Skip to content
← All tracked CVEs

Updated 05:00

High severity

High15d SLA

Our service-level agreement (SLA) gives a high vulnerability a fix within 15 days of publication. 416 CVEs are tracked here: open, or fixed in the last 30 days.

Status
CVEStatusSummaryReleaseClock startedDeadlineFixedTime to fix
Fixed within SLAFFmpeg 7.0–8.1.2 vf_quirc heap OOB write via mismatched PGS/SUP frame dimensionssecure-packages-26.05Aug 11, 2026Aug 26, 2026Aug 15, 20263 days
Fixed within SLAHeap OOB write in FFmpeg PNG/APNG encoders <=8.1.2 via malicious eXIf chunk, RCEsecure-packages-26.05Aug 11, 2026Aug 26, 2026Aug 15, 20263 days
Fixed within SLAFFmpeg ≤8.1.2 MACE6 signed integer overflow leads to heap OOB write via CAFsecure-packages-26.05Aug 11, 2026Aug 26, 2026Aug 15, 20263 days
Fixed within SLAFFmpeg <=8.1.2 LCL/ZLIB decoder info leak via short zlib decompressionsecure-packages-26.05Aug 11, 2026Aug 26, 2026Aug 15, 20263 days
Fixed within SLAFFmpeg ≤8.1.2 IAMF demuxer OOM via crafted count_label during format probingsecure-packages-26.05Aug 11, 2026Aug 26, 2026Aug 15, 20263 days
Fixed within SLAFFmpeg <=8.1.2 vf_hqdn3d heap out-of-bounds write with -reinit_filter 0 and growing framessecure-packages-26.05Aug 11, 2026Aug 26, 2026Aug 15, 20263 days
Fixed within SLAFFmpeg 3.0–8.1.2 vf_swaprect OOB write on NV12 odd-width frames causes heap corruptionsecure-packages-26.05Aug 11, 2026Aug 26, 2026Aug 15, 20263 days
Fixed within SLAFFmpeg 3.4-8.1.2 vf_floodfill OOB write on dynamic frames with -reinit_filter 0secure-packages-26.05Aug 11, 2026Aug 26, 2026Aug 15, 20263 days
Fixed within SLAFFmpeg <=8.1.2 OOB write via crafted ffconcat (-safe 0) in TY demuxersecure-packages-26.05Aug 11, 2026Aug 26, 2026Aug 15, 20263 days
Fixed within SLAFFmpeg 2.7–8.1.2 TDSC decoder OOB write on frame dimension changes enables RCEsecure-packages-26.05Aug 11, 2026Aug 26, 2026Aug 15, 20263 days
Fixed within SLAHigh severity use-after-free in Aura allows sandbox escape on Chrome Linux <151.0.7922.109secure-packages-rollingAug 12, 2026Aug 27, 2026Aug 14, 20262 days
Fixed within SLAUse-after-free in Chrome HTML before 151.0.7922.109 enables remote heap corruptionsecure-packages-rollingAug 12, 2026Aug 27, 2026Aug 14, 20262 days
Fixed within SLAUse-after-free in Chrome Views pre-151.0.7922.109 allows remote heap corruption via crafted HTMLsecure-packages-rollingAug 12, 2026Aug 27, 2026Aug 14, 20262 days
Fixed within SLAAura use-after-free in Chrome Linux pre-151.0.7922.109 enables sandbox escape via HTML from compromised renderersecure-packages-26.05Aug 12, 2026Aug 27, 2026Aug 14, 20262 days
Fixed within SLAUse-after-free in Chrome HTML enables remote heap corruption before 151.0.7922.109secure-packages-26.05Aug 12, 2026Aug 27, 2026Aug 14, 20262 days
Fixed within SLAChrome Views use-after-free before 151.0.7922.109 allows heap corruption via crafted HTML and gesturessecure-packages-26.05Aug 12, 2026Aug 27, 2026Aug 14, 20262 days
Fixed within SLAmlx5e XSK: Unprotected ICOSQ IRQ triggering races with NAPI, causing ICOSQ CQE errorssecure-packages-25.11Aug 12, 2026Aug 27, 2026Aug 14, 20262 days
Fixed within SLAType mismatch in nx_crypto_ctx_exit triggers kernel oops via nx_crypto_ctx_shash_exitsecure-packages-25.11Aug 4, 2026Aug 19, 2026Aug 14, 202610 days
Fixed within SLAfbdev omap2: omapfb_mmap use-after-free race with OMAPFB_SETUP_PLANE mapping freed memorysecure-packages-25.11Aug 4, 2026Aug 19, 2026Aug 14, 202610 days
Fixed within SLAf2fs: Race reading nat_entry flags causes incorrect inode dentry mark and fsck inconsistency after checkpointsecure-packages-25.11Aug 4, 2026Aug 19, 2026Aug 14, 202610 days
Fixed within SLAFFmpeg vf_quirc heap out-of-bounds write via crafted PGS/SUP with mismatched frame dimensionssecure-packages-25.11Aug 10, 2026Aug 25, 2026Aug 14, 20264 days
Fixed within SLAFFmpeg ≤8.1.2 PNG/APNG encoder eXIf handling causes heap OOB write, crash/RCEsecure-packages-25.11Aug 10, 2026Aug 25, 2026Aug 14, 20264 days
Fixed within SLAFFmpeg ≤8.1.2 MACE6 CAF signed integer overflow causes heap OOB write, RCE risksecure-packages-25.11Aug 10, 2026Aug 25, 2026Aug 14, 20264 days
Fixed within SLAFFmpeg ≤8.1.2 LCL/ZLIB decoder information disclosure: short inflate leaks uninitialized heapsecure-packages-25.11Aug 10, 2026Aug 25, 2026Aug 14, 20264 days
Fixed within SLAFFmpeg ≤8.1.2 IAMF demuxer OOM via crafted count_label causing massive allocation during probingsecure-packages-25.11Aug 10, 2026Aug 25, 2026Aug 14, 20264 days
Fixed within SLAFFmpeg <=8.1.2 vf_hqdn3d heap OOB write on resolution increase with -reinit_filter 0 disabledsecure-packages-25.11Aug 10, 2026Aug 25, 2026Aug 14, 20264 days
Fixed within SLAFFmpeg 3.0–8.1.2 vf_swaprect OOB write with odd-width NV12 frames causes heap corruptionsecure-packages-25.11Aug 10, 2026Aug 25, 2026Aug 14, 20264 days
Fixed within SLAFFmpeg 3.4–8.1.2 OOB write in vf_floodfill with -reinit_filter 0secure-packages-25.11Aug 10, 2026Aug 25, 2026Aug 14, 20264 days
Fixed within SLAFFmpeg <=8.1.2 OOB write processing ffconcat -safe 0 via TY demuxersecure-packages-25.11Aug 10, 2026Aug 25, 2026Aug 14, 20264 days
Fixed within SLAFFmpeg 2.7–8.1.2 TDSC decoder out-of-bounds write via crafted AVI frame dimension changessecure-packages-25.11Aug 10, 2026Aug 25, 2026Aug 14, 20264 days
Fixed within SLAfbdev omap2: omapfb_mmap race with OMAPFB_SETUP_PLANE causes use-after-freesecure-packages-26.05Aug 4, 2026Aug 19, 2026Aug 12, 20268 days
Fixed within SLAfbdev omap2 omapfb_mmap race with OMAPFB_SETUP_PLANE leads to use-after-freesecure-packages-rollingAug 4, 2026Aug 19, 2026Aug 12, 20268 days
Fixed within SLAUse-after-free in Aura allows sandbox escape after renderer compromise in Chrome Linux <151.0.7922.109secure-packages-25.11Aug 12, 2026Aug 27, 2026Aug 12, 2026same day
Fixed within SLAChrome pre-151.0.7922.109 HTML use-after-free allows remote heap corruption via crafted pagesecure-packages-25.11Aug 12, 2026Aug 27, 2026Aug 12, 2026same day
Fixed within SLAChrome pre-151.0.7922.109 Views UAF enables remote heap corruption via crafted HTML page, requires UI gesturessecure-packages-25.11Aug 12, 2026Aug 27, 2026Aug 12, 2026same day
Fixed within SLAcJSON <=1.7.19 cJSON_Compare exponential time on deep nested equal objects causes DoSsecure-packages-rollingAug 5, 2026Aug 20, 2026Aug 12, 20267 days
Fixed within SLAcJSON through 1.7.19: Untrusted RFC 6902 patch triggers recursion, stack exhaustion DoSsecure-packages-rollingAug 5, 2026Aug 20, 2026Aug 12, 20267 days
Fixed within SLAcJSON 1.7.19 and earlier: cJSON_Compare exponential complexity allows DoS via nested JSONsecure-packages-26.05Aug 5, 2026Aug 20, 2026Aug 12, 20267 days
Fixed within SLAcJSON <=1.7.19: Untrusted JSON Patch via cJSONUtils_ApplyPatches triggers uncontrolled recursion and stack exhaustion DoSsecure-packages-26.05Aug 5, 2026Aug 20, 2026Aug 12, 20267 days
Fixed within SLAcJSON <=1.7.19: cJSON_Compare exponential-time recursion causes DoS on deeply nested JSONsecure-packages-25.11Aug 5, 2026Aug 20, 2026Aug 12, 20267 days
Fixed within SLAcJSON <=1.7.19 DoS: stack exhaustion from uncontrolled recursion applying RFC6902 JSON Patchsecure-packages-25.11Aug 5, 2026Aug 20, 2026Aug 12, 20267 days
Fixed within SLAglibc ≤ 2.43 ungetwc wrong buffer causes under-read with overlapping encodings, data leak/crashsecure-packages-26.05Aug 4, 2026Aug 19, 2026Aug 12, 20267 days
Fixed within SLAglibc <=2.43 iconv assertion failure on IBM1390/IBM1399 may allow remote crashsecure-packages-26.05Aug 4, 2026Aug 19, 2026Aug 12, 20267 days
Fixed within SLAsecure-packages-rollingAug 10, 2026Aug 25, 2026Aug 12, 20261 day
Fixed within SLAsecure-packages-rollingAug 10, 2026Aug 25, 2026Aug 12, 20261 day
Fixed within SLAChrome UI input validation flaw enables sandbox escape from renderer via crafted HTML pre-151.0.7922.109secure-packages-26.05Aug 11, 2026Aug 26, 2026Aug 11, 2026same day
Fixed within SLASkia use-after-free in Chrome <151.0.7922.109 enables sandboxed RCE via crafted HTMLsecure-packages-26.05Aug 11, 2026Aug 26, 2026Aug 11, 2026same day
Fixed within SLAV8 integer overflow enables sandboxed arbitrary code execution in Chrome <151.0.7922.109 via crafted HTMLsecure-packages-26.05Aug 11, 2026Aug 26, 2026Aug 11, 2026same day
Fixed within SLASkia out-of-bounds write enables sandbox escape from compromised renderer in Chrome <151.0.7922.109secure-packages-26.05Aug 11, 2026Aug 26, 2026Aug 11, 2026same day
Fixed within SLAUse-after-free in Chrome Views enables sandbox escape from compromised renderer via crafted HTMLsecure-packages-26.05Aug 11, 2026Aug 26, 2026Aug 11, 2026same day