Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.5 CVE-2025-46399 A flaw was found in fig2dev. This vulnerability allows availability via local input manipulation via genge_itp_spline function. Enterprise Linux No fix yet Fix from $1,6002025-04-23 MEDIUM 5.5 CVE-2025-46400 In xfig diagramming tool, a segmentation fault while running fig2dev allows an attacker to availability via local input manipulation via read_arcobje… Enterprise Linux No fix yet Fix from $1,6002025-04-23 HIGH 7.8 CVE-2025-46397 A flaw was found in xfig. This vulnerability allows possible code execution via local input manipulation via bezier_spline function. Enterprise Linux No fix yet Fix from $1,9502025-04-23 MEDIUM 5.5 CVE-2025-46398 In xfig diagramming tool, a stack-overflow while running fig2dev allows memory corruption via local input manipulation via read_objects function. Enterprise Linux No fix yet Fix from $1,6002025-04-23 MEDIUM 6.5 CVE-2025-2784 A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_insight_whitespace() function. L… Codeready Linux Builder No fix yet Fix from $1,6002025-04-03 HIGH 8.1 CVE-2025-23368 A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attem… Wildfly Core 31.0.3+ Fix from $1,9502025-03-04 HIGH 7.8 CVE-2025-0678 A flaw was found in grub2. When reading data from a squash4 filesystem, grub's squash4 fs module uses user-controlled parameters from the filesystem … Openshift Container Platform after 2.12 Fix from $1,9502025-03-03 HIGH 7.8 CVE-2024-45782 A flaw was found in the HFS filesystem. When reading an HFS volume's name at grub_fs_mount(), the HFS filesystem driver performs a strcpy() using the… Openshift Container Platform after 2.12 Fix from $1,9502025-03-03 MEDIUM 5.5 CVE-2024-45778 A stack overflow flaw was found when reading a BFS file system. A crafted BFS filesystem may lead to an uncontrolled loop, causing grub2 to crash. Openshift Container Platform after 2.12 Fix from $1,6002025-03-03 HIGH 7.8 CVE-2025-26599 An access to an uninitialized pointer flaw was found in X.Org and Xwayland. The function compCheckRedirect() may fail if it cannot allocate the backi… Enterprise Linux 21.1.16 / 24.1.6+ Fix from $1,9502025-02-25 HIGH 7.8 CVE-2025-26600 A use-after-free flaw was found in X.Org and Xwayland. When a device is removed while still frozen, the events queued for that device remain while th… Enterprise Linux 21.1.16 / 24.1.6+ Fix from $1,9502025-02-25 HIGH 7.8 CVE-2025-26601 A use-after-free flaw was found in X.Org and Xwayland. When changing an alarm, the values of the change mask are evaluated one after the other, chang… Enterprise Linux 21.1.16 / 24.1.6+ Fix from $1,9502025-02-25 HIGH 7.8 CVE-2025-26594 A use-after-free flaw was found in X.Org and Xwayland. The root cursor is referenced in the X server as a global variable. If a client frees the root… Enterprise Linux 21.1.16 / 24.1.6+ Fix from $1,9502025-02-25 HIGH 7.8 CVE-2025-26595 A buffer overflow flaw was found in X.Org and Xwayland. The code in XkbVModMaskText() allocates a fixed-sized buffer on the stack and copies the name… Enterprise Linux 21.1.16 / 24.1.6+ Fix from $1,9502025-02-25 HIGH 7.8 CVE-2025-26596 A heap overflow flaw was found in X.Org and Xwayland. The computation of the length in XkbSizeKeySyms() differs from what is written in XkbWriteKeySy… Enterprise Linux 21.1.16 / 24.1.6+ Fix from $1,9502025-02-25 HIGH 7.8 CVE-2025-26597 A buffer overflow flaw was found in X.Org and Xwayland. If XkbChangeTypesOfKey() is called with a 0 group, it will resize the key symbols table to 0 … Enterprise Linux 21.1.16 / 24.1.6+ Fix from $1,9502025-02-25 HIGH 7.8 CVE-2025-26598 An out-of-bounds write flaw was found in X.Org and Xwayland. The function GetBarrierDevice() searches for the pointer device based on its device ID a… Enterprise Linux 21.1.16 / 24.1.6+ Fix from $1,9502025-02-25 MEDIUM 6.7 CVE-2024-45777 A flaw was found in grub2. The calculation of the translation buffer when reading a language .mo file in grub_gettext_getstr_from_position() may over… Openshift after 2.12 Fix from $1,6002025-02-19 MEDIUM 6.8 CVE-2025-26465EPSS 7% A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious mach… Openshift Container Platform after 9.8 Fix from $1,6002025-02-18 MEDIUM 6.5 CVE-2025-23367 A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured usin… Jboss Enterprise Application Platform 7.4.21 / 8.0.7+ Fix from $1,6002025-01-30 HIGH 7.1 CVE-2025-0752 A flaw was found in OpenShift Service Mesh 2.6.3 and 2.5.6. Rate-limiter avoidance, access-control bypass, CPU and memory exhaustion, and replay atta… Openshift Service Mesh Mitigation only Fix from $1,9502025-01-28 HIGH 7.5 CVE-2024-12085EPSS 9% A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length… Openshift No fix yet Fix from $1,9502025-01-14 HIGH 7.5 CVE-2024-12088 A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from t… Discovery Mitigation only Fix from $1,9502025-01-14 MEDIUM 6.8 CVE-2024-12086 A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when f… Openshift Container Platform 24.11+ Fix from $1,6002025-01-14 MEDIUM 5.3 CVE-2024-49394 In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacker to reuse an unencrypted but… Enterprise Linux Patch available Fix from $1,6002024-11-12 MEDIUM 5.3 CVE-2024-49395 In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipien… Enterprise Linux Patch available Fix from $1,6002024-11-12 MEDIUM 6.5 CVE-2024-49393 In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to cha… Enterprise Linux Patch available Fix from $1,6002024-11-12 MEDIUM 6.1 CVE-2023-1932 A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, w… Codeready Studio 6.2+ Fix from $1,6002024-11-07 HIGH 7.1 CVE-2024-51127 An issue in the createTempFile method of hornetq v2.4.9 allows attackers to arbitrarily overwrite files or access sensitive information. Hornetq after 2.4.9 Fix from $1,9502024-11-04 HIGH 7.5 CVE-2024-10295 A flaw was found in Gateway. Sending a non-base64 'basic' auth with special characters can cause APICast to incorrectly authenticate a request. A mal… 3scale Api Management Mitigation only Fix from $1,9502024-10-24