Vulnerability index

Browse CVEs

2,581 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2026-12969 An out-of-bounds read vulnerability exists in dnsmasq's find_soa() function in src/rfc1035.c. When parsing NS section records, extract_name() is call… Enterprise Linux 2.93+ Fix from $1,6002026-06-23 MEDIUM 6.8 CVE-2026-10609 A missing authorization flaw was found in the OpenShift Cluster Logging Operator. The operator creates and forwards ServiceAccount tokens to output d… Cluster Logging Operator Mitigation only Fix from $1,6002026-06-23 MEDIUM 6.1 CVE-2026-55655 A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible… Enterprise Linux Mitigation only Fix from $1,6002026-06-23 MEDIUM 6.5 CVE-2026-55653 A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path… Hardened Images No fix yet Fix from $1,6002026-06-23 MEDIUM 5.9 CVE-2026-12725 A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies contain… Openshift Container Platform 2.93+ Fix from $1,6002026-06-22 HIGH 8.8 CVE-2026-54099 A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a … Openshift Container Platform 4.22.1+ Fix from $1,9502026-06-22 HIGH 8.3 CVE-2026-54100 A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Windows … Openshift Container Platform after 4.22.1 Fix from $1,9502026-06-22 MEDIUM 5.0 CVE-2026-11791 A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function unconditionally frees attribute syntax information… Directory Server Mitigation only Fix from $1,6002026-06-18 HIGH 7.5 CVE-2026-47774 Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.35.11, 1.36.7, 1.37.3, and 1.38.1, a vulne… Openshift Service Mesh 1.35.11 / 1.36.7+ Fix from $1,9502026-06-17 MEDIUM 5.4 CVE-2026-12528 A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Access Control Instruction) strin… Directory Server Patch available Fix from $1,6002026-06-17 HIGH 8.1 CVE-2026-1767 A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component. A remote attacker could… Enterprise Linux No fix yet Fix from $1,9502026-06-16 MEDIUM 6.1 CVE-2026-1766 A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracker-extract-mp3 component. This… Enterprise Linux No fix yet Fix from $1,6002026-06-16 MEDIUM 5.6 CVE-2026-1764 A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor. When processing specially crafted MP3 files containing ID3v… Enterprise Linux No fix yet Fix from $1,6002026-06-16 HIGH 7.7 CVE-2026-44495 Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets… Advanced Cluster Management For Kubernetes 2.13.9 / 4.10.3+ Fix from $1,9502026-06-11 HIGH 7.5 CVE-2025-71319 image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by suppl… Discovery 1.4.2+ Fix from $1,9502026-06-09 MEDIUM 6.5 CVE-2026-11789 A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when computing salt length from a craf… Directory Server Mitigation only Fix from $1,6002026-06-09 HIGH 7.5 CVE-2026-11788 A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing… Directory Server Mitigation only Fix from $1,9502026-06-09 MEDIUM 6.5 CVE-2026-11786 A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when processing attribute types with trailing semicolon… Directory Server Mitigation only Fix from $1,6002026-06-09 MEDIUM 6.3 CVE-2026-11787 A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a he… Directory Server Mitigation only Fix from $1,6002026-06-09 MEDIUM 6.5 CVE-2026-11611 A flaw was found in 389 Directory Server. The Content Synchronization persistent search plugin allows unbounded memory growth when an authenticated c… Directory Server Mitigation only Fix from $1,6002026-06-08 HIGH 7.8 CVE-2026-50264 An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DR… Enterprise Linux 21.1.23 / 24.1.12+ Fix from $1,9502026-06-05 HIGH 7.8 CVE-2026-50258 A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers sized XkbMaxShiftLevel * Xkb… Enterprise Linux 21.1.23 / 24.1.12+ Fix from $1,9502026-06-05 HIGH 7.8 CVE-2026-50259 A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. _XkbSetMapChecks() declares a fixed-size stack buffer mapWidths[256]… Enterprise Linux 21.1.23 / 24.1.12+ Fix from $1,9502026-06-05 HIGH 7.8 CVE-2026-50260 A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple SyncCounters and awaits on those … Enterprise Linux 21.1.23 / 24.1.12+ Fix from $1,9502026-06-05 HIGH 7.8 CVE-2026-50261 A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a … Enterprise Linux 21.1.23 / 24.1.12+ Fix from $1,9502026-06-05 MEDIUM 5.5 CVE-2026-50262 An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size validation check can re… Enterprise Linux 21.1.23 / 24.1.12+ Fix from $1,6002026-06-05 MEDIUM 5.5 CVE-2026-50263 A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-after-free read after changing … Enterprise Linux 21.1.23 / 24.1.12+ Fix from $1,6002026-06-05 HIGH 7.8 CVE-2026-50256 A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the libXfont2 library's maximum … Enterprise Linux 21.1.23 / 24.1.12+ Fix from $1,9502026-06-05 HIGH 7.8 CVE-2026-50257 A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multiple fence triggers can trigger… Enterprise Linux 21.1.23 / 24.1.12+ Fix from $1,9502026-06-05 HIGH 8.8 CVE-2026-1784 The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on… Openshift Container Platform Mitigation only Fix from $1,9502026-06-02