-Infinity
0

Vendor Risk Score

See how rpm compares to other vendors in security performance

View Risk Score →

RPM RPMCommand Injection, OS Command Injection

Risk 19
Severity
4
First published (updated )

RPM RPMA crafted RPM file can trigger a Rust panic in the OpenPGP signature parsing code (librpm_sequoia) d…

Risk 19
Severity
4
First published (updated )

dnf5 dnf5daemon-serverLocal Root Exploit via Configuration Dictionary

Risk 62
Severity
8.4
First published (updated )

redhat/rpmRPM Project RPM could allow a local authenticated attacker to gain elevated privileges on the system…

Risk 60
Severity
6.7
First published (updated )

redhat Enterprise LinuxRace Condition

Risk 56
Severity
6.4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

redhat Enterprise LinuxRPM Project RPM could allow a local authenticated attacker to gain elevated privileges on the system…

Risk 60
Severity
6.7
First published (updated )

rpm rpmRPM does not require subkeys to have a valid binding signature. This could potentially result in a s…

Risk 28
Severity
4.7
First published (updated )

RPM RPM Package ManagerRPM does not require subkeys to have a valid binding signature. This could potentially result in a s…

Risk 18
Severity
4
First published (updated )

RPM RPM Package ManagerA flaw was found in rpm. Given an RPM package signed by a trusted key, it is possible to modify it s…

Risk 19
Severity
4
First published (updated )

RPM RPMA flaw was found in rpm. Given an RPM package signed by a trusted key, it is possible to modify it s…

Risk 65
Severity
7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

IBM QRadar SIEMlibdnf does its own signature verification, but this can be tricked by placing a signature in the ma…

Risk 72
Severity
7.5
First published (updated )

IBM Cloud Pak for Security (CP4S)RPM Project RPM could allow a remote attacker to bypass security restrictions, caused by a flaw in t…

Risk 42
Severity
6.1
First published (updated )

IBM QRadar SIEMMissing length checks in `hdrblobInit()` which may be able to cause memory unsafety.

Risk 31
Severity
4.9
First published (updated )

RPM libcompsUse After Free

Risk 77
Severity
8.8
First published (updated )

rpm rpmIt was found that rpm did not properly handle RPM installations when a destination path was a symbol…

Risk 69
Severity
7.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

redhat Enterprise Linux DesktopPath Traversal

Risk 79
Severity
9.3
First published (updated )

rpm rpmIt was found that versions of rpm before 4.13.0.2 use temporary files with predictable names when in…

Risk 69
Severity
7.8
First published (updated )

rpm rpmBuffer Overflow, Integer Overflow

Risk 87
Severity
10
First published (updated )

RPM RPMRace Condition

Risk 69
Severity
7.6
First published (updated )

rpm rpmThe rpmpkgRead function in lib/package.c in RPM 4.10.x before 4.10.2 does not return an error code i…

Risk 22
Severity
4.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

RPM RPMInput Validation

Risk 47
Severity
6.8
First published (updated )

RPM RPMInput Validation

Risk 47
Severity
6.8
First published (updated )

RPM RPMThe headerVerifyInfo function in lib/header.c in RPM before 4.9.1.3 allows remote attackers to cause…

Risk 48
Severity
6.8
First published (updated )

RPM RPMCode Injection, Buffer Overflow

Risk 82
Severity
9.3
First published (updated )

rpm rpmrpmbuild in RPM 4.8.0 and earlier does not properly parse the syntax of spec files, which allows use…

Risk 35
Severity
5.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

RPM RPMCreated attachment 418879 [details] SRPM for testing this bug Description of problem: When RPM repl…

Risk 18
Severity
4
First published (updated )

RPM RPMlib/fsm.c in RPM before 4.4.3 does not properly reset the metadata of an executable file during dele…

Risk 65
Severity
7.2
First published (updated )

RPM RPMlib/fsm.c in RPM 4.8.0 and unspecified 4.7.x and 4.6.x versions, and RPM before 4.4.3, does not prop…

Risk 65
Severity
7.2
First published (updated )

rpm rpmlib/fsm.c in RPM 4.8.0 and earlier does not properly reset the metadata of an executable file during…

Risk 63
Severity
7.2
First published (updated )

rpm rpmlib/fsm.c in RPM 4.8.0 and earlier does not properly reset the metadata of an executable file during…

Risk 63
Severity
7.2
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203