Export limit exceeded: 16856 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (16856 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-103641 | 1 Redhat | 1 Enterprise Linux | 2026-10-01 | 5.5 Medium |
| A flaw was found in GEGL. The Radiance HDR loader reads past the end of a memory-mapped image when an uncompressed scanline is shorter than the width declared in the file header. Opening a crafted HDR file crashes the application that uses the loader. | ||||
| CVE-2026-88924 | 2 Gnome, Redhat | 2 Gvfs, Enterprise Linux | 2026-10-01 | 7 High |
| A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory. A local attacker can exploit this via a Time-of-Check Time-of-Use (TOCTOU) race condition and exchange the socket pathname with a symbolic link pointing to an arbitrary root-owned file (such as /etc/pam.d/su). The daemon subsequently follows the symlink and changes the ownership of the targeted root-owned file to the attacker's user ID. This allows an authenticated local attacker to modify critical system files, leading to a full local privilege escalation to root. | ||||
| CVE-2026-84268 | 1 Redhat | 1 Enterprise Linux | 2026-09-30 | 8.8 High |
| A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the allocated buffer size, causing the operation to write past the intended boundaries. This issue allows a malicious server to corrupt adjacent heap memory in the gvfsd-sftp process, resulting in a denial of service as the process aborts upon detecting the heap corruption or potentially allowing arbitrary code execution. | ||||
| CVE-2026-16529 | 1 Redhat | 7 Enterprise Linux, Enterprise Linux Eus, Openshift and 4 more | 2026-09-30 | 7.5 High |
| A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network packets during PDU processing or SASL negotiation. This permanently blinds the affected daemon, resulting in a total denial of service (DoS) for subsequent packet reads. | ||||
| CVE-2026-16527 | 1 Redhat | 7 Enterprise Linux, Enterprise Linux Eus, Openshift and 4 more | 2026-09-30 | 7.3 High |
| An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover. | ||||
| CVE-2026-16526 | 1 Redhat | 7 Enterprise Linux, Enterprise Linux Eus, Openshift and 4 more | 2026-09-30 | 8.8 High |
| A flaw in the PCP linux_sockets module exposes an unsecured internal connection. An attacker with initial code execution can exploit this to escalate privileges and execute arbitrary commands as root. | ||||
| CVE-2026-16524 | 1 Redhat | 7 Enterprise Linux, Enterprise Linux Eus, Openshift and 4 more | 2026-09-30 | 7.8 High |
| A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric. This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh. | ||||
| CVE-2026-83596 | 1 Redhat | 1 Enterprise Linux | 2026-09-30 | 8.8 High |
| A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling. | ||||
| CVE-2026-78376 | 1 Redhat | 1 Enterprise Linux | 2026-09-30 | 8.8 High |
| A flaw was found in WebKitGTK. Processing malicious web content can cause a use-after-free issue due to improper memory handling and result in memory corruption. | ||||
| CVE-2026-97026 | 2 Flatpak, Redhat | 2 Flatpak, Enterprise Linux | 2026-09-30 | 3.9 Low |
| Flatpak creates temporary child repository directories under the user cache with world-writable permissions (0777). On multi-user systems with a permissive umask, other local users could read or modify the temporary directory used while installing apps or runtimes, potentially causing installation failures (denial of service); tampered content would fail signature/digest verification rather than being trusted. | ||||
| CVE-2026-96281 | 2 Flatpak, Redhat | 2 Flatpak, Enterprise Linux | 2026-09-30 | 6.2 Medium |
| On a multi-user system, a user with an active local login session could downgrade a system-wide Flatpak app to an older version by removing the app's remote ref via the unprivileged system-helper RemoveLocalRef method, causing the anti-downgrade check to fail to find a reference date. A malicious local user could use this to expose other users of the same system to an app version with unfixed vulnerabilities. | ||||
| CVE-2026-102559 | 2 Libsoup, Redhat | 2 Libsoup, Enterprise Linux | 2026-09-30 | 8.6 High |
| A flaw was found in libsoup. When constructing a masked WebSocket client frame for a very large outgoing payload, size values passed to GByteArray allocation APIs could be truncated while the masking routine still used the full length, causing a heap buffer overflow. | ||||
| CVE-2026-102557 | 2 Libsoup, Redhat | 2 Libsoup, Enterprise Linux | 2026-09-30 | 8.6 High |
| A flaw was found in libsoup. When reassembling fragmented WebSocket messages into a GByteArray, libsoup did not adequately cap total message size against the limits of the underlying buffer type. A remote peer could send fragments that caused size truncation while the implementation still used the full length, leading to heap corruption or a crash. | ||||
| CVE-2026-102473 | 2 Dash, Redhat | 2 Dash, Enterprise Linux | 2026-09-30 | 5.5 Medium |
| A flaw was found in dash. When built without libc fnmatch, the internal pmatch() matcher implements * by unbounded recursion over candidate positions. A local user who can plant filenames, or otherwise feed that matcher, can make a short multi-star pattern such as *.*.*.*.*.tar.gz consume excessive CPU. | ||||
| CVE-2026-102556 | 2 Libsoup, Redhat | 2 Libsoup, Enterprise Linux | 2026-09-30 | 8.6 High |
| A flaw was found in libsoup. When handling an incoming WebSocket Pong frame, SoupWebsocketConnection emitted the ::pong signal with a GByteArray pointer even though the signal is declared to pass a GBytes. Applications connecting a handler that follows the documented GBytes API can trigger heap corruption or a crash upon receiving a crafted Pong. | ||||
| CVE-2026-102555 | 2 Libsoup, Redhat | 2 Libsoup, Enterprise Linux | 2026-09-30 | 8.2 High |
| A flaw was found in libsoup. The soup_uri_decode_data_uri() function incorrectly treated base64 data-URI payloads as NUL-terminated strings when calling g_base64_decode_inplace(). If the percent-decoded payload contained embedded NUL bytes, the decoded length could remain uninitialized and be used as the size of the returned GBytes. This can lead to an out-of-bounds read or application crash when processing a crafted data URI. | ||||
| CVE-2026-102558 | 2 Libsoup, Redhat | 2 Libsoup, Enterprise Linux | 2026-09-30 | 8.6 High |
| A flaw was found in libsoup. When max-incoming-payload-size is unlimited (0), SoupWebsocketConnection could grow its incoming GByteArray based on an attacker-controlled frame length until the length wrapped, causing a heap buffer overflow while reading frame data. | ||||
| CVE-2026-102560 | 2 Libsoup, Redhat | 2 Libsoup, Enterprise Linux | 2026-09-30 | 8.6 High |
| A flaw was found in libsoup. When the permessage-deflate WebSocket extension compresses a very large outgoing message, truncated size calculations used for GByteArray growth could wrap, causing zlib to write past the allocated buffer and resulting in a heap buffer overflow. | ||||
| CVE-2026-103399 | 1 Redhat | 1 Enterprise Linux | 2026-09-30 | 5.3 Medium |
| A flaw was found in SoupServer (libsoup). When an HTTP/1.x client sends a request with Expect: 100-continue and a request body, and SoupServer returns an early final (non-1xx) response before the body is read, the server neither drains the declared body bytes nor closes the connection. On a keep-alive connection, those leftover bytes are interpreted as a subsequent HTTP request. A remote, unauthenticated attacker can place a complete HTTP request in the body and cause SoupServer to process that smuggled request, leading to unintended request handling. | ||||
| CVE-2023-39417 | 3 Debian, Postgresql, Redhat | 10 Debian Linux, Postgresql, Advanced Cluster Security and 7 more | 2026-09-30 | 7.5 High |
| IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, '', or ""). If an administrator has installed files of a vulnerable, trusted, non-bundled extension, an attacker with database-level CREATE privilege can execute arbitrary code as the bootstrap superuser. | ||||