Redhat

Enterprise Linux

1952 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.87%
  • Veröffentlicht 31.07.2026 09:18:50
  • Zuletzt bearbeitet 08.10.2026 15:17:50

A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checkin...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 27.07.2026 19:17:23
  • Zuletzt bearbeitet 10.08.2026 13:45:01

A flaw was found in the file-sgi plugin in GIMP. When processing an RLE-compressed SGI image, the plugin allocates memory for a row table. The image header dimensions (ysize and zsize) are read as 16-bit unsigned integers. If a crafted file sets both...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 27.07.2026 19:17:23
  • Zuletzt bearbeitet 30.09.2026 15:22:33

A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation sizes using signed 32-bit integers for width and height. If a crafted file sets both values to large values, their product ex...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 27.07.2026 19:17:23
  • Zuletzt bearbeitet 24.08.2026 18:17:01

A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the plugin reads from the mask data buffer without verifying if the cursor exceeds the allocated resource size. If a crafted file contai...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 24.07.2026 23:16:52
  • Zuletzt bearbeitet 24.08.2026 16:44:22

A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk sizes that silently accepts inputs violating RFC 9112, including leading whitespace, plus sign prefixes, and trailing invalid characters. W...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 24.07.2026 23:16:52
  • Zuletzt bearbeitet 24.08.2026 16:44:01

A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header to subsequent HTTPS requests sent through that tunnel to the destination server. This allows the des...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 24.07.2026 23:16:51
  • Zuletzt bearbeitet 24.08.2026 16:44:56

A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes a heap buffer over-read when parsing multipart HTTP responses. A malicious HTTP server can exploit this by sending a crafted multi...

  • EPSS 0.4%
  • Veröffentlicht 22.07.2026 12:51:43
  • Zuletzt bearbeitet 22.07.2026 19:16:57

A heap-buffer-overflow flaw was found in Directory Server (389-ds-base). When a DN contains a legacy-quoted value, the server won't close the heap allocation allowing another call to refer to the same memory pointer causing a denial of service or an ...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 21.07.2026 19:17:09
  • Zuletzt bearbeitet 24.08.2026 16:45:12

A heap out-of-bounds read flaw was found in libsoup. When parsing multipart HTTP messages, an integer type mismatch between the caller and soup_headers_parse() can cause the length parameter to be incorrectly truncated, leading to a heap buffer over-...

  • EPSS 0.29%
  • Veröffentlicht 21.07.2026 14:20:47
  • Zuletzt bearbeitet 17.08.2026 22:17:15

A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for the requested local user, allowing authenticated clients to log in as arbitrar...