enterprise linux kayıtları
enterprise linux üreticisine ait 90 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 10
- Düzeltme kaydı olan
- %92,2
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-122 Heap-based Buffer Overflow8
- CWE-125 Out-of-bounds Read7
- CWE-190 Integer Overflow or Wraparound7
- CWE-400 Uncontrolled Resource Consumption5
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-121 Stack-based Buffer Overflow3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
90 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
42Planlayın | CVE-2026-4631Kavram kanıtı | Cockpit: cockpit: unauthenticated remote code execution due to ssh command-line argument injectionred hat · red hat enterprise linux 10 · CWE-78 | Kritik9,8 | — | %9,2 | 7 Nis 2026 |
37İzleyin | CVE-2026-8450İstismar yok | HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file()oalders · http::daemon · CWE-73 | Kritik9,1 | — | %2,6 | 27 May 2026 |
37İzleyin | CVE-2025-14813İstismar yok | GOSTCTR implementation unable to process more than 255 blocks correctlylegion of the bouncy castle inc. · bc-java · CWE-327 | Kritik9,3 | — | %0,3 | 15 Nis 2026 |
36İzleyin | CVE-2026-9277Kavram kanıtı | shell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`CWE-77 | Kritik9,2 | — | %1,0 | 22 May 2026 |
36İzleyin | CVE-2026-6100İstismar yok | Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressurepython software foundation · cpython · CWE-416 | Kritik9,1 | — | %0,8 | 13 Nis 2026 |
36İzleyin | CVE-2025-10263İstismar yok | Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-arm · c1-ultra · CWE-362 | Kritik9,1 | — | %0,5 | 9 Haz 2026 |
35İzleyin | CVE-2026-52720İstismar yok | Gstreamer1-plugins-bad-free: gstreamer: heap buffer overflow via crafted vnc server rectangle in librfbred hat · red hat enterprise linux 10 · CWE-122 | Yüksek8,8 | — | %1,2 | 15 Haz 2026 |
35İzleyin | CVE-2026-5598İstismar yok | Non-constant time comparisons risk private key leakage in FrodoKEM.legion of the bouncy castle inc. · bc-java · CWE-385 | Yüksek8,9 | — | %1,0 | 15 Nis 2026 |
34İzleyin | CVE-2026-1761İstismar yok | Libsoup: stack-based buffer overflow in libsoup multipart response parsingmultipart http responsered hat · red hat enterprise linux 10 · CWE-121 | Yüksek8,6 | — | %1,0 | 2 Şub 2026 |
34İzleyin | CVE-2026-46384İstismar yok | iskorotkov/avro: Integer Overflow in Avro Decoderiskorotkov · avro · CWE-190 | Yüksek8,7 | — | %0,9 | 29 May 2026 |
34İzleyin | CVE-2026-31812İstismar yok | Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsingquinn-rs · quinn · CWE-248 | Yüksek8,7 | — | %0,9 | 10 Mar 2026 |
34İzleyin | CVE-2026-46385İstismar yok | iskorotkov/avro: CPU Exhaustion in Avro Decoderiskorotkov · avro · CWE-400 | Yüksek8,7 | — | %0,9 | 29 May 2026 |
34İzleyin | CVE-2026-3505İstismar yok | Unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion.legion of the bouncy castle inc. · bc-java · CWE-400 | Yüksek8,7 | — | %0,9 | 15 Nis 2026 |
34İzleyin | CVE-2026-41673İstismar yok | xmldom: Denial of service via uncontrolled recursion in XML serializationxmldom · xmldom · CWE-674 | Yüksek8,7 | — | %0,9 | 7 May 2026 |
34İzleyin | CVE-2026-5367İstismar yok | Ovn: ovn: information disclosure via crafted dhcpv6 packetsred hat · fast datapath for red hat enterprise linux 10 · CWE-130 | Yüksek8,6 | — | %0,9 | 24 Nis 2026 |
34İzleyin | CVE-2026-12143İstismar yok | form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)form-data · form-data · CWE-93 | Yüksek8,7 | — | %0,7 | 12 Haz 2026 |
34İzleyin | CVE-2026-41672İstismar yok | xmldom: XML node injection through unvalidated comment serializationxmldom · xmldom · CWE-91 | Yüksek8,7 | — | %0,7 | 7 May 2026 |
34İzleyin | CVE-2026-41675İstismar yok | xmldom: XML node injection through unvalidated processing instruction serializationxmldom · xmldom · CWE-91 | Yüksek8,7 | — | %0,6 | 7 May 2026 |
34İzleyin | CVE-2026-0719İstismar yok | Libsoup: signed to unsigned conversion error leading to stack-based buffer overflow in libsoup ntlm authenticationred hat · red hat enterprise linux 10 · CWE-121 | Yüksek8,6 | — | %0,6 | 8 Oca 2026 |
34İzleyin | CVE-2026-10649İstismar yok | Pacemaker: pacemaker: denial of service via integer overflow in remote message decompressionred hat · red hat enterprise linux 10 · CWE-190 | Yüksek8,6 | — | %0,6 | 16 Haz 2026 |
34İzleyin | CVE-2026-41163İstismar yok | bubblewrap vulnerable to privilege escalation in setuid mode via ptracecontainers · bubblewrap · CWE-269 | Yüksek8,7 | — | %0,4 | 9 May 2026 |
33İzleyin | CVE-2025-13878İstismar yok | Malformed BRID/HHIT records can cause named to terminate unexpectedlyisc · bind 9 · CWE-617 | Yüksek7,5 | — | %9,2 | 21 Oca 2026 |
33İzleyin | CVE-2026-46529Kavram kanıtı | PDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopenmate-desktop · atril · CWE-77 | Yüksek8,4 | — | %0,4 | 10 Haz 2026 |
33İzleyin | CVE-2026-4892İstismar yok | A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code withdnsmasq · dnsmasq · CWE-122 | Yüksek8,4 | — | %0,3 | 11 May 2026 |
33İzleyin | CVE-2026-54369İstismar yok | acl < 2.4.0 Symlink Traversal Privilege Escalation via libacl Functionsacl project · acl · CWE-59 | Yüksek8,4 | — | %0,2 | 29 Haz 2026 |
- CVE-2026-463142Planlayın
Cockpit: cockpit: unauthenticated remote code execution due to ssh command-line argument injection
KritikCVSS 9,8Kavram kanıtıEPSS %9red hat · red hat enterprise linux 107 Nis 2026
- CVE-2026-845037İzleyin
HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file()
KritikCVSS 9,1İstismar yokEPSS %3oalders · http::daemon27 May 2026
- CVE-2025-1481337İzleyin
GOSTCTR implementation unable to process more than 255 blocks correctly
KritikCVSS 9,3İstismar yokEPSS %0legion of the bouncy castle inc. · bc-java15 Nis 2026
- CVE-2026-927736İzleyin
shell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`
KritikCVSS 9,2Kavram kanıtıEPSS %122 May 2026
- CVE-2026-610036İzleyin
Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure
KritikCVSS 9,1İstismar yokEPSS %1python software foundation · cpython13 Nis 2026
- CVE-2025-1026336İzleyin
Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-
KritikCVSS 9,1İstismar yokEPSS %1arm · c1-ultra9 Haz 2026
- CVE-2026-5272035İzleyin
Gstreamer1-plugins-bad-free: gstreamer: heap buffer overflow via crafted vnc server rectangle in librfb
YüksekCVSS 8,8İstismar yokEPSS %1red hat · red hat enterprise linux 1015 Haz 2026
- CVE-2026-559835İzleyin
Non-constant time comparisons risk private key leakage in FrodoKEM.
YüksekCVSS 8,9İstismar yokEPSS %1legion of the bouncy castle inc. · bc-java15 Nis 2026
- CVE-2026-176134İzleyin
Libsoup: stack-based buffer overflow in libsoup multipart response parsingmultipart http response
YüksekCVSS 8,6İstismar yokEPSS %1red hat · red hat enterprise linux 102 Şub 2026
- CVE-2026-4638434İzleyin
iskorotkov/avro: Integer Overflow in Avro Decoder
YüksekCVSS 8,7İstismar yokEPSS %1iskorotkov · avro29 May 2026
- CVE-2026-3181234İzleyin
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
YüksekCVSS 8,7İstismar yokEPSS %1quinn-rs · quinn10 Mar 2026
- CVE-2026-4638534İzleyin
iskorotkov/avro: CPU Exhaustion in Avro Decoder
YüksekCVSS 8,7İstismar yokEPSS %1iskorotkov · avro29 May 2026
- CVE-2026-350534İzleyin
Unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion.
YüksekCVSS 8,7İstismar yokEPSS %1legion of the bouncy castle inc. · bc-java15 Nis 2026
- CVE-2026-4167334İzleyin
xmldom: Denial of service via uncontrolled recursion in XML serialization
YüksekCVSS 8,7İstismar yokEPSS %1xmldom · xmldom7 May 2026
- CVE-2026-536734İzleyin
Ovn: ovn: information disclosure via crafted dhcpv6 packets
YüksekCVSS 8,6İstismar yokEPSS %1red hat · fast datapath for red hat enterprise linux 1024 Nis 2026
- CVE-2026-1214334İzleyin
form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)
YüksekCVSS 8,7İstismar yokEPSS %1form-data · form-data12 Haz 2026
- CVE-2026-4167234İzleyin
xmldom: XML node injection through unvalidated comment serialization
YüksekCVSS 8,7İstismar yokEPSS %1xmldom · xmldom7 May 2026
- CVE-2026-4167534İzleyin
xmldom: XML node injection through unvalidated processing instruction serialization
YüksekCVSS 8,7İstismar yokEPSS %1xmldom · xmldom7 May 2026
- CVE-2026-071934İzleyin
Libsoup: signed to unsigned conversion error leading to stack-based buffer overflow in libsoup ntlm authentication
YüksekCVSS 8,6İstismar yokEPSS %1red hat · red hat enterprise linux 108 Oca 2026
- CVE-2026-1064934İzleyin
Pacemaker: pacemaker: denial of service via integer overflow in remote message decompression
YüksekCVSS 8,6İstismar yokEPSS %1red hat · red hat enterprise linux 1016 Haz 2026
- CVE-2026-4116334İzleyin
bubblewrap vulnerable to privilege escalation in setuid mode via ptrace
YüksekCVSS 8,7İstismar yokEPSS %0containers · bubblewrap9 May 2026
- CVE-2025-1387833İzleyin
Malformed BRID/HHIT records can cause named to terminate unexpectedly
YüksekCVSS 7,5İstismar yokEPSS %9isc · bind 921 Oca 2026
- CVE-2026-4652933İzleyin
PDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopen
YüksekCVSS 8,4Kavram kanıtıEPSS %0mate-desktop · atril10 Haz 2026
- CVE-2026-489233İzleyin
A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with
YüksekCVSS 8,4İstismar yokEPSS %0dnsmasq · dnsmasq11 May 2026
- CVE-2026-5436933İzleyin
acl < 2.4.0 Symlink Traversal Privilege Escalation via libacl Functions
YüksekCVSS 8,4İstismar yokEPSS %0acl project · acl29 Haz 2026