Redhat

Enterprise Linux

1780 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.01%
  • Veröffentlicht 26.03.2026 15:16:43
  • Zuletzt bearbeitet 21.04.2026 16:29:29

A flaw was found in polkit. A local user can exploit this by providing a specially crafted, excessively long input to the `polkit-agent-helper-1` setuid binary via standard input (stdin). This unbounded input can lead to an out-of-memory (OOM) condit...

  • EPSS 0.05%
  • Veröffentlicht 24.03.2026 14:42:47
  • Zuletzt bearbeitet 11.05.2026 22:22:14

A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile function by providing a specially crafted TIFF file. This flaw can lead to an out-of-bounds heap write du...

  • EPSS 0.64%
  • Veröffentlicht 24.03.2026 04:11:16
  • Zuletzt bearbeitet 08.04.2026 19:11:02

A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending an HTTP GET request containing multipart/form-data content. If the underlying application processes parameters using methods like `getParameterMap()`, the ser...

  • EPSS 0.05%
  • Veröffentlicht 23.03.2026 21:26:14
  • Zuletzt bearbeitet 04.05.2026 15:30:08

An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function. The patch added a size validation check lsize + 8 > size, but it does not account for the GST_ROUND_UP_2(lsize) used in the actual offset calcula...

  • EPSS 0%
  • Veröffentlicht 23.03.2026 13:37:44
  • Zuletzt bearbeitet 24.03.2026 19:02:03

A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not prop...

  • EPSS 0.16%
  • Veröffentlicht 19.03.2026 13:53:39
  • Zuletzt bearbeitet 03.05.2026 21:16:11

A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by suppl...

  • EPSS 0.36%
  • Veröffentlicht 19.03.2026 13:50:27
  • Zuletzt bearbeitet 14.05.2026 23:16:37

A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote attacker can expl...

Exploit
  • EPSS 0.88%
  • Veröffentlicht 17.03.2026 11:14:21
  • Zuletzt bearbeitet 14.05.2026 11:16:18

A flaw was found in libsoup, a library for handling HTTP requests. This vulnerability, known as a Use-After-Free, occurs in the HTTP/2 server implementation. A remote attacker can exploit this by sending specially crafted HTTP/2 requests that cause a...

Exploit
  • EPSS 0.11%
  • Veröffentlicht 17.03.2026 09:44:19
  • Zuletzt bearbeitet 19.03.2026 19:56:43

A flaw was found in libsoup, a library used by applications to send network requests. This vulnerability occurs because libsoup does not properly validate hostnames, allowing special characters to be injected into HTTP headers. A remote attacker coul...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 17.03.2026 09:44:19
  • Zuletzt bearbeitet 19.03.2026 19:53:34

A flaw was found in libsoup. A remote attacker, by controlling the method parameter of the `soup_message_new()` function, could inject arbitrary headers and additional request data. This vulnerability, known as CRLF (Carriage Return Line Feed) inject...