Where
-Infinity
0

redhat Enterprise Linux389-ds-base: 389-ds-base: sasl plain bind installs connection credentials before account-lock check, allowing continued access as a locked account

Risk 34
Severity
5.4
First published (updated )

redhat Enterprise LinuxTar: tar: toctou in incremental dumpdir 'x' rename handling allows restore path escape

Risk 25
Severity
4.4
First published (updated )

redhat Enterprise LinuxGimp: out-of-bounds read in file-icns plugin causes information disclosure or crash on crafted icns images

Risk 51
Severity
7.1
First published (updated )

redhat Enterprise LinuxGimp: integer overflow in file-fits plugin causes a heap-based buffer overflow on crafted fits images

Risk 68
Severity
7.8
First published (updated )

redhat Enterprise LinuxGimp: signed integer overflow in file-sgi (sgi-lib) causes the plugin to crash on rle sgi images

Risk 31
Severity
5.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

redhat Enterprise Linux389-ds-base: 389-ds-base: pre-authentication stack buffer overflow in get_ruvelement_from_berval() via unbounded replica id parsing

Risk 43
Severity
7.5
First published (updated )

libssh libsshLibssh: libssh: stack buffer overflow in sftp server longname construction

Risk 68
Severity
7.3
First published (updated )

redhat Enterprise LinuxLibssh: libssh: denial of service via unchecked proxycommand fork() failure

Risk 35
Severity
5.9
First published (updated )

redhat Enterprise LinuxLibssh: libssh: denial of service via oversized sftp read length

Risk 40
Severity
6.5
First published (updated )

redhat Enterprise LinuxLibssh: libssh: information disclosure via proxycommand %r username expansion

Risk 27
Severity
3.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

redhat Enterprise LinuxLibssh: libssh: integrity downgrade via openssl aes-gcm tag verification

Risk 46
Severity
7.5
First published (updated )

redhat Enterprise LinuxLibssh: libssh: denial of service via sftp responses with unknown request ids

Risk 29
Severity
5.3
First published (updated )

libssh libsshLibssh: libssh: authentication bypass via missing gssapi principal check

Risk 83
Severity
8.8
First published (updated )

libssh libsshLibssh: libssh: denial of service via automatic certificate authentication loop

Risk 46
Severity
7.5
First published (updated )

redhat Enterprise LinuxLibssh: libssh: use-after-free via data callbacks on closed channels

Risk 46
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

redhat Enterprise LinuxLibssh: libssh: denial of service via zero advertised channel packet size

Risk 40
Severity
6.5
First published (updated )

libssh libsshLibssh: libssh: information disclosure via short gssapi curve25519 public key

Risk 28
Severity
5.3
First published (updated )

redhat Enterprise Linux389-ds-base: 389-ds-base: non-constant-time comparison in pbkdf2-sha256 password verification

Risk 20
Severity
3.7
First published (updated )

redhat Enterprise Linux389-ds-base: 389-ds-base: static initialization vector in aes-cbc/3des-cbc attribute encryption

Risk 26
Severity
4.4
First published (updated )

redhat Enterprise Linux389-ds-base: 389-ds-base: heap-buffer-overflow in dn normalization via quoted multivalued rdn

Risk 27
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

GIMP GIMPGimp: gimp: integer overflow in read_rle_channel()

Risk 68
Severity
7.8
First published (updated )

redhat Enterprise LinuxGimp: gimp: denial of service via integer overflow in playstation tim loader

Risk 31
Severity
5.5
First published (updated )

redhat Enterprise LinuxGimp: gimp: stack buffer overflow in pnmscanner_gettoken()

Risk 68
Severity
7.8
First published (updated )

redhat Enterprise LinuxP11-kit: stack exhaustion via unbounded recursion in rpc attribute parsing

Risk 36
Severity
6.2
First published (updated )

redhat Enterprise LinuxYelp: yelp-xsl: overly permissive content security policy in yelp allows host file disclosure from flatpak applications

Risk 40
Severity
7.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

redhat Enterprise LinuxUtil-linux: util-linux: heap use-after-free in libblkid nested partition probing

Risk 45
Severity
6.8
First published (updated )

redhat Enterprise LinuxSpice-vdagent: integer overflow in udscs_write() leading to heap buffer overflow

Risk 35
Severity
5.1
First published (updated )

redhat Enterprise LinuxSpice-vdagent: path traversal in file transfer via unsanitized filename

Risk 26
Severity
4.4
First published (updated )

Linux Linux kernelmm/list_lru: drain before clearing xarray entry on reparent

Risk 69
Severity
7.8
First published (updated )

Linux Linux kerneldrm/gem: Try to fix change_handle ioctl, attempt 4

Risk 69
Severity
7.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203