Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enterprise Linux MEDIUM 5.5
CVE-2025-46399

A flaw was found in fig2dev. This vulnerability allows availability via local input manipulation via genge_itp_spline function.

No fix yet
Fix from $1,600 2025-04-23
Enterprise Linux MEDIUM 5.5
CVE-2025-46400

In xfig diagramming tool, a segmentation fault while running fig2dev allows an attacker to availability via local input manipulation via read_arcobje…

No fix yet
Fix from $1,600 2025-04-23
Enterprise Linux HIGH 7.8
CVE-2025-46397

A flaw was found in xfig. This vulnerability allows possible code execution via local input manipulation via bezier_spline function.

No fix yet
Fix from $1,950 2025-04-23
Enterprise Linux MEDIUM 5.5
CVE-2025-46398

In xfig diagramming tool, a stack-overflow while running fig2dev allows memory corruption via local input manipulation via read_objects function.

No fix yet
Fix from $1,600 2025-04-23
Codeready Linux Builder MEDIUM 6.5
CVE-2025-2784

A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_insight_whitespace() function. L…

No fix yet
Fix from $1,600 2025-04-03
Wildfly Core HIGH 8.1
CVE-2025-23368

A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attem…

Fix: 31.0.3+
Fix from $1,950 2025-03-04
Openshift Container Platform HIGH 7.8
CVE-2025-0678

A flaw was found in grub2. When reading data from a squash4 filesystem, grub's squash4 fs module uses user-controlled parameters from the filesystem …

Fix: after 2.12
Fix from $1,950 2025-03-03
Openshift Container Platform HIGH 7.8
CVE-2024-45782

A flaw was found in the HFS filesystem. When reading an HFS volume's name at grub_fs_mount(), the HFS filesystem driver performs a strcpy() using the…

Fix: after 2.12
Fix from $1,950 2025-03-03
Openshift Container Platform MEDIUM 5.5
CVE-2024-45778

A stack overflow flaw was found when reading a BFS file system. A crafted BFS filesystem may lead to an uncontrolled loop, causing grub2 to crash.

Fix: after 2.12
Fix from $1,600 2025-03-03
Enterprise Linux HIGH 7.8
CVE-2025-26599

An access to an uninitialized pointer flaw was found in X.Org and Xwayland. The function compCheckRedirect() may fail if it cannot allocate the backi…

Fix: 21.1.16 / 24.1.6+
Fix from $1,950 2025-02-25
Enterprise Linux HIGH 7.8
CVE-2025-26600

A use-after-free flaw was found in X.Org and Xwayland. When a device is removed while still frozen, the events queued for that device remain while th…

Fix: 21.1.16 / 24.1.6+
Fix from $1,950 2025-02-25
Enterprise Linux HIGH 7.8
CVE-2025-26601

A use-after-free flaw was found in X.Org and Xwayland. When changing an alarm, the values of the change mask are evaluated one after the other, chang…

Fix: 21.1.16 / 24.1.6+
Fix from $1,950 2025-02-25
Enterprise Linux HIGH 7.8
CVE-2025-26594

A use-after-free flaw was found in X.Org and Xwayland. The root cursor is referenced in the X server as a global variable. If a client frees the root…

Fix: 21.1.16 / 24.1.6+
Fix from $1,950 2025-02-25
Enterprise Linux HIGH 7.8
CVE-2025-26595

A buffer overflow flaw was found in X.Org and Xwayland. The code in XkbVModMaskText() allocates a fixed-sized buffer on the stack and copies the name…

Fix: 21.1.16 / 24.1.6+
Fix from $1,950 2025-02-25
Enterprise Linux HIGH 7.8
CVE-2025-26596

A heap overflow flaw was found in X.Org and Xwayland. The computation of the length in XkbSizeKeySyms() differs from what is written in XkbWriteKeySy…

Fix: 21.1.16 / 24.1.6+
Fix from $1,950 2025-02-25
Enterprise Linux HIGH 7.8
CVE-2025-26597

A buffer overflow flaw was found in X.Org and Xwayland. If XkbChangeTypesOfKey() is called with a 0 group, it will resize the key symbols table to 0 …

Fix: 21.1.16 / 24.1.6+
Fix from $1,950 2025-02-25
Enterprise Linux HIGH 7.8
CVE-2025-26598

An out-of-bounds write flaw was found in X.Org and Xwayland. The function GetBarrierDevice() searches for the pointer device based on its device ID a…

Fix: 21.1.16 / 24.1.6+
Fix from $1,950 2025-02-25
Openshift MEDIUM 6.7
CVE-2024-45777

A flaw was found in grub2. The calculation of the translation buffer when reading a language .mo file in grub_gettext_getstr_from_position() may over…

Fix: after 2.12
Fix from $1,600 2025-02-19
Openshift Container Platform MEDIUM 6.8
CVE-2025-26465EPSS 7%

A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious mach…

Fix: after 9.8
Fix from $1,600 2025-02-18
Jboss Enterprise Application Platform MEDIUM 6.5
CVE-2025-23367

A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured usin…

Fix: 7.4.21 / 8.0.7+
Fix from $1,600 2025-01-30
Openshift Service Mesh HIGH 7.1
CVE-2025-0752

A flaw was found in OpenShift Service Mesh 2.6.3 and 2.5.6. Rate-limiter avoidance, access-control bypass, CPU and memory exhaustion, and replay atta…

Mitigation only
Fix from $1,950 2025-01-28
Openshift HIGH 7.5
CVE-2024-12085EPSS 9%

A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length…

No fix yet
Fix from $1,950 2025-01-14
Discovery HIGH 7.5
CVE-2024-12088

A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from t…

Mitigation only
Fix from $1,950 2025-01-14
Openshift Container Platform MEDIUM 6.8
CVE-2024-12086

A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when f…

Fix: 24.11+
Fix from $1,600 2025-01-14
Enterprise Linux MEDIUM 5.3
CVE-2024-49394

In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacker to reuse an unencrypted but…

Patch available
Fix from $1,600 2024-11-12
Enterprise Linux MEDIUM 5.3
CVE-2024-49395

In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipien…

Patch available
Fix from $1,600 2024-11-12
Enterprise Linux MEDIUM 6.5
CVE-2024-49393

In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to cha…

Patch available
Fix from $1,600 2024-11-12
Codeready Studio MEDIUM 6.1
CVE-2023-1932

A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, w…

Fix: 6.2+
Fix from $1,600 2024-11-07
Hornetq HIGH 7.1
CVE-2024-51127

An issue in the createTempFile method of hornetq v2.4.9 allows attackers to arbitrarily overwrite files or access sensitive information.

Fix: after 2.4.9
Fix from $1,950 2024-11-04
3scale Api Management HIGH 7.5
CVE-2024-10295

A flaw was found in Gateway. Sending a non-base64 'basic' auth with special characters can cause APICast to incorrectly authenticate a request. A mal…

Mitigation only
Fix from $1,950 2024-10-24