|
41
|
2.5
-
|
LOW
Local
|
A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, …
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2025-6170
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2026-04-20 05:16
2025-06-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
42
|
7.5
-
|
HIGH
Network
|
A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a de…
|
CWE-787
Out-of-bounds Write
|
CVE-2025-6021
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2026-04-20 05:16
2025-06-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
43
|
7.8
-
|
HIGH
Local
|
A flaw was found in the HFS filesystem. When reading an HFS volume's name at grub_fs_mount(), the HFS filesystem driver performs a strcpy() using the user-provided volume name as input without proper…
|
CWE-787 CWE-120
Out-of-bounds Write Classic Buffer Overflow
|
CVE-2024-45782
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2025-03-8 04:45
2025-03-4
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
44
|
5.5
-
|
MEDIUM
Local
|
A stack overflow flaw was found when reading a BFS file system. A crafted BFS filesystem may lead to an uncontrolled loop, causing grub2 to crash.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2024-45778
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2025-03-8 04:45
2025-03-4
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
45
|
7.8
-
|
HIGH
Local
|
A flaw was found in grub2. When reading data from a squash4 filesystem, grub's squash4 fs module uses user-controlled parameters from the filesystem geometry to determine the internal buffer size, ho…
|
CWE-190 CWE-787
Integer Overflow or Wraparound Out-of-bounds Write
|
CVE-2025-0678
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2025-03-8 04:45
2025-03-4
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
46
|
7.8
-
|
HIGH
Local
|
A use-after-free flaw was found in X.Org and Xwayland. When changing an alarm, the values of the change mask are evaluated one after the other, changing the trigger values as requested, and eventuall…
|
-
|
CVE-2025-26601
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2025-03-10 22:15
2025-02-26
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
47
|
7.8
-
|
HIGH
Local
|
A use-after-free flaw was found in X.Org and Xwayland. When a device is removed while still frozen, the events queued for that device remain while the device is freed. Replaying the events will cause…
|
-
|
CVE-2025-26600
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2025-03-10 22:15
2025-02-26
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
48
|
7.8
-
|
HIGH
Local
|
An access to an uninitialized pointer flaw was found in X.Org and Xwayland. The function compCheckRedirect() may fail if it cannot allocate the backing pixmap. In that case, compRedirectWindow() will…
|
-
|
CVE-2025-26599
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2025-03-10 22:15
2025-02-26
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
49
|
7.8
-
|
HIGH
Local
|
An out-of-bounds write flaw was found in X.Org and Xwayland. The function GetBarrierDevice() searches for the pointer device based on its device ID and returns the matching value, or supposedly NULL,…
|
-
|
CVE-2025-26598
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2025-03-10 22:15
2025-02-26
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
50
|
7.8
-
|
HIGH
Local
|
A buffer overflow flaw was found in X.Org and Xwayland. If XkbChangeTypesOfKey() is called with a 0 group, it will resize the key symbols table to 0 but leave the key actions unchanged. If the same f…
|
-
|
CVE-2025-26597
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2025-03-10 22:15
2025-02-26
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|