Skip to content
Noroxi

enterprise linux records

90 published records for vendor enterprise linux.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
10
With a fix record
92.2%
Median publish → KEV
No record has entered KEV

All records

90 records
  • Cockpit: cockpit: unauthenticated remote code execution due to ssh command-line argument injection

    CriticalCVSS 9.8Proof of conceptEPSS 9%

    red hat · red hat enterprise linux 10Apr 7, 2026

  • CVE-2026-8450
    37Monitor

    HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file()

    CriticalCVSS 9.1No exploitEPSS 3%

    oalders · http::daemonMay 27, 2026

  • GOSTCTR implementation unable to process more than 255 blocks correctly

    CriticalCVSS 9.3No exploitEPSS 0%

    legion of the bouncy castle inc. · bc-javaApr 15, 2026

  • CVE-2026-9277
    36Monitor

    shell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`

    CriticalCVSS 9.2Proof of conceptEPSS 1%

    May 22, 2026

  • CVE-2026-6100
    36Monitor

    Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure

    CriticalCVSS 9.1No exploitEPSS 1%

    python software foundation · cpythonApr 13, 2026

  • Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-

    CriticalCVSS 9.1No exploitEPSS 1%

    arm · c1-ultraJun 9, 2026

  • Gstreamer1-plugins-bad-free: gstreamer: heap buffer overflow via crafted vnc server rectangle in librfb

    HighCVSS 8.8No exploitEPSS 1%

    red hat · red hat enterprise linux 10Jun 15, 2026

  • CVE-2026-5598
    35Monitor

    Non-constant time comparisons risk private key leakage in FrodoKEM.

    HighCVSS 8.9No exploitEPSS 1%

    legion of the bouncy castle inc. · bc-javaApr 15, 2026

  • CVE-2026-1761
    34Monitor

    Libsoup: stack-based buffer overflow in libsoup multipart response parsingmultipart http response

    HighCVSS 8.6No exploitEPSS 1%

    red hat · red hat enterprise linux 10Feb 2, 2026

  • iskorotkov/avro: Integer Overflow in Avro Decoder

    HighCVSS 8.7No exploitEPSS 1%

    iskorotkov · avroMay 29, 2026

  • Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing

    HighCVSS 8.7No exploitEPSS 1%

    quinn-rs · quinnMar 10, 2026

  • iskorotkov/avro: CPU Exhaustion in Avro Decoder

    HighCVSS 8.7No exploitEPSS 1%

    iskorotkov · avroMay 29, 2026

  • CVE-2026-3505
    34Monitor

    Unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion.

    HighCVSS 8.7No exploitEPSS 1%

    legion of the bouncy castle inc. · bc-javaApr 15, 2026

  • xmldom: Denial of service via uncontrolled recursion in XML serialization

    HighCVSS 8.7No exploitEPSS 1%

    xmldom · xmldomMay 7, 2026

  • CVE-2026-5367
    34Monitor

    Ovn: ovn: information disclosure via crafted dhcpv6 packets

    HighCVSS 8.6No exploitEPSS 1%

    red hat · fast datapath for red hat enterprise linux 10Apr 24, 2026

  • form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)

    HighCVSS 8.7No exploitEPSS 1%

    form-data · form-dataJun 12, 2026

  • xmldom: XML node injection through unvalidated comment serialization

    HighCVSS 8.7No exploitEPSS 1%

    xmldom · xmldomMay 7, 2026

  • xmldom: XML node injection through unvalidated processing instruction serialization

    HighCVSS 8.7No exploitEPSS 1%

    xmldom · xmldomMay 7, 2026

  • CVE-2026-0719
    34Monitor

    Libsoup: signed to unsigned conversion error leading to stack-based buffer overflow in libsoup ntlm authentication

    HighCVSS 8.6No exploitEPSS 1%

    red hat · red hat enterprise linux 10Jan 8, 2026

  • Pacemaker: pacemaker: denial of service via integer overflow in remote message decompression

    HighCVSS 8.6No exploitEPSS 1%

    red hat · red hat enterprise linux 10Jun 16, 2026

  • bubblewrap vulnerable to privilege escalation in setuid mode via ptrace

    HighCVSS 8.7No exploitEPSS 0%

    containers · bubblewrapMay 9, 2026

  • Malformed BRID/HHIT records can cause named to terminate unexpectedly

    HighCVSS 7.5No exploitEPSS 9%

    isc · bind 9Jan 21, 2026

  • PDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopen

    HighCVSS 8.4Proof of conceptEPSS 0%

    mate-desktop · atrilJun 10, 2026

  • CVE-2026-4892
    33Monitor

    A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with

    HighCVSS 8.4No exploitEPSS 0%

    dnsmasq · dnsmasqMay 11, 2026

  • acl < 2.4.0 Symlink Traversal Privilege Escalation via libacl Functions

    HighCVSS 8.4No exploitEPSS 0%

    acl project · aclJun 29, 2026