VendorsRed Hatenterprise_linux10.0
Vulnerabilities

Red Hat Enterprise Linux 10.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

200CVEs
CVE-2026-2625
Rust-rpm-sequoia: rust-rpm-sequoia: denial of service via crafted rpm file during signature verification
Published 2026-04-03 · Analyzed
5.5EPSS 0.001
CVE-2026-26104
Udisks: missing authorization check allows unprivileged users to back up luks headers via udisks d-bus api
Published 2026-02-25 · Modified
5.5EPSS 0.001
CVE-2026-18651
389-ds-base: 389-ds-base: sasl plain bind installs connection credentials before account-lock check, allowing continued access as a locked account
Published 2026-08-03 · Analyzed
5.4EPSS 0.003
CVE-2026-12528
389-ds-base: 389-ds-base: heap-buffer-overflows in __aclp__normalize_acltxt()
Published 2026-06-17 · Analyzed
5.4EPSS 0.002
CVE-2025-32989
Gnutls: vulnerability in gnutls sct extension parsing
Published 2025-07-10 · Modified
5.3EPSS 0.013
CVE-2026-59848
Libssh: libssh: denial of service via sftp responses with unknown request ids
Published 2026-07-21 · Modified
5.3EPSS 0.006
CVE-2026-59842
Libssh: libssh: information disclosure via short gssapi curve25519 public key
Published 2026-07-21 · Analyzed
5.3EPSS 0.005
CVE-2026-14940
389-ds-base: 389-ds-base: heap-buffer-overflow in dn normalization via quoted multivalued rdn
Published 2026-07-07 · Analyzed
5.3EPSS 0.005
CVE-2026-2443
Libsoup: out-of-bounds read in libsoup handle_partial_get() leading to heap information disclosure
Published 2026-02-13 · Modified
5.3EPSS 0.004
CVE-2026-2708
Libsoup: libsoup: http request smuggling via duplicate content-length headers
Published 2026-04-23 · Analyzed
5.3EPSS 0.004
CVE-2026-12969
Dnsmasq: dnsmasq: out-of-bounds read in find_soa() due to missing extrabytes validation
Published 2026-06-23 · Analyzed
5.3EPSS 0.004
CVE-2026-71227
Libkcapi: infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return
Published 2026-08-05 · Modified
5.1EPSS 0.002
CVE-2026-57965
Spice-vdagent: integer overflow in udscs_write() leading to heap buffer overflow
Published 2026-06-29 · Analyzed
5.1EPSS 0.002
CVE-2026-11791
389-ds-base: 389-ds-base: use-after-free in schema reload via attr_syntax_swap_ht()
Published 2026-06-18 · Modified
5.0EPSS 0.004
CVE-2025-5917
Libarchive: off by one error in build_ustar_entry_name() at archive_write_set_format_pax.c
Published 2025-06-09 · Modified
5.0EPSS 0.002
CVE-2026-6845
Binutils: binutils: denial of service via crafted elf file
Published 2026-04-22 · Modified
5.0EPSS 0.001
CVE-2026-11790
389-ds-base: 389-ds-base: pbkdf2 password storage plugin unbounded iteration count denial of service
Published 2026-06-09 · Modified
4.9EPSS 0.003
CVE-2026-12549
Libsoup: incomplete fix for cve-2026-2443: range suffix overflow in libsoup soupserver
Published 2026-06-22 · Analyzed
4.8EPSS 0.004
CVE-2025-4598
Systemd-coredump: race condition that allows a local attacker to crash a suid program and gain read access to the resulting core dump
Published 2025-05-30 · Modified
4.7EPSS 0.012
CVE-2026-57966
Spice-vdagent: path traversal in file transfer via unsanitized filename
Published 2026-06-29 · Analyzed
4.4EPSS 0.002
CVE-2026-12892
Gstreamer1-plugins-bad: gstreamer1-plugins-bad: 1-byte heap out-of-bounds read in h.264 nal extension slice parser
Published 2026-06-23 · Analyzed
4.4EPSS 0.002
CVE-2026-13002
Dnsmasq: infinite loop dos in dnssec nsec/nsec3 type bitmap parsing
Published 2026-08-14 · Analyzed
4.4EPSS 0.001
CVE-2026-18508
Tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite
Published 2026-08-03 · Modified
4.4EPSS 0.001
CVE-2026-14969
389-ds-base: 389-ds-base: static initialization vector in aes-cbc/3des-cbc attribute encryption
Published 2026-07-07 · Analyzed
4.4EPSS 0.001
CVE-2026-18477
Tar: tar: toctou in incremental dumpdir 'x' rename handling allows restore path escape
Published 2026-08-03 · Modified
4.4EPSS 0.001
CVE-2026-12891
Gstreamer1-plugins-bad: gstreamer1-plugins-bad: global buffer overflow (oob read) in h.266/vvc vui parameter parser
Published 2026-06-23 · Analyzed
4.3EPSS 0.004
CVE-2026-11785
389-ds-base: 389-ds-base: partial stack address information leak via ber_printf type confusion in sso token handler
Published 2026-06-09 · Modified
4.3EPSS 0.002
CVE-2026-12548
Libsoup: heap out-of-bounds read in libsoup due to integer truncation
Published 2026-07-21 · Analyzed
4.2EPSS 0.003
CVE-2026-59846
Libssh: libssh: information disclosure via proxycommand %r username expansion
Published 2026-07-21 · Modified
3.9EPSS 0.002
CVE-2026-3832
Gnutls: gnutls: security bypass allows acceptance of revoked server certificates via crafted ocsp response
Published 2026-04-30 · Modified
3.7EPSS 0.009
CVE-2026-55654
Openssh: heap out-of-bounds read in red hat enterprise linux versions of openssh gssapi indicator cleanup due to missing null sentinel termination
Published 2026-06-23 · Modified
3.7EPSS 0.007
CVE-2026-0989
Libxml2: unbounded relaxng include recursion leading to stack overflow
Published 2026-01-15 · Analyzed
3.7EPSS 0.005
CVE-2026-15041
389-ds-base: 389-ds-base: non-constant-time comparison in pbkdf2-sha256 password verification
Published 2026-07-08 · Analyzed
3.7EPSS 0.004
CVE-2025-8283
Netavark: podman: netavark may resolve hostnames to unexpected hosts
Published 2025-07-28 · Modified
3.7EPSS 0.003
CVE-2025-6199
Gdk-pixbuf: uninitialized memory disclosure in gdkpixbuf gif lzw decoder
Published 2025-06-17 · Modified
3.3EPSS 0.002
CVE-2026-0965
Libssh: libssh: denial of service via improper configuration file handling
Published 2026-03-26 · Modified
3.3EPSS 0.002
CVE-2026-68744
Sssd: sssd: nss responder uninitialized heap disclosure in initgroups reply
Published 2026-08-04 · Analyzed
3.3EPSS 0.001
CVE-2026-0968
Libssh: libssh: denial of service due to malformed sftp message
Published 2026-03-26 · Modified
3.1EPSS 0.004
CVE-2026-0992
Libxml2: libxml2: denial of service via crafted xml catalogs
Published 2026-01-15 · Analyzed
2.9EPSS 0.005
CVE-2025-6170
Libxml2: stack buffer overflow in xmllint interactive shell command handling
Published 2025-06-16 · Modified
2.5EPSS 0.003
← Prev5 / 5