large loop and continuously print warning…
CVE-2023-39327
Severity medium
A flaw was found in the mod_proxy_cluster in the Apache server. This issue may allow a malicious user to add a script in the 'alias'…
CVE-2023-6710
Severity medium
An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in environments which have millions of…
CVE-2023-6563
Severity high
A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A…
CVE-2023-6291
Severity high
A flaw was found in Keycloak that prevents certain schemes in redirects, but permits them if a wildcard is appended to the token. This…
CVE-2023-6134
Severity medium
A flaw was found in wildfly-core. A management user could use the resolve-expression in the HAL Interface to read possible sensitive…
CVE-2023-4061
Severity medium
A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the…
CVE-2023-1380
Severity high
A flaw was found in the Linux kernel. This flaw allows an attacker to crash the Linux kernel by simulating amateur radio from the user…
CVE-2022-1199
Severity high
OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of…
CVE-2020-6851
Severity high
Red Hat Libuser Race Condition Vulnerability
CVE-2015-3246
Severity high Exploited yes
The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx 8.1.2 and earlier allows remote attackers to execute…
CVE-2004-2771