Vulnerability index

Browse CVEs

20 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Heap-based Buffer OverflowCWE-122 × clear
MEDIUM 5.3 CVE-2026-14940 A heap-buffer-overflow flaw was found in 389 Directory Server (389-ds-base). When normalizing a Distinguished Name (DN) that contains a legacy-quoted… Directory Server Mitigation only Fix from $1,6002026-07-07 MEDIUM 5.9 CVE-2026-12725 A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies contain… Openshift Container Platform 2.93+ Fix from $1,6002026-06-22 MEDIUM 6.5 CVE-2026-9149 A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negat… Hardened Images after 0.7.36 Fix from $1,6002026-05-21 HIGH 7.8 CVE-2026-6846 A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Form… Hardened Images after 2.46 Fix from $1,9502026-04-22 HIGH 7.5 CVE-2026-5201 A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation … Enterprise Linux Mitigation only Fix from $1,9502026-03-31 HIGH 8.2 CVE-2025-32990 A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads ce… Openshift Container Platform Mitigation only Fix from $1,9502025-07-10 MEDIUM 6.6 CVE-2025-5915 A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potent… Openshift Container Platform 3.8.0+ Fix from $1,6002025-06-09 MEDIUM 5.5 CVE-2024-1062 A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than 256 chars in log_entry_attr. 389 Directory Server 2.2.0+ Fix from $1,6002024-02-12 HIGH 7.5 CVE-2023-52356 A segment fault (SEGV) flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFReadRGBATileExt() API. This flaw a… Enterprise Linux Patch available Fix from $1,9502024-01-25 HIGH 7.8 CVE-2023-4692 An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may allow an attacker to present a specially crafted NTFS filesys… Enterprise Linux 2.12+ Fix from $1,9502023-10-25 HIGH 7.8 CVE-2023-43787 A vulnerability was found in libX11 due to an integer overflow within the XCreateImage() function. This flaw allows a local user to trigger an intege… Enterprise Linux 1.8.7+ Fix from $1,9502023-10-10 MEDIUM 5.5 CVE-2022-25309 A heap-based buffer overflow flaw was found in the Fribidi package and affects the fribidi_cap_rtl_to_unicode() function of the fribidi-char-sets-cap… Enterprise Linux 1.0.12+ Fix from $1,6002022-09-06 HIGH 7.8 CVE-2020-25712 A flaw was found in xorg-x11-server before 1.20.10. A heap-buffer overflow in XkbSetDeviceInfo may lead to a privilege escalation vulnerability. The … Enterprise Linux 1.20.10+ Fix from $1,9502020-12-15 MEDIUM 6.0 CVE-2020-14310 There is an issue on grub2 before version 2.06 at function read_section_as_string(). It expects a font name to be at max UINT32_MAX - 1 length in byt… Enterprise Linux 2.06+ Fix from $1,6002020-07-31 MEDIUM 6.0 CVE-2020-14311 There is an issue with grub2 before version 2.06 while handling symlink on ext filesystems. A filesystem containing a symbolic link with an inode siz… Enterprise Linux 2.06+ Fix from $1,6002020-07-31 MEDIUM 6.0 CVE-2020-1711 An out-of-bounds heap buffer access flaw was found in the way the iSCSI Block driver in QEMU versions 2.12.0 before 4.2.1 handled a response coming f… Openstack 4.2.1+ Fix from $1,6002020-02-11 HIGH 8.8 CVE-2018-14653 The Gluster file system through versions 4.1.4 and 3.12 is vulnerable to a heap-based buffer overflow in the '__server_getspec' function via the 'gf_… Gluster Storage after 4.1.4 Fix from $1,9502018-10-31 HIGH 7.5 CVE-2018-1089 389-ds-base before versions 1.4.0.9, 1.3.8.1, 1.3.6.15 did not properly handle long search filters with characters needing escapes, possibly leading … Enterprise Linux Desktop 1.3.6.15 / 1.4.0.9+ Fix from $1,9502018-05-09 HIGH 7.5 CVE-2017-2591 389-ds-base before version 1.3.6 is vulnerable to an improperly NULL terminated array in the uniqueness_entry_to_config() function in the "attribute … Enterprise Linux 1.3.6+ Fix from $1,9502018-04-30 CRITICAL 9.8 CVE-2015-3113 KEVEPSS 100% Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.46… Enterprise Linux Desktop 11.2.202.468 / 13.0.0.296+ Fix from $2,3002015-06-23