Enterprise Linux Server
by Red Hat
CVEs (3,563)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-34002 | Med | 0.40 | 6.1 | 0.00 | May 5, 2026 | A flaw was found in the X.Org X server. This vulnerability, an out-of-bounds read, affects the XKB (X Keyboard Extension) modifier map handling. An attacker with access to the X11 server can exploit this by sending a malformed request, which causes the server to read beyond its… | ||
| CVE-2026-34000 | Med | 0.40 | 6.1 | 0.00 | May 5, 2026 | A flaw was found in the X.Org X server. This out-of-bounds read vulnerability in the XKB geometry processing, specifically within the `CheckSetGeom()` and `XkbAddGeomKeyAlias` functions, allows an attacker to read uninitialized or out-of-bounds memory. An attacker with a… | ||
| CVE-2026-41082 | Hig | 0.40 | 7.3 | 0.00 | Apr 16, 2026 | In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory. | ||
| CVE-2026-40919 | Med | 0.40 | 6.1 | 0.00 | Apr 15, 2026 | A flaw was found in GIMP. This vulnerability, a buffer overflow in the `file-seattle-filmworks` plugin, can be exploited when a user opens a specially crafted Seattle Filmworks file. A remote attacker could leverage this to cause a denial of service (DoS), leading to the plugin… | ||
| CVE-2026-4647 | Med | 0.40 | 6.1 | 0.00 | Mar 23, 2026 | A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being… | ||
| CVE-2026-3442 | Med | 0.40 | 6.1 | 0.00 | Mar 16, 2026 | A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful… | ||
| CVE-2026-3441 | Med | 0.40 | 6.1 | 0.00 | Mar 16, 2026 | A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker… | ||
| CVE-2024-12086 | Med | 0.40 | 6.1 | 0.02 | Jan 14, 2025 | A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a client to a server. During this process, the rsync server will send checksums of local data to the… | ||
| CVE-2023-40549 | Med | 0.40 | 6.2 | 0.00 | Jan 29, 2024 | An out-of-bounds read flaw was found in Shim due to the lack of proper boundary verification during the load of a PE binary. This flaw allows an attacker to load a crafted PE binary, triggering the issue and crashing Shim, resulting in a denial of service. | ||
| CVE-2023-40546 | Med | 0.40 | 6.2 | 0.00 | Jan 29, 2024 | A flaw was found in Shim when an error happened while creating a new ESL variable. If Shim fails to create the new variable, it tries to print an error message to the user; however, the number of parameters used by the logging function doesn't match the format string used by it,… | ||
| CVE-2023-38473 | Med | 0.40 | 6.2 | 0.00 | Nov 2, 2023 | A vulnerability was found in Avahi. A reachable assertion exists in the avahi_alternative_host_name() function. | ||
| CVE-2022-4900 | Med | 0.40 | 6.2 | 0.00 | Nov 2, 2023 | A vulnerability was found in PHP where setting the environment variable PHP_CLI_SERVER_WORKERS to a large value leads to a heap buffer overflow. | ||
| CVE-2023-38472 | Med | 0.40 | 6.2 | 0.00 | Nov 2, 2023 | A vulnerability was found in Avahi. A reachable assertion exists in the avahi_rdata_parse() function. | ||
| CVE-2023-38471 | Med | 0.40 | 6.2 | 0.00 | Nov 2, 2023 | A vulnerability was found in Avahi. A reachable assertion exists in the dbus_set_host_name function. | ||
| CVE-2023-38470 | Med | 0.40 | 6.2 | 0.00 | Nov 2, 2023 | A vulnerability was found in Avahi. A reachable assertion exists in the avahi_escape_label() function. | ||
| CVE-2023-38469 | Med | 0.40 | 6.2 | 0.00 | Nov 2, 2023 | A vulnerability was found in Avahi, where a reachable assertion exists in avahi_dns_packet_append_record. | ||
| CVE-2023-39193 | Med | 0.40 | 6.1 | 0.00 | Oct 9, 2023 | A flaw was found in the Netfilter subsystem in the Linux kernel. The sctp_mt_check did not validate the flag_count field. This flaw allows a local privileged (CAP_NET_ADMIN) attacker to trigger an out-of-bounds read, leading to a crash or information disclosure. | ||
| CVE-2023-3428 | Med | 0.40 | 6.2 | 0.00 | Oct 4, 2023 | A heap-based buffer overflow vulnerability was found in coders/tiff.c in ImageMagick. This issue may allow a local attacker to trick the user into opening a specially crafted file, resulting in an application crash and denial of service. | ||
| CVE-2023-32627 | Med | 0.40 | 6.2 | 0.00 | Jul 10, 2023 | A floating point exception vulnerability was found in sox, in the read_samples function at sox/src/voc.c:334:18. This flaw can lead to a denial of service. | ||
| CVE-2023-26590 | Med | 0.40 | 6.2 | 0.00 | Jul 10, 2023 | A floating point exception vulnerability was found in sox, in the lsx_aiffstartwrite function at sox/src/aiff.c:622:58. This flaw can lead to a denial of service. |
- risk 0.40cvss 6.1epss 0.00
A flaw was found in the X.Org X server. This vulnerability, an out-of-bounds read, affects the XKB (X Keyboard Extension) modifier map handling. An attacker with access to the X11 server can exploit this by sending a malformed request, which causes the server to read beyond its…
- risk 0.40cvss 6.1epss 0.00
A flaw was found in the X.Org X server. This out-of-bounds read vulnerability in the XKB geometry processing, specifically within the `CheckSetGeom()` and `XkbAddGeomKeyAlias` functions, allows an attacker to read uninitialized or out-of-bounds memory. An attacker with a…
- risk 0.40cvss 7.3epss 0.00
In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.
- risk 0.40cvss 6.1epss 0.00
A flaw was found in GIMP. This vulnerability, a buffer overflow in the `file-seattle-filmworks` plugin, can be exploited when a user opens a specially crafted Seattle Filmworks file. A remote attacker could leverage this to cause a denial of service (DoS), leading to the plugin…
- risk 0.40cvss 6.1epss 0.00
A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being…
- risk 0.40cvss 6.1epss 0.00
A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful…
- risk 0.40cvss 6.1epss 0.00
A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker…
- risk 0.40cvss 6.1epss 0.02
A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a client to a server. During this process, the rsync server will send checksums of local data to the…
- risk 0.40cvss 6.2epss 0.00
An out-of-bounds read flaw was found in Shim due to the lack of proper boundary verification during the load of a PE binary. This flaw allows an attacker to load a crafted PE binary, triggering the issue and crashing Shim, resulting in a denial of service.
- risk 0.40cvss 6.2epss 0.00
A flaw was found in Shim when an error happened while creating a new ESL variable. If Shim fails to create the new variable, it tries to print an error message to the user; however, the number of parameters used by the logging function doesn't match the format string used by it,…
- risk 0.40cvss 6.2epss 0.00
A vulnerability was found in Avahi. A reachable assertion exists in the avahi_alternative_host_name() function.
- risk 0.40cvss 6.2epss 0.00
A vulnerability was found in PHP where setting the environment variable PHP_CLI_SERVER_WORKERS to a large value leads to a heap buffer overflow.
- risk 0.40cvss 6.2epss 0.00
A vulnerability was found in Avahi. A reachable assertion exists in the avahi_rdata_parse() function.
- risk 0.40cvss 6.2epss 0.00
A vulnerability was found in Avahi. A reachable assertion exists in the dbus_set_host_name function.
- risk 0.40cvss 6.2epss 0.00
A vulnerability was found in Avahi. A reachable assertion exists in the avahi_escape_label() function.
- risk 0.40cvss 6.2epss 0.00
A vulnerability was found in Avahi, where a reachable assertion exists in avahi_dns_packet_append_record.
- risk 0.40cvss 6.1epss 0.00
A flaw was found in the Netfilter subsystem in the Linux kernel. The sctp_mt_check did not validate the flag_count field. This flaw allows a local privileged (CAP_NET_ADMIN) attacker to trigger an out-of-bounds read, leading to a crash or information disclosure.
- risk 0.40cvss 6.2epss 0.00
A heap-based buffer overflow vulnerability was found in coders/tiff.c in ImageMagick. This issue may allow a local attacker to trick the user into opening a specially crafted file, resulting in an application crash and denial of service.
- risk 0.40cvss 6.2epss 0.00
A floating point exception vulnerability was found in sox, in the read_samples function at sox/src/voc.c:334:18. This flaw can lead to a denial of service.
- risk 0.40cvss 6.2epss 0.00
A floating point exception vulnerability was found in sox, in the lsx_aiffstartwrite function at sox/src/aiff.c:622:58. This flaw can lead to a denial of service.
Page 85 of 179