Skip to main content

Vendor/product archive

redhat / enterprise_linux CVEs

Beta · best-effort

2,217 CVEs tagged to redhat / enterprise_linux203 Critical, 712 High, 1,105 Medium, 197 Low, 0 Unrated.

CVE-2026-4887

Published Mar 26, 2026

A flaw was found in GIMP. This issue is a heap buffer over-read in GIMP PCX file loader due to an off-by-one error. A remote attacker could exploit this by convincing a user to op…

CVSS 6.1 · Medium
evidence mentions
14
Buzz score
35.1
Vendor/product tagsBeta · best-effort

CVE-2026-4424

Published Mar 19, 2026

A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size af…

CVSS 7.5 · High
evidence mentions
39
Buzz score
48.0

CVE-2026-4271

Published Mar 17, 2026

A flaw was found in libsoup, a library for handling HTTP requests. This vulnerability, known as a Use-After-Free, occurs in the HTTP/2 server implementation. A remote attacker can…

CVSS 5.3 · Medium
evidence mentions
6
Buzz score
27.5
Vendor/product tagsBeta · best-effort

CVE-2026-3634

Published Mar 17, 2026

A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage Return Line Feed (CRLF) sequence due to improper input san…

CVSS 3.9 · Low
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-3633

Published Mar 17, 2026

A flaw was found in libsoup. A remote attacker, by controlling the method parameter of the `soup_message_new()` function, could inject arbitrary headers and additional request dat…

CVSS 3.9 · Low
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-3632

Published Mar 17, 2026

A flaw was found in libsoup, a library used by applications to send network requests. This vulnerability occurs because libsoup does not properly validate hostnames, allowing spec…

CVSS 3.9 · Low
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-3099

Published Mar 12, 2026

A flaw was found in Libsoup. The server-side digest authentication implementation in the SoupAuthDomainDigest class does not properly track issued nonces or enforce the required i…

CVSS 5.8 · Medium
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-26104

Published Feb 25, 2026

A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization. The issue occurs because a privil…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
25.9
Vendor/product tagsBeta · best-effort

CVE-2026-26103

Published Feb 25, 2026

A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper authorization checks. The issue a…

CVSS 7.1 · High
evidence mentions
6
Buzz score
32.5
Vendor/product tagsBeta · best-effort

CVE-2026-2443

Published Feb 13, 2026

A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing specially crafted HTTP Range headers, the library may improperly validate requ…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-1709

Published Feb 6, 2026

A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authentication bypass vu…

CVSS 9.4 · Critical
evidence mentions
6
Buzz score
31.0

CVE-2026-1801

Published Feb 3, 2026

A flaw was found in libsoup, an HTTP client/server library. This HTTP Request Smuggling vulnerability arises from non-RFC-compliant parsing in the soup_filter_input_stream_read_li…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort
Showing 151-175 of 2,217 CVEsPage 7 of 89