Skip to content
All tracked CVEs

Updated 14:01

395 in progress

Severity
CVEStatusSeveritySummaryDistribution
In progressCriticaltarfile erroneously converts AREGTYPE to DIRTYPE during GNU longname/longlink, misinterpreting crafted archivessecure-packages-26.05
In progressCriticaltarfile misinterprets crafted archives by normalizing AREGTYPE during GNUTYPE_LONGNAME/LONGLINK processingsecure-packages-rolling
In progressMediumConfigParser write() allows key/value injection via CR in attacker-controlled multiline valuessecure-packages-25.11
In progressHighGHSA-rgw5-rvv9-x895: brace-expansion 5.0.8 CVE-2026-14257: maxLength bypass causing uncatchable OOM and CPU DoSsecure-packages-25.11
In progressHighcJSON v1.7.19 32-bit print_string_ptr integer overflow; heap overflow via cJSON_PrintBuffered, RCE.secure-packages-25.11
In progressHighcJSON 32-bit integer overflow in print_string_ptr causes heap overflow in cJSON_PrintBufferedsecure-packages-rolling
In progressHighcJSON 32-bit integer overflow in print_string_ptr causes heap overflow; possible RCE (v1.7.19)secure-packages-26.05
In progressHighGStreamer MRF parser out-of-bounds write enables remote code execution (ZDI-CAN-29510)secure-packages-26.05
In progressHighGStreamer MRF parsing out-of-bounds write leads to user-assisted remote code executionsecure-packages-25.11
In progressHighGStreamer MRF parsing heap buffer overflow enables RCE via crafted file (ZDI-CAN-29608)secure-packages-26.05
In progressHighGStreamer MRF parsing heap buffer overflow allows RCE via malicious files (ZDI-CAN-29608)secure-packages-25.11
In progressHighGStreamer OGG parser stack-based buffer overflow allows remote code execution; user interaction requiredsecure-packages-26.05
In progressHighGStreamer OGG parser stack-based buffer overflow allows RCE when opening malicious file or webpagesecure-packages-25.11
In progressHighGStreamer PNG parser heap overflow allows RCE via malicious PNG; user interaction requiredsecure-packages-26.05
In progressHighGStreamer PNG parsing heap buffer overflow enables remote code execution (ZDI-CAN-29581)secure-packages-25.11
In progressHighUse-after-free RCE in GStreamer rtpsbcdepay RTP payload handling (ZDI-CAN-29787)secure-packages-26.05
In progressHighGStreamer rtpsbcdepay use-after-free allows RCE via RTP payload processing (ZDI-CAN-29787)secure-packages-25.11
In progressMediumIncomplete CVE-2024-47778 fix causes OOB read in gst_wavparse_adtl_chunk when lsize oddsecure-packages-26.05
In progressHighGStreamer ASF demuxer heap-based buffer overflow allows RCE via malformed ASF stream headerssecure-packages-26.05
In progressHighGStreamer RIFF palette integer overflow in AVI parsing enables remote code execution ZDI-CAN-28854secure-packages-26.05
In progressHighGStreamer RealMedia demuxer out-of-bounds write enables RCE via malformed video packetssecure-packages-26.05
In progressHighGStreamer DVB subtitles coordinate handling out-of-bounds write enables remote code execution (ZDI-CAN-28838)secure-packages-26.05
In progressHighGStreamer H.266 codec parser stack-based overflow allows RCE via unchecked decoding unit lengthsecure-packages-26.05
In progressHighGStreamer JPEG parser Huffman table processing heap overflow enables remote code execution (ZDI-CAN-28840)secure-packages-26.05
In progressHighGStreamer rtpqdm2depay X-QDM RTP packetid OOB write allows RCE (ZDI-CAN-28850)secure-packages-26.05
In progressHighGStreamer H.266 parser integer underflow enables remote code execution via picture partitionssecure-packages-26.05
In progressHighGStreamer rtpqdm2depay heap-based buffer overflow allows RCE via malformed X-QDM RTP payloads ZDI-CAN-28851secure-packages-26.05
In progressHighGStreamer H.266 APS unit parsing out-of-bounds write allows remote code execution (ZDI-CAN-28911)secure-packages-26.05
In progressHighIncomplete CVE-2026-0672 fix allows control characters via Morsel.update, |=, unpickling; BaseCookie.js_output lacks output validationsecure-packages-26.05
In progressHighwebbrowser.open() accepted leading-dash URLs causing potential command-line option injectionsecure-packages-26.05
In progressHighsecure-packages-rolling
In progressLowGHSA-p688-r7jv-fm6f: Cargo sparse index URL normalization flaw may send credentials to attacker-controlled .git registry (CVE-2026-5222)secure-packages-26.05
In progressLowGHSA-p688-r7jv-fm6f: Cargo sparse index URL normalization flaw may send credentials to attacker-controlled .git registry (CVE-2026-5222)secure-packages-26.05
In progressLowGHSA-p688-r7jv-fm6f: Cargo sparse registry URL normalization leaks credentials to attacker-controlled .git registry (CVE-2026-5222)secure-packages-25.11
In progressMediumGHSA-jq42-7mfv-hm57: Cargo tarball symlink extraction allows overwriting other crates' cache from same registry (CVE-2026-5223)secure-packages-26.05
In progressMediumGHSA-jq42-7mfv-hm57: Cargo tarball symlink extraction allows overwriting other crates' cache from same registry (CVE-2026-5223)secure-packages-26.05
In progressMediumGNU coreutils uniq out-of-bounds read with -w multibyte input causing crash and heap exposuresecure-packages-25.11
In progressMediumGNU coreutils unexpand integer overflow causes heap buffer overflow with large -t valuessecure-packages-25.11
In progressMediumlibssh OpenSSL backend AES-GCM finalization bug allows undetected MITM plaintext modificationsecure-packages-25.11
In progressHighAFS symlink get_link lacks proper locking and RCU, causing races, leaks, update conflictssecure-packages-26.05
In progressHighAFS symlink handling lacks locking and RCU barriers, causing races and memory leakssecure-packages-rolling
In progressHighLinux kernel netfs_read_folio() fails to wait on writeback, misinterpreting dirty flag and folio->privatesecure-packages-25.11
In progressMediumnetfs_write_begin() request reference leak on netfs_wait_for_read() errorsecure-packages-25.11
In progressCriticalLinux kernel netfs_read_to_pagecache() doesn't pause new subrequests after subrequest failuresecure-packages-25.11
In progressCriticalMissing barriers in lockless netfs stream->subrequests list cause stale subreq->flags accesssecure-packages-26.05
In progressCriticalLinux kernel netfs lockless subrequests list lacks barriers, risking stale subreq->flags readssecure-packages-rolling
In progressCriticalnetfs: Lockless stream->subrequests access lacks memory barriers, risking stale subreq->flags readssecure-packages-25.11
In progressCriticalnetfs_retry_read_subrequests and netfs_retry_write_stream missing locking when adding subrequestssecure-packages-26.05
In progressCriticalnetfs: Missing lock when retrying adding subrequests to stream->subrequests causes race conditionssecure-packages-rolling
In progressCriticalLinux netfs: Missing lock when adding subrequests to stream during retry operationssecure-packages-25.11

Contact sales

Provide us with some basic details and we'll follow up with you about , usually within one business day.

We'll only use this to get back to you. See our privacy policy (opens in a new tab). This site is protected by reCAPTCHA and the Google Privacy Policy (opens in a new tab) and Terms of Service (opens in a new tab) apply.