Rosa virtualization
This hub aggregates every CVE we track for Rosa virtualization, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
Operating Systemson-prem
546
CVEs tracked
83
Critical
246
High
9
In CISA KEV
Severity distribution
HIGH246MEDIUM199CRITICAL83LOW18
Monthly trend
14
7
7
2
2
2
6
2
2
11
2
7
9
0
3
1
1
1
0
0
0
0
0
0
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Rosa virtualization.
- CVE-2025-66293LIBPNG has an out-of-bounds read in png_image_read_composite7.1
- CVE-2025-65018LIBPNG is vulnerable to a heap buffer overflow in `png_combine_row` triggered via `png_image_finish_read`7.1
- CVE-2025-40778Cache poisoning attacks with unsolicited RRs8.6
- CVE-2025-9086Out of bounds read for cookie path7.5
- CVE-2025-58364cups: Remote DoS via null dereference6.5
- CVE-2025-58060cups has Authentication bypass with AuthType Negotiate8.0
- CVE-2025-5994Cache poisoning via the ECS-enabled Rebirthday Attack7.5
- CVE-2025-53906Vim has path traversal issue with zip.vim and special crafted zip archives4.1
- CVE-2025-53905Vim has path traversial issue with tar.vim and special crafted tar files4.1
- CVE-2025-6965Integer Truncation on SQLite9.8
- CVE-2025-6395Gnutls: null pointer dereference in _gnutls_figure_common_ciphersuite()6.5
- CVE-2025-32990Gnutls: vulnerability in gnutls certtool template parsing6.5
- CVE-2025-32988Gnutls: vulnerability in gnutls othername san export6.5
- CVE-2025-7345Gdk‑pixbuf: heap‑buffer‑overflow in gdk‑pixbuf7.5
- CVE-2025-5372Libssh: incorrect return code handling in ssh_kdf() in libssh5.0
Product normalization is registry-driven with AI assist and human review. How it works