A denial-of-service flaw was found in gnome-remote-desktop. An unauthenticated remote attacker can open RDP connections without completing the handshake and retain the connection-throttling slots indefinitely because no pre-authentication handshake deadline is
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 8 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 9 | any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84502 | 9.9 CRITICAL | Automation-controller: automation-controller-container: automation-controller: project scm |
| CVE-2026-84474 | 9.9 CRITICAL | Automation-controller: automation-controller-container: automation-controller: view_jobtem |
| CVE-2026-96275 | 8.8 HIGH | Flatpak: flatpak: arbitrary write access as root via extra-data extraction |
| CVE-2026-84683 | 8.7 HIGH | Automation-controller: automation-controller-container: automation-controller: stored cros |
| CVE-2026-84691 | 8.7 HIGH | Automation-controller: automation-controller-container: automation-controller: format stri |
| CVE-2026-76648 | 8.5 HIGH | Automation-controller: automation-controller-container: aap controller: copyapiview.post() |
| CVE-2026-84486 | 8.2 HIGH | Automation-controller: automation-controller-container: automation-controller: unauthentic |
| CVE-2026-96442 | 7.8 HIGH | Emacs: emacs: arbitrary code execution, incomplete fix for cve-2024-53920 |
| CVE-2026-96512 | 7.8 HIGH | Sudo: sudo: tz environment variable allows bypass of notbefore/notafter time-based authori |
| CVE-2026-84499 | 7.7 HIGH | Automation-controller: automation-controller-container: automation-controller: write-only |
| CVE-2026-88830 | 7.5 HIGH | Busybox: busybox: tls montgomery reduction allocates bytes instead of digits, causing a pr |
| CVE-2026-88832 | 7.3 HIGH | Busybox: busybox: romfs volume id parsing performs unbounded memcpy into fixed-size label |
| CVE-2026-96445 | 6.8 MEDIUM | Keycloak-services: keycloak-services: conditional otp skip-header policy evaluated against |
| CVE-2026-88839 | 6.7 MEDIUM | Busybox: busybox: passwd/group parser writes heap pointers out of bounds due to stale toke |
| CVE-2026-88837 | 6.5 MEDIUM | Busybox: busybox: httpd misidentifies yescrypt password hashes as plaintext, inverting aut |
| CVE-2026-88835 | 6.1 MEDIUM | Busybox: busybox: dpkg read_package_field() steps past nul terminator, causing out-of-boun |
| CVE-2026-88840 | 5.3 MEDIUM | Busybox: busybox: tls ssl_server reads one byte out of bounds when parsing truncated clien |
| CVE-2026-88831 | 5.3 MEDIUM | Busybox: busybox: httpd silently fails open when ip deny rules contain invalid cidr prefix |
| CVE-2026-71459 | 5.0 MEDIUM | Automation-controller: automation-controller-container: automation-controller: jobjobevent |
| CVE-2026-71458 | 5.0 MEDIUM | Automation-controller: automation-controller-container: automation-controller: named-url 4 |
Showing top 20 of 31 CVEs. View all on vendor page → →
No comments yet