Export limit exceeded: 403804 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (16911 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2013-0431 | 2 Oracle, Redhat | 4 Jre, Openjdk, Enterprise Linux and 1 more | 2026-10-01 | 3.7 Low |
| Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-assisted remote attackers to bypass the Java security sandbox via unspecified vectors related to JMX, aka "Issue 52," a different vulnerability than CVE-2013-1490. | ||||
| CVE-2026-103641 | 2 Gegl, Redhat | 2 Gegl, Enterprise Linux | 2026-10-01 | 5.5 Medium |
| A flaw was found in GEGL. The Radiance HDR loader reads past the end of a memory-mapped image when an uncompressed scanline is shorter than the width declared in the file header. Opening a crafted HDR file crashes the application that uses the loader. | ||||
| CVE-2015-3246 | 3 Libuser Project, Opensuse, Redhat | 3 Libuser, Opensuse, Enterprise Linux | 2026-10-01 | 7.4 High |
| libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges. | ||||
| CVE-2026-48710 | 3 Encode, Kludex, Redhat | 9 Starlette, Starlette, Ai Inference Server and 6 more | 2026-10-01 | 6.5 Medium |
| Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make `request.url.path` differ from the path that was actually requested. Middleware and endpoints that apply security restrictions based on `request.url` (rather than the raw `scope` path) could therefore be bypassed. Users should upgrade to a version greater than or equal to version 1.0.1, which validates the `Host` header against the grammar of RFC 9112 §3.2 / RFC 3986 §3.2.2 when constructing `request.url` and falls back to `scope["server"]` for malformed values. | ||||
| CVE-2026-94184 | 1 Redhat | 1 Enterprise Linux | 2026-10-01 | 5.3 Medium |
| A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support. A malicious or compromised mail server advertising NTLM authentication can send a crafted Type 2 challenge that causes fetchmail to write past a fixed stack buffer while building the NTLM authenticate response. This may lead to remote code execution depending on stack-frame layout, or to authentication failure or process termination under memory hardening. | ||||
| CVE-2026-88924 | 2 Gnome, Redhat | 2 Gvfs, Enterprise Linux | 2026-10-01 | 7 High |
| A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory. A local attacker can exploit this via a Time-of-Check Time-of-Use (TOCTOU) race condition and exchange the socket pathname with a symbolic link pointing to an arbitrary root-owned file (such as /etc/pam.d/su). The daemon subsequently follows the symlink and changes the ownership of the targeted root-owned file to the attacker's user ID. This allows an authenticated local attacker to modify critical system files, leading to a full local privilege escalation to root. | ||||
| CVE-2026-84268 | 1 Redhat | 1 Enterprise Linux | 2026-10-01 | 8.8 High |
| A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the allocated buffer size, causing the operation to write past the intended boundaries. This issue allows a malicious server to corrupt adjacent heap memory in the gvfsd-sftp process, resulting in a denial of service as the process aborts upon detecting the heap corruption or potentially allowing arbitrary code execution. | ||||
| CVE-2023-1989 | 4 Debian, Linux, Netapp and 1 more | 11 Debian Linux, Linux Kernel, H300s and 8 more | 2026-10-01 | 7 High |
| A use-after-free flaw was found in btsdio_remove in drivers\bluetooth\btsdio.c in the Linux Kernel. A call to btsdio_remove with an unfinished job may cause a race problem which leads to a UAF on hdev devices. | ||||
| CVE-2026-83596 | 1 Redhat | 1 Enterprise Linux | 2026-09-30 | 8.8 High |
| A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling. | ||||
| CVE-2026-78376 | 1 Redhat | 1 Enterprise Linux | 2026-09-30 | 8.8 High |
| A flaw was found in WebKitGTK. Processing malicious web content can cause a use-after-free issue due to improper memory handling and result in memory corruption. | ||||
| CVE-2026-97026 | 2 Flatpak, Redhat | 2 Flatpak, Enterprise Linux | 2026-09-30 | 3.9 Low |
| Flatpak creates temporary child repository directories under the user cache with world-writable permissions (0777). On multi-user systems with a permissive umask, other local users could read or modify the temporary directory used while installing apps or runtimes, potentially causing installation failures (denial of service); tampered content would fail signature/digest verification rather than being trusted. | ||||
| CVE-2026-96281 | 2 Flatpak, Redhat | 2 Flatpak, Enterprise Linux | 2026-09-30 | 6.2 Medium |
| On a multi-user system, a user with an active local login session could downgrade a system-wide Flatpak app to an older version by removing the app's remote ref via the unprivileged system-helper RemoveLocalRef method, causing the anti-downgrade check to fail to find a reference date. A malicious local user could use this to expose other users of the same system to an app version with unfixed vulnerabilities. | ||||
| CVE-2026-102559 | 2 Libsoup, Redhat | 2 Libsoup, Enterprise Linux | 2026-09-30 | 8.6 High |
| A flaw was found in libsoup. When constructing a masked WebSocket client frame for a very large outgoing payload, size values passed to GByteArray allocation APIs could be truncated while the masking routine still used the full length, causing a heap buffer overflow. | ||||
| CVE-2026-102557 | 2 Libsoup, Redhat | 2 Libsoup, Enterprise Linux | 2026-09-30 | 8.6 High |
| A flaw was found in libsoup. When reassembling fragmented WebSocket messages into a GByteArray, libsoup did not adequately cap total message size against the limits of the underlying buffer type. A remote peer could send fragments that caused size truncation while the implementation still used the full length, leading to heap corruption or a crash. | ||||
| CVE-2026-102473 | 2 Dash, Redhat | 2 Dash, Enterprise Linux | 2026-09-30 | 5.5 Medium |
| A flaw was found in dash. When built without libc fnmatch, the internal pmatch() matcher implements * by unbounded recursion over candidate positions. A local user who can plant filenames, or otherwise feed that matcher, can make a short multi-star pattern such as *.*.*.*.*.tar.gz consume excessive CPU. | ||||
| CVE-2026-102556 | 2 Libsoup, Redhat | 2 Libsoup, Enterprise Linux | 2026-09-30 | 8.6 High |
| A flaw was found in libsoup. When handling an incoming WebSocket Pong frame, SoupWebsocketConnection emitted the ::pong signal with a GByteArray pointer even though the signal is declared to pass a GBytes. Applications connecting a handler that follows the documented GBytes API can trigger heap corruption or a crash upon receiving a crafted Pong. | ||||
| CVE-2026-102555 | 2 Libsoup, Redhat | 2 Libsoup, Enterprise Linux | 2026-09-30 | 8.2 High |
| A flaw was found in libsoup. The soup_uri_decode_data_uri() function incorrectly treated base64 data-URI payloads as NUL-terminated strings when calling g_base64_decode_inplace(). If the percent-decoded payload contained embedded NUL bytes, the decoded length could remain uninitialized and be used as the size of the returned GBytes. This can lead to an out-of-bounds read or application crash when processing a crafted data URI. | ||||
| CVE-2026-102558 | 2 Libsoup, Redhat | 2 Libsoup, Enterprise Linux | 2026-09-30 | 8.6 High |
| A flaw was found in libsoup. When max-incoming-payload-size is unlimited (0), SoupWebsocketConnection could grow its incoming GByteArray based on an attacker-controlled frame length until the length wrapped, causing a heap buffer overflow while reading frame data. | ||||
| CVE-2026-102560 | 2 Libsoup, Redhat | 2 Libsoup, Enterprise Linux | 2026-09-30 | 8.6 High |
| A flaw was found in libsoup. When the permessage-deflate WebSocket extension compresses a very large outgoing message, truncated size calculations used for GByteArray growth could wrap, causing zlib to write past the allocated buffer and resulting in a heap buffer overflow. | ||||
| CVE-2026-103399 | 1 Redhat | 1 Enterprise Linux | 2026-09-30 | 5.3 Medium |
| A flaw was found in SoupServer (libsoup). When an HTTP/1.x client sends a request with Expect: 100-continue and a request body, and SoupServer returns an early final (non-1xx) response before the body is read, the server neither drains the declared body bytes nor closes the connection. On a keep-alive connection, those leftover bytes are interpreted as a subsequent HTTP request. A remote, unauthenticated attacker can place a complete HTTP request in the body and cause SoupServer to process that smuggled request, leading to unintended request handling. | ||||