VulnSea

Tagged “red-hat”

CVEs tagged red-hat, newest first.

2912 CVEsRSS

CVE-2026-90801Medium· 5.3PoC
1w ago

A security flaw has been discovered in GNU Binutils 2.47

A security flaw has been discovered in GNU Binutils 2.47. This impacts the function cache_bwrite of the file bfd/cache.c of the component ld. The manipulation of the argument nbytes results in buffer overflow. The attack requires a local…

▾ Twilightgnu · binutilsEPSS 0.21%via NVD
CVE-2026-90996Medium· 4.0
1w ago

A flaw was found in sssd

A flaw was found in sssd. A local unprivileged user could send a specially crafted request with a zero-length body to the Network Security Services (NSS) responder. This could lead to a denial-of-service condition, causing the NSS respon…

▾ SunlitRed Hat · sssdEPSS 0.16%via NVD
CVE-2026-90995Medium· 5.5
1w ago

A flaw was found in SSSD (System Security Services Daemon)

A flaw was found in SSSD (System Security Services Daemon). A local attacker with privileges to connect to the PAM (Pluggable Authentication Modules) responder socket can send a specially crafted protocol request. If the `pam_app_service…

▾ SunlitRed Hat · sssdEPSS 0.15%via NVD
CVE-2026-90994Medium· 4.0
1w ago

A flaw was found in sssd, specifically within the PAM (Pluggable Authentication Modules) responder's protocol v1 parser, pam_parse_in_data()

A flaw was found in sssd, specifically within the PAM (Pluggable Authentication Modules) responder's protocol v1 parser, pam_parse_in_data(). A local client with access to the PAM responder's UNIX socket can exploit this by negotiating p…

▾ SunlitRed Hat · sssdEPSS 0.17%via NVD
CVE-2026-90463Medium· 4.0
1w ago

A flaw was found in the sssd NSS responder

A flaw was found in the sssd NSS responder. This input validation vulnerability allows a local attacker, by sending specially crafted service lookup requests to the NSS responder's UNIX socket, to cause an out-of-bounds read. This out-of…

▾ SunlitRed Hat · sssdEPSS 0.15%via NVD
CVE-2024-53922Medium· 5.7
1w ago

An issue was discovered in the buffer queue driver in Samsung Automotive Processor Exynos Auto 8890, V7, V9, and V920

An issue was discovered in the buffer queue driver in Samsung Automotive Processor Exynos Auto 8890, V7, V9, and V920. Lack of a length check leads to a Denial of Service in the kernel.

▾ SunlitSamsung · Exynos 8890 firmwareEPSS 0.16%via NVD
CVE-2022-42917Medium· 6.7
1w ago

In FRRouting FRR before 8.5, the service user (usually frr) can escalate its privileges to root by monitoring the configuration directory (/etc/frr) and replacing config files upon creation with, for example, symlinks to change the owner…

In FRRouting FRR before 8.5, the service user (usually frr) can escalate its privileges to root by monitoring the configuration directory (/etc/frr) and replacing config files upon creation with, for example, symlinks to change the owner…

▾ SunlitFRRouting · FRRoutingEPSS 0.13%via NVD
CVE-2025-64031Low· 2.5PoC⚖ disputed
1w ago

libarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer overflow in the gzip writer via the original-filename field to archive_compressor_gzip_open in archive_write_add_filter_gzip.c, aka GHSA-92wx-p669-8gr9

libarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer overflow in the gzip writer via the original-filename field to archive_compressor_gzip_open in archive_write_add_filter_gzip.c, aka GHSA-92wx-p669-8gr9. This relates to bsdtar.…

▾ Twilightlibarchive · libarchiveEPSS 0.18%via NVD
CVE-2026-90682Medium· 5.3PoC
1w ago

A security vulnerability has been detected in Matthias-Wandel jhead up to 3.3

A security vulnerability has been detected in Matthias-Wandel jhead up to 3.3. This impacts the function ProcessGpsInfo of the file gpsinfo.c of the component WebP EXIF Handler. Such manipulation of the argument TAG_GPS_LAT/TAG_GPS_LONG …

▾ TwilightMatthias-Wandel · jheadEPSS 0.17%via NVD
CVE-2023-24291Low· 2.9
1w ago

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the record length parameter.

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the record length parameter.

▾ SunlitSimon Tatham · Portable Puzzle CollectionEPSS 0.12%via NVD
CVE-2026-25832Low· 3.7
1w ago

In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group.

In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group.

▾ SunlitTrustedFirmware · Mbed TLSEPSS 0.28%via NVD
CVE-2026-90698Medium· 5.3PoC
1w ago

A security flaw has been discovered in memcached 1.6.41/1.6.42/1.6.43

A security flaw has been discovered in memcached 1.6.41/1.6.42/1.6.43. This vulnerability affects the function try_read_command_asciiauth of the file proto_text.c of the component mcmc Tokenizer. The manipulation results in out-of-bounds…

▾ TwilightRed Hat · memcachedEPSS 0.86%via NVD
CVE-2024-23176Medium· 5.4PoC
1w ago

An issue was discovered in the MassMessage extension in MediaWiki before 1.40.2

An issue was discovered in the MassMessage extension in MediaWiki before 1.40.2. For a Special:MassMessage?uselang=x-xss URL, the i18n key massmessage-form-page-help allows XSS.

▾ TwilightRed Hat · MassMessageEPSS 0.21%via NVD
CVE-2026-88932Medium· 5.3
1w ago

multer is a Node.js middleware for handling multipart/form-data uploads

multer is a Node.js middleware for handling multipart/form-data uploads. In versions 2.2.0 through 2.3.0, when a request using disk storage is aborted mid-upload, file writes that complete after multer has already run its abort cleanup a…

▾ SunlitRed Hat · Red Hat Developer HubEPSS 0.53%via NVD
CVE-2026-90713Low· 3.3PoC
1w ago

A security flaw has been discovered in vllm-project vLLM up to 0.29.0

A security flaw has been discovered in vllm-project vLLM up to 0.29.0. The affected element is the function TiktokenTokenizer::new of the file rust/src/text/src/backend/hf/mod.rs of the component tiktoken vocab File Handler. The manipula…

▾ Twilightvllm-project · vLLMEPSS 0.16%via NVD
CVE-2023-32803High· 7.5
1w ago

The ca-certificates package before ca-certificates-2021.2.50-72 for Amazon Linux 2 (AL2) does not properly remove certain TrustCor root certificates from the root store

The ca-certificates package before ca-certificates-2021.2.50-72 for Amazon Linux 2 (AL2) does not properly remove certain TrustCor root certificates from the root store. NOTE: this issue exists because of an incorrect fix for CVE-2022-23…

▾ TwilightAmazon · ca-certificatesEPSS 0.18%via NVD
CVE-2026-90949High· 7.8
1w ago

A flaw was found in GIMP's PSP (Paint Shop Pro) file loader

A flaw was found in GIMP's PSP (Paint Shop Pro) file loader. When processing a compressed selection channel, a heap-based buffer overflow can occur due to a mismatch between the allocated buffer size and the amount of data decompressed. …

▾ TwilightRed Hat · gimpEPSS 0.33%via NVD
CVE-2026-90948High· 7.8
1w ago

A flaw was found in GIMP's ICO file loader

A flaw was found in GIMP's ICO file loader. When processing an ICO file containing an embedded PNG image, an integer overflow can occur during the calculation of the required buffer size. This leads to an undersized buffer being allocate…

▾ TwilightRed Hat · gimpEPSS 0.33%via NVD
CVE-2026-71198High· 7.0
1w ago

In OpenStack Glance before 32.0.1, the location API does not validate destination hosts when adding an HTTP location to an image

In OpenStack Glance before 32.0.1, the location API does not validate destination hosts when adding an HTTP location to an image. Unlike the web-download import path, the location API only checks the URL scheme and does not apply the imp…

▾ TwilightOpenStack · GlanceEPSS 0.45%via NVD
CVE-2026-55073Medium· 6.2PoC
1w ago

WeasyPrint helps web developers to create PDF documents

WeasyPrint helps web developers to create PDF documents. Prior to 70.0, server-side applications that configure a restrictive url_fetcher and pass attacker-influenced values to HTML.write_pdf() can have the restriction bypassed through t…

▾ TwilightKozea · WeasyPrintEPSS 0.22%via NVD
CVE-2026-53495Medium· 6.8
1w ago

containerd is an open-source container runtime

containerd is an open-source container runtime. Prior to 1.7.35, 2.0.12, 2.2.8, and 2.3.5, containerd on Linux with the CRI plugin enabled can indefinitely block the drainExecSyncIO goroutine in internal/cri/server/container_execsync.go …

▾ Sunlitcontainerd · containerdEPSS 0.16%via NVD
CVE-2025-24890Medium· 6.8PoC
1w ago

gitoxide is an implementation of git written in Rust

gitoxide is an implementation of git written in Rust. Prior to 0.13.3, the gix-sec crate on Windows incorrectly treats repositories controlled by another user as trusted when an administrator runs a dependent program with an unfiltered e…

▾ TwilightGitoxideLabs · gitoxideEPSS 0.19%via NVD
CVE-2026-84445High· 8.7
1w ago

gRPC-Go is the Go language implementation of gRPC

gRPC-Go is the Go language implementation of gRPC. Prior to 1.82.2 and 1.83.2, servers created with xds.NewGRPCServer() allow internal/transport/http2_server.go to accept an RPC containing neither the :authority header nor the Host heade…

▾ Twilightgrpc · grpc-goEPSS 0.64%via NVD
CVE-2026-55451High· 8.3PoC
1w ago

gettext-converter provides gettext resource conversion utilities for JavaScript

gettext-converter provides gettext resource conversion utilities for JavaScript. Prior to 1.3.3, js2i18next() in lib/js2i18next.js splits nested translation keys using options.keyseparator, whose default value consists of two number sign…

▾ Midnightlocize · gettext-converterEPSS 0.57%via NVD
CVE-2026-53659High· 7.5
1w ago

http4k is a functional toolkit for Kotlin HTTP applications

http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.49.0.0, ServerFilters.GZip, RequestFilters.GunZip, and the underlying Gzip request-body decompression functions impose no limit on decompress…

▾ Twilighthttp4k · http4kEPSS 0.63%via NVD
CVE-2026-54559Medium· 6.9
1w ago

PocketSphinx is a small speech recognizer

PocketSphinx is a small speech recognizer. Prior to 5.1.1, the trie language-model loaders in src/lm/ngram_model_trie.c do not adequately validate boundary conditions in ARPA, DMP, and binary format headers, and the acoustic-model loader…

▾ Sunlitcmusphinx · pocketsphinxEPSS 0.55%via NVD
CVE-2026-53714High· 7.4
1w ago

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, the xDS gRPC server in GatewayNamespaceMode, configured through provider.kubernetes.deplo…

▾ Twilightenvoyproxy · gatewayEPSS 0.35%via NVD
CVE-2026-47701High· 7.7
1w ago

The OpenTelemetry Operator is a Kubernetes Operator for the OpenTelemetry Collector

The OpenTelemetry Operator is a Kubernetes Operator for the OpenTelemetry Collector. Prior to 0.152.0, cmd/otel-allocator TargetAllocator instances with targetAllocator.prometheusCR.enabled set to true preserve a selected ServiceMonitor …

▾ Twilightopen-telemetry · opentelemetry-operatorEPSS 0.46%via NVD
CVE-2026-55866Low· 3.7
1w ago

SpiceDB is an open source database system for creating and managing security-critical application permissions

SpiceDB is an open source database system for creating and managing security-critical application permissions. From 1.34.0 until 1.54.0, SpiceDB can return PERMISSIONSHIP_HAS_PERMISSION instead of PERMISSIONSHIP_CONDITIONAL_PERMISSION or…

▾ Sunlitauthzed · spicedbEPSS 0.34%via NVD
CVE-2026-47256Medium· 5.3PoC
1w ago

OpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generating, collecting, and exporting telemetry data such as traces, metrics, and logs

OpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generating, collecting, and exporting telemetry data such as traces, metrics, and logs. Prior to 0.154.0, the Sentry exporter r…

▾ Twilightopen-telemetry · opentelemetry-collector-contribEPSS 0.44%via NVD
CVEs tagged “red-hat” — page 24 · VulnSea