Vulnerability index

Browse CVEs

108 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
HIGH 7.8 CVE-2025-26597 A buffer overflow flaw was found in X.Org and Xwayland. If XkbChangeTypesOfKey() is called with a 0 group, it will resize the key symbols table to 0 … Enterprise Linux 21.1.16 / 24.1.6+ Fix from $1,9502025-02-25 MEDIUM 6.4 CVE-2023-40661 Several memory vulnerabilities were identified within the OpenSC packages, particularly in the card enrollment process using pkcs15-init when a user … Enterprise Linux after 0.23.0 Fix from $1,6002023-11-06 HIGH 7.5 CVE-2023-3138 A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not check that the values provided … Enterprise Linux 1.8.6+ Fix from $1,9502023-06-28 HIGH 7.1 CVE-2023-2977 A vulnerbility was found in OpenSC. This security flaw cause a buffer overrun vulnerability in pkcs15 cardos_have_verifyrc_package. The attacker can … Enterprise Linux Patch available Fix from $1,9502023-06-01 HIGH 8.8 CVE-2019-8720 KEV A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution.… Codeready Linux Builder Mitigation only Fix from $1,9502023-03-06 HIGH 7.8 CVE-2022-3715 A flaw was found in the bash package, where a heap-buffer overflow can occur in valid parameter_transform. This issue may lead to memory problems. Enterprise Linux 5.1.8+ Fix from $1,9502023-01-05 MEDIUM 5.5 CVE-2022-25310 A segmentation fault (SEGV) flaw was found in the Fribidi package and affects the fribidi_remove_bidi_marks() function of the lib/fribidi.c file. Thi… Enterprise Linux 1.0.12+ Fix from $1,6002022-09-06 MEDIUM 6.5 CVE-2021-3611 A stack overflow vulnerability was found in the Intel HD Audio device (intel-hda) of QEMU. A malicious guest could use this flaw to crash the QEMU pr… Enterprise Linux 7.0.0+ Fix from $1,6002022-05-11 CRITICAL 9.8 CVE-2021-20325 Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5.0, causes a security regress… Enterprise Linux Mitigation only Fix from $2,3002022-02-18 MEDIUM 5.5 CVE-2021-3605 There's a flaw in OpenEXR's rleUncompress functionality in versions prior to 3.0.5. An attacker who is able to submit a crafted file to an applicatio… Enterprise Linux 3.0.5+ Fix from $1,6002021-08-25 HIGH 8.8 CVE-2021-3570 A flaw was found in the ptp4l program of the linuxptp package. A missing length check when forwarding a PTP message between ports allows a remote att… Enterprise Linux 1.5.1 / 1.6.1+ Fix from $1,9502021-07-09 HIGH 7.1 CVE-2021-3571 A flaw was found in the ptp4l program of the linuxptp package. When ptp4l is operating on a little-endian architecture as a PTP transparent clock, a … Enterprise Linux 2.0.1 / 3.1.1+ Fix from $1,9502021-07-09 MEDIUM 5.5 CVE-2021-3598 There's a flaw in OpenEXR's ImfDeepScanLineInputFile functionality in versions prior to 3.0.5. An attacker who is able to submit a crafted file to an… Enterprise Linux 3.0.5+ Fix from $1,6002021-07-06 MEDIUM 6.5 CVE-2021-3559 A flaw was found in libvirt in the virConnectListAllNodeDevices API in versions before 7.0.0. It only affects hosts with a PCI device and driver that… Libvirt 7.0.0+ Fix from $1,6002021-05-24 MEDIUM 5.7 CVE-2021-3409 The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus making QEMU vulnerable to the out-of-bounds read/write access issues pr… Enterprise Linux after 5.2.0 Fix from $1,6002021-03-23 MEDIUM 5.5 CVE-2020-35521 A flaw was found in libtiff. Due to a memory allocation failure in tif_read.c, a crafted TIFF file can lead to an abort, resulting in denial of servi… Enterprise Linux 4.2.0+ Fix from $1,6002021-03-09 HIGH 7.8 CVE-2021-3404 In ytnef 1.9.3, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a h… Enterprise Linux No fix yet Fix from $1,9502021-03-04 HIGH 7.8 CVE-2017-5332 The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cau… Enterprise Linux Patch available Fix from $1,9502019-11-04 HIGH 7.8 CVE-2012-6711 A heap-based buffer overflow exists in GNU Bash before 4.3 when wide characters, not supported by the current locale set in the LC_CTYPE environment … Enterprise Linux after 4.3 Fix from $1,9502019-06-18 HIGH 7.5 CVE-2019-10245 In Eclipse OpenJ9 prior to the 0.14.0 release, the Java bytecode verifier incorrectly allows a method to execute past the end of bytecode array causi… Satellite 0.14.0+ Fix from $1,9502019-04-19 CRITICAL 9.8 CVE-2018-12547 In Eclipse OpenJ9, prior to the 0.12.0 release, the jio_snprintf() and jio_vsnprintf() native methods ignored the length parameter. This affects exis… Satellite 0.12.0+ Fix from $2,3002019-02-11 MEDIUM 6.5 CVE-2018-14652 The Gluster file system through versions 3.12 and 4.1.4 is vulnerable to a buffer overflow in the 'features/index' translator via the code handling t… Gluster Storage after 4.1.8 Fix from $1,6002018-10-31 CRITICAL 9.8 CVE-2018-12376 Memory safety bugs present in Firefox 61 and Firefox ESR 60.1. Some of these bugs showed evidence of memory corruption and we presume that with enoug… Enterprise Linux Desktop Mitigation only Fix from $2,3002018-10-18 HIGH 8.8 CVE-2018-12359 A buffer overflow can occur when rendering canvas content while adjusting the height and width of the canvas element dynamically, causing data to be … Enterprise Linux Desktop Mitigation only Fix from $1,9502018-10-18 MEDIUM 6.5 CVE-2017-15416 Heap buffer overflow in Blob API in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafte… Enterprise Linux Desktop 63.0.3239.84+ Fix from $1,6002018-08-28 CRITICAL 9.8 CVE-2017-15101 A missing patch for a stack-based buffer overflow in findTable() was found in Red Hat version of liblouis before 2.5.4. An attacker could cause a den… Enterprise Linux Desktop 2.5.4+ Fix from $2,3002018-07-27 MEDIUM 5.5 CVE-2018-10872 A flaw was found in the way the Linux kernel handled exceptions delivered after a stack switch operation via Mov SS or Pop SS instructions. During th… Enterprise Linux Patch available Fix from $1,6002018-07-10 MEDIUM 6.5 CVE-2017-2668 389-ds-base before versions 1.3.5.17 and 1.3.6.10 is vulnerable to an invalid pointer dereference in the way LDAP bind requests are handled. A remote… Enterprise Linux Desktop 1.3.5.17 / 1.3.6.10+ Fix from $1,6002018-06-22 HIGH 7.8 CVE-2018-5848 In the function wmi_set_ie(), the length validation code does not handle unsigned integer overflow properly. As a result, a large value of the 'ie_le… Virtualization Host Patch available Fix from $1,9502018-06-12 CRITICAL 9.8 CVE-2018-5183 Mozilla developers backported selected changes in the Skia library. These changes correct memory corruption issues including invalid buffer reads and… Enterprise Linux Desktop Mitigation only Fix from $2,3002018-06-11