VEX records
Browse vendor VEX statements available in this Vulnerability-Lookup instance and pivot to the related vulnerability.
73931 VEX records
API response| Vulnerability | Source | Title | Product status | Imported | Links |
|---|---|---|---|---|---|
| CVE-2021-46923 | redhat_vex | kernel: fs/mount_setattr: always cleanup mount_kattr | known affected: 44 known not affected: 154 | 2026-10-02T02:24:24+00:00 | Vulnerability · Source |
| CVE-2021-46920 | redhat_vex | kernel: clobbering of SWERR overflow bit on writeback | known affected: 50 known not affected: 148 | 2026-10-02T02:24:22+00:00 | Vulnerability · Source |
| CVE-2021-46918 | redhat_vex | kernel: MSIX permission entry on shutdown | known affected: 50 known not affected: 148 | 2026-10-02T02:24:20+00:00 | Vulnerability · Source |
| CVE-2026-102010 | redhat_vex | gcc-toolset-15-gcc: gcc: gcc-toolset-16: gcc: Denial of Service via use-after-free in binary heap erase_if | fixed: 83 known affected: 270 known not affected: 22 | 2026-10-02T02:22:52+00:00 | Vulnerability · Source |
| CVE-2026-102824 | redhat_vex | russh: russh: Cryptographic fallback bypass via missing public key validation | fixed: 7 | 2026-10-02T02:22:45+00:00 | Vulnerability · Source |
| CVE-2026-54411 | redhat_vex | linux-pam: Plaintext password recovery via timing discrepancy in pam_userdb module | fixed: 384 known affected: 5 | 2026-10-02T02:20:23+00:00 | Vulnerability · Source |
| CVE-2026-48864 | redhat_vex | libsolv: Heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data | fixed: 617 known affected: 1 known not affected: 503 | 2026-10-02T02:20:22+00:00 | Vulnerability · Source |
| CVE-2026-46483 | redhat_vex | vim: command injection when decompressing .tgz archives | fixed: 489 known affected: 1 known not affected: 206 | 2026-10-02T02:20:19+00:00 | Vulnerability · Source |
| CVE-2026-44431 | redhat_vex | urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers | fixed: 760 known affected: 44 known not affected: 1342 | 2026-10-02T02:20:16+00:00 | Vulnerability · Source |
| CVE-2026-42015 | redhat_vex | gnutls: gnutls: Memory corruption due to off-by-one error in PKCS#12 bag handling | fixed: 816 known affected: 7 known not affected: 63 under investigation: 1 | 2026-10-02T02:20:15+00:00 | Vulnerability · Source |
| CVE-2026-42014 | redhat_vex | gnutls: gnutls: Use-after-free in gnutls_pkcs11_token_set_pin | fixed: 816 known affected: 7 known not affected: 63 under investigation: 1 | 2026-10-02T02:20:12+00:00 | Vulnerability · Source |
| CVE-2026-42013 | redhat_vex | gnutls: gnutls: Certificate validation bypass due to oversized Subject Alternative Name | fixed: 833 known affected: 6 known not affected: 63 under investigation: 1 | 2026-10-02T02:20:09+00:00 | Vulnerability · Source |
| CVE-2026-42012 | redhat_vex | gnutls: gnutls: Certificate validation bypass due to improper handling of URI and SRV SANs | fixed: 816 known affected: 7 known not affected: 63 under investigation: 1 | 2026-10-02T02:20:07+00:00 | Vulnerability · Source |
| CVE-2026-42011 | redhat_vex | gnutls: gnutls: Security bypass due to incorrect name constraint handling | fixed: 833 known affected: 1 known not affected: 68 under investigation: 1 | 2026-10-02T02:20:03+00:00 | Vulnerability · Source |
| CVE-2026-41989 | redhat_vex | Libgcrypt: Libgcrypt: Denial of Service and buffer overflow via crafted ECDH ciphertext | fixed: 212 known not affected: 204 | 2026-10-02T02:20:02+00:00 | Vulnerability · Source |
| CVE-2026-41411 | redhat_vex | vim: Command injection allows arbitrary code execution via malicious tag files | fixed: 515 known affected: 1 known not affected: 184 | 2026-10-02T02:20:00+00:00 | Vulnerability · Source |
| CVE-2026-40356 | redhat_vex | krb5: MIT Kerberos 5 (krb5): Denial of Service via integer underflow and out-of-bounds read | fixed: 644 known affected: 18 known not affected: 67 | 2026-10-02T02:19:58+00:00 | Vulnerability · Source |
| CVE-2026-35414 | redhat_vex | OpenSSH: OpenSSH: Security bypass via mishandling of authorized_keys principals option | fixed: 963 known affected: 19 known not affected: 162 | 2026-10-02T02:19:55+00:00 | Vulnerability · Source |
| CVE-2026-35177 | redhat_vex | vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass | fixed: 487 known affected: 2 known not affected: 207 | 2026-10-02T02:19:50+00:00 | Vulnerability · Source |
| CVE-2026-33636 | redhat_vex | libpng: libpng: Information disclosure and denial of service via out-of-bounds read/write in Neon palette expansion | fixed: 3672 known affected: 19 known not affected: 197 | 2026-10-02T02:19:48+00:00 | Vulnerability · Source |
| CVE-2026-33416 | redhat_vex | libpng: libpng: Arbitrary code execution due to use-after-free vulnerability | fixed: 4163 known affected: 19 known not affected: 9 | 2026-10-02T02:19:45+00:00 | Vulnerability · Source |
| CVE-2026-31790 | redhat_vex | openssl: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key | fixed: 306 known affected: 6 known not affected: 59 | 2026-10-02T02:19:43+00:00 | Vulnerability · Source |
| CVE-2026-29111 | redhat_vex | systemd: systemd: Arbitrary code execution or Denial of Service via spurious IPC API call data | fixed: 1419 known affected: 73 known not affected: 33 under investigation: 1 | 2026-10-02T02:19:39+00:00 | Vulnerability · Source |
| CVE-2026-14164 | redhat_vex | libarchive: Double-Free Vulnerability in RAR5 Decompression Logic via dangling filtered_buf pointer in init_unpack() | fixed: 480 known not affected: 22 | 2026-10-02T02:19:38+00:00 | Vulnerability · Source |
| CVE-2026-5450 | redhat_vex | glibc: glibc: Heap Buffer Overflow in `scanf` with `%mc` format specifier and large width | fixed: 8754 known affected: 3 known not affected: 7 | 2026-10-02T02:19:35+00:00 | Vulnerability · Source |
| CVE-2026-5260 | redhat_vex | gnutls: gnutls: Information disclosure via heap overread in RSA key exchange | fixed: 804 known affected: 7 known not affected: 62 | 2026-10-02T02:19:33+00:00 | Vulnerability · Source |
| CVE-2026-3833 | redhat_vex | gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison | fixed: 842 known affected: 1 known not affected: 68 under investigation: 1 | 2026-10-02T02:19:30+00:00 | Vulnerability · Source |
| CVE-2025-14512 | redhat_vex | glib: Integer Overflow in GLib GIO Attribute Escaping Causes Heap Buffer Overflow | fixed: 896 known affected: 29 known not affected: 1 under investigation: 1 | 2026-10-02T02:19:29+00:00 | Vulnerability · Source |
| CVE-2025-14087 | redhat_vex | glib: GLib: Buffer underflow in GVariant parser leads to heap corruption | fixed: 948 known affected: 15 known not affected: 25 under investigation: 1 | 2026-10-02T02:19:24+00:00 | Vulnerability · Source |
| CVE-2023-52355 | redhat_vex | libtiff: TIFFRasterScanlineSize64 produce too-big size and could cause OOM | fixed: 189 known affected: 17 known not affected: 2 | 2026-10-02T02:19:23+00:00 | Vulnerability · Source |
| CVE-2025-10911 | redhat_vex | libxslt: use-after-free with key data stored cross-RVT | fixed: 241 known affected: 10 known not affected: 9 | 2026-10-02T02:19:23+00:00 | Vulnerability · Source |
| CVE-2026-59858 | redhat_vex | vim: Vim: Arbitrary command execution via crafted tags file in C omni-completion | fixed: 320 known not affected: 273 | 2026-10-02T02:17:43+00:00 | Vulnerability · Source |
| CVE-2026-59856 | redhat_vex | vim: Vim: Arbitrary code execution via crafted PHP file in omni-completion | fixed: 288 known affected: 6 known not affected: 207 | 2026-10-02T02:17:39+00:00 | Vulnerability · Source |
| CVE-2026-58015 | redhat_vex | glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive | fixed: 757 known affected: 15 known not affected: 6 | 2026-10-02T02:17:36+00:00 | Vulnerability · Source |
| CVE-2026-58014 | redhat_vex | glib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list" | fixed: 761 known affected: 15 known not affected: 6 | 2026-10-02T02:17:34+00:00 | Vulnerability · Source |
| CVE-2026-58013 | redhat_vex | glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend" | fixed: 752 known affected: 15 known not affected: 6 | 2026-10-02T02:17:30+00:00 | Vulnerability · Source |
| CVE-2026-58012 | redhat_vex | glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char() | fixed: 752 known affected: 15 known not affected: 6 | 2026-10-02T02:17:28+00:00 | Vulnerability · Source |
| CVE-2026-58011 | redhat_vex | glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid GDateTime | fixed: 752 known affected: 15 known not affected: 6 | 2026-10-02T02:17:24+00:00 | Vulnerability · Source |
| CVE-2026-58010 | redhat_vex | glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal() | fixed: 752 known affected: 15 known not affected: 6 | 2026-10-02T02:17:20+00:00 | Vulnerability · Source |
| CVE-2026-57455 | redhat_vex | vim: Vim: Denial of Service via stack out-of-bounds write in spell_soundfold_sofo() | fixed: 333 known not affected: 260 | 2026-10-02T02:17:18+00:00 | Vulnerability · Source |
| CVE-2026-55693 | redhat_vex | vim: Vim: Out-of-bounds Write in Spell File Word Count | fixed: 333 known not affected: 260 | 2026-10-02T02:17:14+00:00 | Vulnerability · Source |
| CVE-2026-16118 | redhat_vex | xdgmime: heap-based buffer overflow in _xdg_mime_magic_parse_magic_line() in xdgmimemagic.c | fixed: 581 known affected: 25 known not affected: 4 | 2026-10-02T02:17:13+00:00 | Vulnerability · Source |
| CVE-2026-15588 | redhat_vex | GDBusServer: glib2: GDBusServer pre-authentication DoS via unbounded SASL line buffering | fixed: 754 known affected: 22 known not affected: 5 | 2026-10-02T02:17:12+00:00 | Vulnerability · Source |
| CVE-2026-78679 | redhat_vex | GitPython: GitPython: Arbitrary file read via TagReference.create() | fixed: 52 known affected: 45 known not affected: 829 | 2026-10-02T02:16:43+00:00 | Vulnerability · Source |
| CVE-2026-100690 | redhat_vex | github.com/gohugoio/hugo: Hugo: Arbitrary file read via symbolic link sandbox escape | fixed: 7 known affected: 2 known not affected: 100 | 2026-10-02T02:15:02+00:00 | Vulnerability · Source |
| CVE-2026-39244 | redhat_vex | adm-zip: adm-zip: Denial of Service via crafted ZIP file leading to excessive memory allocation | fixed: 12 known affected: 20 known not affected: 87 | 2026-10-02T02:15:01+00:00 | Vulnerability · Source |
| CVE-2026-45623 | redhat_vex | postcss: PostCSS: Information disclosure and denial of service via crafted CSS input | fixed: 198 known affected: 26 known not affected: 8223 | 2026-10-02T02:15:01+00:00 | Vulnerability · Source |
| CVE-2026-19553 | redhat_vex | python: python: Certificate verification bypass via missing server_hostname validation in SSLContext.wrap_bio() | fixed: 95 known affected: 139 | 2026-10-02T02:12:36+00:00 | Vulnerability · Source |
| CVE-2026-76835 | redhat_vex | github.com/oauth2-proxy/oauth2-proxy: OAuth2 Proxy 7.15.2 through 7.15.4 Authentication Bypass via X-Forwarded-Uri Under the Default Trusted Proxy Set | fixed: 3 known affected: 1 known not affected: 3 | 2026-10-02T02:09:39+00:00 | Vulnerability · Source |
| CVE-2026-73077 | redhat_vex | vim: Vim: Arbitrary Code Execution via Insecure Shell Command Handling | fixed: 270 known not affected: 153 | 2026-10-02T02:07:41+00:00 | Vulnerability · Source |