Linux enterprise desktop
This hub aggregates every CVE we track for Linux enterprise desktop, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
461
CVEs tracked
136
Critical
109
High
36
In CISA KEV
Severity distribution
MEDIUM173CRITICAL136HIGH109LOW43
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
1
0
0
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Linux enterprise desktop.
- CVE-2026-31431crypto: algif_aead - Revert to operating out-of-placeKEV7.8
- CVE-2025-32463Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.KEV9.3
- CVE-2022-27239In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges.7.8
- CVE-2021-4034A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users acc...KEV7.8
- CVE-2018-10195lrzsz before version 0.12.21~rc can leak information to the receiving side due to an incorrect length check in the function zsdata that causes a size_t to wrap around.7.1
- CVE-2020-8018User owned /etc in SLES15-SP1-CHOST-BYOS8.4
- CVE-2014-1947Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick 6.5.4 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrar...7.8
- CVE-2006-7246NetworkManager 0.9.x does not pin a certificate's subject to an ESSID when 802.11X authentication is used.6.8
- CVE-2015-5239Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial of service (process crash) via a CLIENT_CUT_TEXT message, which triggers an infinite loop.6.5
- CVE-2019-11038Uninitialized read in gdImageCreateFromXbm5.3
- CVE-2017-16232LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third...7.5
- CVE-2018-19541An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900...8.8
- CVE-2018-19543An issue was discovered in JasPer 2.0.14. There is a heap-based buffer over-read of size 8 in the function jp2_decode in libjasper/jp2/jp2_dec.c.7.8
- CVE-2018-19542An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function jp2_decode in libjasper/jp2/jp2_dec.c, leading to a denial of service.6.5
- CVE-2018-19539An issue was discovered in JasPer 2.0.14. There is an access violation in the function jas_image_readcmpt in libjasper/base/jas_image.c, leading to a denial of service.6.5
Product normalization is registry-driven with AI assist and human review. How it works