Vulnerability index

Browse CVEs

116 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Directory Server MEDIUM 5.4
CVE-2026-12528

A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Access Control Instruction) strin…

Patch available
Fix from $1,600 2026-06-17
Enterprise Linux HIGH 7.8
CVE-2026-50264

An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DR…

Fix: 21.1.23 / 24.1.12+
Fix from $1,950 2026-06-05
Hardened Images HIGH 7.8
CVE-2026-48864

A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files du…

No fix yet
Fix from $1,950 2026-05-26
Enterprise Linux MEDIUM 5.5
CVE-2026-40919

A flaw was found in GIMP. This vulnerability, a buffer overflow in the `file-seattle-filmworks` plugin, can be exploited when a user opens a speciall…

Mitigation only
Fix from $1,600 2026-04-15
Enterprise Linux MEDIUM 5.5
CVE-2026-40916

A flaw was found in GIMP. A stack buffer overflow vulnerability in the TIM image loader's 4BPP decoding path allows a local user to cause a Denial of…

Mitigation only
Fix from $1,600 2026-04-15
Openshift Container Platform MEDIUM 6.7
CVE-2025-7519

A flaw was found in polkit. When processing an XML policy with 32 or more nested elements in depth, an out-of-bounds write can be triggered. This iss…

Patch available
Fix from $1,600 2025-07-14
Jboss Core Services HIGH 7.5
CVE-2025-6021

A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. …

No fix yet
Fix from $1,950 2025-06-12
Openshift Container Platform MEDIUM 5.0
CVE-2025-5917

A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes …

Fix: 3.8.0+
Fix from $1,600 2025-06-09
Openshift Container Platform HIGH 7.8
CVE-2024-45782

A flaw was found in the HFS filesystem. When reading an HFS volume's name at grub_fs_mount(), the HFS filesystem driver performs a strcpy() using the…

Fix: after 2.12
Fix from $1,950 2025-03-03
Enterprise Linux HIGH 7.8
CVE-2025-26595

A buffer overflow flaw was found in X.Org and Xwayland. The code in XkbVModMaskText() allocates a fixed-sized buffer on the stack and copies the name…

Fix: 21.1.16 / 24.1.6+
Fix from $1,950 2025-02-25
Enterprise Linux HIGH 7.8
CVE-2025-26596

A heap overflow flaw was found in X.Org and Xwayland. The computation of the length in XkbSizeKeySyms() differs from what is written in XkbWriteKeySy…

Fix: 21.1.16 / 24.1.6+
Fix from $1,950 2025-02-25
Enterprise Linux HIGH 7.8
CVE-2025-26598

An out-of-bounds write flaw was found in X.Org and Xwayland. The function GetBarrierDevice() searches for the pointer device based on its device ID a…

Fix: 21.1.16 / 24.1.6+
Fix from $1,950 2025-02-25
Openshift MEDIUM 6.7
CVE-2024-45777

A flaw was found in grub2. The calculation of the translation buffer when reading a language .mo file in grub_gettext_getstr_from_position() may over…

Fix: after 2.12
Fix from $1,600 2025-02-19
Shim HIGH 7.4
CVE-2023-40548

A buffer overflow was found in Shim in the 32-bit system. The overflow happens due to an addition operation involving a user-controlled value parsed …

Fix: 15.8+
Fix from $1,950 2024-01-29
Enterprise Linux HIGH 7.5
CVE-2023-52356

A segment fault (SEGV) flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFReadRGBATileExt() API. This flaw a…

Patch available
Fix from $1,950 2024-01-25
Enterprise Linux HIGH 7.5
CVE-2023-52355

An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw al…

Fix: 4.6.0+
Fix from $1,950 2024-01-25
Shim HIGH 8.3
CVE-2023-40547

A remote code execution vulnerability was found in Shim. The Shim boot support trusts attacker-controlled values when parsing an HTTP response. This …

Fix: 15.8+
Fix from $1,950 2024-01-25
Enterprise Linux MEDIUM 5.3
CVE-2023-6693

A stack based buffer overflow was found in the virtio-net device of QEMU. This issue occurs when flushing TX in the virtio_net_flush_tx function if g…

Fix: 8.2.1+
Fix from $1,600 2024-01-02
Enterprise Linux MEDIUM 5.5
CVE-2023-3164

A heap-buffer-overflow vulnerability was found in LibTIFF, in extractImageSection() at tools/tiffcrop.c:7916 and tools/tiffcrop.c:7801. This flaw all…

Fix: 4.6.0+
Fix from $1,600 2023-11-02
Enterprise Linux HIGH 7.8
CVE-2023-5367

A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect calculation of a buffer offset when copying data s…

Patch available
Fix from $1,950 2023-10-25
Enterprise Linux HIGH 7.8
CVE-2023-4692

An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may allow an attacker to present a specially crafted NTFS filesys…

Fix: 2.12+
Fix from $1,950 2023-10-25
Enterprise Linux MEDIUM 5.5
CVE-2023-43785

A vulnerability was found in libX11 due to a boundary condition within the _XkbReadKeySyms() function. This flaw allows a local user to trigger an ou…

Fix: 1.8.7+
Fix from $1,600 2023-10-10
Codeready Linux Builder MEDIUM 5.5
CVE-2023-4042

A flaw was found in ghostscript. The fix for CVE-2020-16305 in ghostscript was not included in RHSA-2021:1852-06 advisory as it was claimed to be. Th…

No fix yet
Fix from $1,600 2023-08-23
Shim HIGH 7.8
CVE-2022-28737

There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables; The handle_image() function takes into acc…

Fix: 15.6+
Fix from $1,950 2023-07-20
Enterprise Linux HIGH 7.5
CVE-2023-3138

A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not check that the values provided …

Fix: 1.8.6+
Fix from $1,950 2023-06-28
Enterprise Linux HIGH 7.8
CVE-2022-3715

A flaw was found in the bash package, where a heap-buffer overflow can occur in valid parameter_transform. This issue may lead to memory problems.

Fix: 5.1.8+
Fix from $1,950 2023-01-05
Enterprise Linux HIGH 7.1
CVE-2022-3775

When rendering certain unicode sequences, grub2's font code doesn't proper validate if the informed glyph's width and height is constrained within bi…

Fix: after 2.06
Fix from $1,950 2022-12-19
Enterprise Linux HIGH 7.8
CVE-2022-25308

A stack-based buffer overflow flaw was found in the Fribidi package. This flaw allows an attacker to pass a specially crafted file to the Fribidi app…

Fix: 1.0.12+
Fix from $1,950 2022-09-06
Enterprise Linux MEDIUM 5.5
CVE-2022-25309

A heap-based buffer overflow flaw was found in the Fribidi package and affects the fribidi_cap_rtl_to_unicode() function of the fribidi-char-sets-cap…

Fix: 1.0.12+
Fix from $1,600 2022-09-06
Enterprise Linux HIGH 7.8
CVE-2022-0135

An out-of-bounds write issue was found in the VirGL virtual OpenGL renderer (virglrenderer). This flaw allows a malicious guest to create a specially…

Fix: 0.10.0+
Fix from $1,950 2022-08-25