Red Hat / Jboss Core Services
36 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-6732 | Libxml2: libxml2: denial of service via crafted xsd-validated document | HIGH | 7.5 | Apr 23, 2026 |
| CVE-2026-0992 | Libxml2: libxml2: denial of service via crafted xml catalogs | LOW | 2.9 | Jan 15, 2026 |
| CVE-2026-0989 | Libxml2: unbounded relaxng include recursion leading to stack overflow | LOW | 3.7 | Jan 15, 2026 |
| CVE-2026-0990 | Libxml2: libxml2: denial of service via uncontrolled recursion in xml catalog processing | MEDIUM | 5.9 | Jan 15, 2026 |
| CVE-2025-6170 | Libxml2: stack buffer overflow in xmllint interactive shell command handling | LOW | 2.5 | Jun 16, 2025 |
| CVE-2025-6021 | Libxml2: integer overflow in xmlbuildqname() leads to stack buffer overflow in libxml2 | HIGH | 7.5 | Jun 12, 2025 |
| CVE-2023-44487 KEV | HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) | MEDIUM | 6.9 | Oct 10, 2023 |
| CVE-2021-40438 KEV | mod_proxy SSRF | CRITICAL | 9.0 | Sep 16, 2021 |
| CVE-2021-3541 | libxml2: Exponential entity expansion attack bypasses all existing protection mechanisms | MEDIUM | 6.5 | Jul 9, 2021 |
| CVE-2021-3516 | libxml2: Use-after-free in xmlEncodeEntitiesInternal() in entities.c | HIGH | 7.8 | Jun 1, 2021 |
| CVE-2020-25710 | openldap: assertion failure in CSN normalization with invalid input | HIGH | 7.5 | May 28, 2021 |
| CVE-2021-3517 | libxml2: Heap-based buffer overflow in xmlEncodeEntitiesInternal() in entities.c | HIGH | 8.6 | May 19, 2021 |
| CVE-2020-25709 | openldap: assertion failure in Certificate List syntax validation | HIGH | 7.5 | May 18, 2021 |
| CVE-2021-3518 | libxml2: Use-after-free in xmlXIncludeDoProcess() in xinclude.c | HIGH | 8.8 | May 18, 2021 |
| CVE-2021-3537 | libxml2: NULL pointer dereference when post-validating mixed content parsed in recovery mode | HIGH | 7.5 | May 14, 2021 |
| CVE-2019-9518 | Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service | HIGH | 7.5 | Aug 13, 2019 |
| CVE-2019-9517 | Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service | HIGH | 7.5 | Aug 13, 2019 |
| CVE-2019-9516 | Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service | MEDIUM | 6.5 | Aug 13, 2019 |
| CVE-2019-9515 | Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service | HIGH | 7.5 | Aug 13, 2019 |
| CVE-2019-9513 | Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service | HIGH | 7.5 | Aug 13, 2019 |
| CVE-2019-9511 | Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service | HIGH | 7.5 | Aug 13, 2019 |
| CVE-2019-9514 | Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service | HIGH | 7.5 | Aug 13, 2019 |
| CVE-2019-0197 | httpd: mod_http2: possible crash on late upgrade | MEDIUM | 4.2 | Jun 11, 2019 |
| CVE-2019-0211 KEV | httpd: privilege escalation from modules scripts | HIGH | 7.8 | Apr 8, 2019 |
| CVE-2018-17189 | httpd: mod_http2: DoS via slow, unneeded request bodies | MEDIUM | 5.3 | Jan 30, 2019 |
Showing 1 to 25 of 36 CVEs