|
21
|
7.8
-
|
HIGH
Local
|
A flaw was found in grub2. When reading data from a squash4 filesystem, grub's squash4 fs module uses user-controlled parameters from the filesystem geometry to determine the internal buffer size, ho…
|
CWE-190 CWE-787
Integer Overflow or Wraparound Out-of-bounds Write
|
CVE-2025-0678
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2025-03-8 04:45
2025-03-4
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
22
|
7.8
-
|
HIGH
Local
|
A use-after-free flaw was found in X.Org and Xwayland. When changing an alarm, the values of the change mask are evaluated one after the other, changing the trigger values as requested, and eventuall…
|
-
|
CVE-2025-26601
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2025-03-10 22:15
2025-02-26
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
23
|
7.8
-
|
HIGH
Local
|
A use-after-free flaw was found in X.Org and Xwayland. When a device is removed while still frozen, the events queued for that device remain while the device is freed. Replaying the events will cause…
|
-
|
CVE-2025-26600
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2025-03-10 22:15
2025-02-26
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
24
|
7.8
-
|
HIGH
Local
|
An access to an uninitialized pointer flaw was found in X.Org and Xwayland. The function compCheckRedirect() may fail if it cannot allocate the backing pixmap. In that case, compRedirectWindow() will…
|
-
|
CVE-2025-26599
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2025-03-10 22:15
2025-02-26
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
25
|
7.8
-
|
HIGH
Local
|
An out-of-bounds write flaw was found in X.Org and Xwayland. The function GetBarrierDevice() searches for the pointer device based on its device ID and returns the matching value, or supposedly NULL,…
|
-
|
CVE-2025-26598
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2025-03-10 22:15
2025-02-26
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
26
|
7.8
-
|
HIGH
Local
|
A buffer overflow flaw was found in X.Org and Xwayland. If XkbChangeTypesOfKey() is called with a 0 group, it will resize the key symbols table to 0 but leave the key actions unchanged. If the same f…
|
-
|
CVE-2025-26597
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2025-03-10 22:15
2025-02-26
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
27
|
7.8
-
|
HIGH
Local
|
A heap overflow flaw was found in X.Org and Xwayland. The computation of the length in XkbSizeKeySyms() differs from what is written in XkbWriteKeySyms(), which may lead to a heap-based buffer overfl…
|
-
|
CVE-2025-26596
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2025-03-10 22:15
2025-02-26
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
28
|
7.8
-
|
HIGH
Local
|
A buffer overflow flaw was found in X.Org and Xwayland. The code in XkbVModMaskText() allocates a fixed-sized buffer on the stack and copies the names of the virtual modifiers to that buffer. The cod…
|
-
|
CVE-2025-26595
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2025-03-10 22:15
2025-02-26
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
29
|
7.8
-
|
HIGH
Local
|
A use-after-free flaw was found in X.Org and Xwayland. The root cursor is referenced in the X server as a global variable. If a client frees the root cursor, the internal reference points to freed me…
|
-
|
CVE-2025-26594
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2025-03-10 22:15
2025-02-26
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
30
|
6.8
-
|
MEDIUM
Network
|
A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occur…
|
-
|
CVE-2025-26465
|
cpe:2.3:o:redhat:enterprise_linux:9.0:*
|
|
|
|
|
2025-03-6 03:54
2025-02-19
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|