Search

Found 27,140 results in 1693ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2025-11579 unknown FIX debian debian sles 8mo ago github.com/nwaples/rardecode versions <=2.1.1 fail to restrict the dictionary size when reading large RAR dictionary sizes, which allows an attacker to provide a specially crafted RAR file and cause …
CVE-2025-11495 medium 5.5 5.5 FIX debian debian sles gnu 8mo ago A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap…
CVE-2025-11494 medium 5.5 5.5 FIX debian debian sles gnu 8mo ago A vulnerability was found in GNU Binutils 2.45. Impacted is the function _bfd_x86_elf_late_size_sections of the file bfd/elfxx-x86.c of the component Linker. The manipulation results in out-of-bounds…
CVE-2025-48964 medium 5.5 FIX rheldebian debian sles 8mo ago Moderate: iputils security update
CVE-2025-11414 medium 5.5 5.5 FIX debian debian sles gnu 8mo ago A vulnerability was determined in GNU Binutils 2.45. Affected by this vulnerability is the function get_link_hash_entry of the file bfd/elflink.c of the component Linker. This manipulation causes out…
CVE-2025-11413 medium 5.5 5.5 FIX debian debian sles gnu 8mo ago A vulnerability was found in GNU Binutils 2.45. Affected is the function elf_link_add_object_symbols of the file bfd/elflink.c of the component Linker. The manipulation results in out-of-bounds read.…
CVE-2025-11412 medium 5.5 5.5 FIX debian debian sles gnu 8mo ago A vulnerability has been found in GNU Binutils 2.45. This impacts the function bfd_elf_gc_record_vtentry of the file bfd/elflink.c of the component Linker. The manipulation leads to out-of-bounds rea…
CVE-2025-61594 medium 5.5 FIX rocky rheldebian debian 8mo ago URI Credential Leakage Bypass over CVE-2025-27221
CVE-2025-39761 medium 5.5 FIX rhel slesdebian debian 8mo ago Moderate: kernel security update
CVE-2025-38351 medium 5.5 FIX rhel slesdebian debian 8mo ago Moderate: kernel security update
CVE-2025-11274 medium 5.5 5.5 debian debian sles assimp 8mo ago A vulnerability was determined in Open Asset Import Library Assimp 6.0.2. Affected is the function Q3DImporter::InternReadFile of the file assimp/code/AssetLib/Q3D/Q3DLoader.cpp. This manipulation ca…
CVE-2025-39931 medium 5.5 5.5 FIX slesdebian debian linux-kernel 8mo ago In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Set merge to zero early in af_alg_sendmsg If an error causes af_alg_sendmsg to abort, ctx->merge may contain a g…
CVE-2025-39929 medium 5.5 5.5 FIX slesdebian debian linux-kernel 8mo ago In the Linux kernel, the following vulnerability has been resolved: smb: client: fix smbdirect_recv_io leak in smbd_negotiate() error path During tests of another unrelated patch I was able to trig…
CVE-2025-54286 unknown FIX debian debian 8mo ago Cross-Site Request Forgery (CSRF) in LXD-UI in Canonical LXD versions >= 5.0 on Linux allows an attacker to create and start container instances without user consent via crafted HTML form submissions…
CVE-2025-54287 unknown FIX debian debian 8mo ago Template Injection in instance snapshot creation component in Canonical LXD (>= 4.0) allows an attacker with instance configuration permissions to read arbitrary files on the host system via special…
CVE-2025-54288 unknown FIX debian debian 8mo ago Information Spoofing in devLXD Server in Canonical LXD versions 4.0 and above on Linux container platforms allows attackers with root privileges within any container to impersonate other containers a…
CVE-2025-54289 unknown FIX debian debian 8mo ago Privilege Escalation in operations API in Canonical LXD <6.5 on multiple platforms allows attacker with read permissions to hijack terminal or console sessions and execute arbitrary commands via WebS…
CVE-2025-54290 unknown FIX debian debian 8mo ago Information disclosure in image export API in Canonical LXD before 6.5 and 5.21.4 on Linux allows network attackers to determine project existence without authentication via crafted requests using wi…
CVE-2025-54293 unknown FIX debian debian 8mo ago Path Traversal in the log file retrieval function in Canonical LXD 5.0 LTS on Linux allows authenticated remote attackers to read arbitrary files on the host system via crafted log file names or symb…
CVE-2025-54291 unknown FIX debian debian 8mo ago Information disclosure in images API in Canonical LXD before 6.5 and 5.21.4 on all platforms allows unauthenticated remote attackers to determine project existence via differing HTTP status code resp…
CVE-2014-6278 unknown 2.5 KEVEXPFIX debian debian 8mo ago GNU Bash contains an OS command injection vulnerability which allows remote attackers to execute arbitrary commands via a crafted environment.
CVE-2025-59682 unknown FIX slesdebian debian 8mo ago An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. The django.utils.archive.extract() function, used by the "startapp --template" and "startproject --templa…
CVE-2025-59681 unknown FIX slesdebian debian 8mo ago Django vulnerable to SQL injection in column aliases
CVE-2025-40928 medium 5.5 FIX rhel rockydebian debian 8mo ago RHSA-2025:17163: perl-JSON-XS security update (Moderate)
CVE-2025-9232 medium 5.9 5.9 FIX slesdebian debian 8mo ago Issue summary: An application using the OpenSSL HTTP client API functions may trigger an out-of-bounds read if the 'no_proxy' environment variable is set and the host portion of the authority compone…
CVE-2025-9231 medium 6.5 6.5 FIX slesdebian debian 8mo ago Issue summary: A timing side-channel which could potentially allow remote recovery of the private key exists in the SM2 algorithm implementation on 64 bit ARM platforms. Impact summary: A timing sid…
CVE-2025-39698 medium 5.5 FIX rhel sles rocky 8mo ago Moderate: kernel security update
CVE-2025-38718 medium 5.5 FIX rhel rocky sles 8mo ago Moderate: kernel security update
CVE-2025-38527 medium 5.5 FIX rhel sles rocky 8mo ago Moderate: kernel security update
CVE-2025-38472 medium 5.5 FIX rhel sles rocky 8mo ago Moderate: kernel security update
CVE-2025-32463 unknown 2.5 KEVEXPFIX slesdebian debian 8mo ago Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.
CVE-2025-11081 medium 5.5 5.5 FIX debian debian sles gnu 8mo ago A vulnerability was detected in GNU Binutils 2.45. This issue affects the function dump_dwarf_section of the file binutils/objdump.c. Performing manipulation results in out-of-bounds read. The attack…
CVE-2025-59842 unknown debian debian 8mo ago jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to version 4.4.8, links generated with LaTeX typesetters in Markd…
CVE-2025-11017 medium 5.5 5.5 debian debian ogre3d 8mo ago A vulnerability was detected in OGRECave Ogre up to 14.4.1. The impacted element is the function Ogre::LogManager::stream of the file /ogre/OgreMain/src/OgreLogManager.cpp. Performing manipulation of…
CVE-2025-11015 medium 5.3 5.3 debian debian 8mo ago A weakness has been identified in OGRECave Ogre up to 14.4.1. Impacted is the function STBIImageCodec::encode of the file /ogre/PlugIns/STBICodec/src/OgreSTBICodec.cpp. This manipulation causes misma…
CVE-2025-11000 medium 5.5 5.5 debian debian openbabel 8mo ago A vulnerability was determined in Open Babel up to 3.1.1. This affects the function PQSFormat::ReadMolecule of the file /src/formats/PQSformat.cpp. This manipulation causes null pointer dereference. …
CVE-2025-10999 medium 5.5 5.5 slesdebian debian openbabel 8mo ago A vulnerability was found in Open Babel up to 3.1.1. The impacted element is the function CacaoFormat::SetHilderbrandt of the file /src/formats/cacaoformat.cpp. The manipulation results in null point…
CVE-2025-10998 medium 5.5 5.5 slesdebian debian openbabel 8mo ago A vulnerability has been found in Open Babel up to 3.1.1. The affected element is the function ChemKinFormat::ReadReactionQualifierLines of the file /src/formats/chemkinformat.cpp. The manipulation l…
CVE-2025-55560 unknown FIX debian debian 8mo ago An issue in pytorch v2.7.0 can lead to a Denial of Service (DoS) when a PyTorch model consists of torch.Tensor.to_sparse() and torch.Tensor.to_dense() and is compiled by Inductor.
CVE-2025-55558 unknown FIX debian debian 8mo ago A buffer overflow occurs in pytorch v2.7.0 when a PyTorch model consists of torch.nn.Conv2d, torch.nn.functional.hardshrink, and torch.Tensor.view-torch.mv() and is compiled by Inductor, leading to a…
CVE-2025-55557 unknown FIX debian debian 8mo ago A Name Error occurs in pytorch v2.7.0 when a PyTorch model consists of torch.cummin and is compiled by Inductor, leading to a Denial of Service (DoS).
CVE-2025-55554 unknown debian debian 8mo ago pytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long().
CVE-2025-55553 unknown FIX debian debian 8mo ago A syntax error in the component proxy_tensor.py of pytorch v2.7.0 allows attackers to cause a Denial of Service (DoS).
CVE-2025-55552 unknown FIX debian debian 8mo ago pytorch v2.8.0 was discovered to display unexpected behavior when the components torch.rot90 and torch.randn_like are used together.
CVE-2025-10911 medium 5.5 5.5 FIX slesdebian debian 8mo ago A use-after-free vulnerability was found in libxslt while parsing xsl nodes that may lead to the dereference of expired pointers and application crash.
CVE-2025-55551 unknown FIX debian debian 9mo ago An issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when performing a slice operation.
CVE-2025-46153 unknown FIX debian debian 9mo ago PyTorch before 3.7.0 has a bernoulli_p decompose function in decompositions.py even though it lacks full consistency with the eager CPU implementation, negatively affecting nn.Dropout1d, nn.Dropout2d…
CVE-2025-46152 unknown FIX debian debian 9mo ago In PyTorch before 2.7.0, bitwise_right_shift produces incorrect output for certain out-of-bounds values of the "other" argument.
CVE-2025-46150 unknown FIX debian debian 9mo ago In PyTorch before 2.7.0, when torch.compile is used, FractionalMaxPool2d has inconsistent results.
CVE-2025-46149 unknown FIX debian debian 9mo ago In PyTorch before 2.7.0, when inductor is used, nn.Fold has an assertion error.
CVE-2025-46148 unknown FIX debian debian 9mo ago In PyTorch through 2.6.0, when eager is used, nn.PairwiseDistance(p=2) produces incorrect results.
CVE-2025-8869 unknown FIX slesdebian debian 9mo ago When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for th…
CVE-2025-58457 unknown FIX debian debian 9mo ago Apache ZooKeeper: Insufficient Permission Check in AdminServer Snapshot/Restore Commands
CVE-2025-58674 medium 5.9 5.9 FIX debian debian 9mo ago Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WordPress allows Stored XSS. WordPress core security team is aware of the issue and working on a …
CVE-2025-58246 medium 4.3 4.3 FIX debian debian 9mo ago Insertion of Sensitive Information Into Sent Data vulnerability in WordPress allows Retrieve Embedded Sensitive Data. The WordPress Core security team is aware of the issue and is already working on …
CVE-2025-10824 medium 5.3 5.3 debian debian 9mo ago A vulnerability was determined in axboe fio up to 3.41. This impacts the function __parse_jobs_ini of the file init.c. Executing manipulation can lead to use after free. The attack needs to be launch…
CVE-2025-39694 medium 5.5 5.5 FIX rhel slesdebian debian 9mo ago Moderate: kernel security update
CVE-2025-38498 medium 5.5 5.5 FIX rhel rocky sles 9mo ago Moderate: kernel security update
CVE-2025-37810 medium 5.5 FIX rhel slesdebian debian 9mo ago Moderate: kernel security update
CVE-2025-10585 unknown 1.5 KEVFIX debian debian 9mo ago Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2023-53125 medium 5.5 FIX rhel slesdebian debian 9mo ago Moderate: kernel security update
CVE-2025-47910 unknown FIX debian debian sles 9mo ago When using http.CrossOriginProtection, the AddInsecureBypassPattern method can unexpectedly bypass more requests than intended. CrossOriginProtection then skips validation, but forwards the original …
CVE-2025-59420 unknown FIX debian debian 9mo ago Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.4, Authlib’s JWS verification accepts tokens that declare unknown critical header parameters (crit), vi…
CVE-2025-9905 unknown debian debian 9mo ago The Keras `Model.load_model` method **silently** ignores `safe_mode=True` and allows arbitrary code execution when a `.h5`/`.hdf5` file is loaded.
CVE-2025-39865 medium 5.5 5.5 FIX slesdebian debian linux-kernel 9mo ago In the Linux kernel, the following vulnerability has been resolved: tee: fix NULL pointer dereference in tee_shm_put tee_shm_put have NULL pointer dereference: __optee_disable_shm_cache --> shm =…
CVE-2025-39857 medium 5.5 5.5 FIX slesdebian debian linux-kernel 9mo ago In the Linux kernel, the following vulnerability has been resolved: net/smc: fix one NULL pointer dereference in smc_ib_is_sg_need_sync() BUG: kernel NULL pointer dereference, address: 000000000000…
CVE-2025-39848 medium 5.5 5.5 FIX slesdebian debian linux-kernel 9mo ago In the Linux kernel, the following vulnerability has been resolved: ax25: properly unshare skbs in ax25_kiss_rcv() Bernard Pidoux reported a regression apparently caused by commit c353e8983e0d ("ne…
CVE-2025-39847 medium 5.5 5.5 FIX slesdebian debian linux-kernel 9mo ago In the Linux kernel, the following vulnerability has been resolved: ppp: fix memory leak in pad_compress_skb If alloc_skb() fails in pad_compress_skb(), it returns NULL without releasing the old sk…
CVE-2025-39846 medium 5.5 5.5 FIX slesdebian debian linux-kernel 9mo ago In the Linux kernel, the following vulnerability has been resolved: pcmcia: Fix a NULL pointer dereference in __iodyn_find_io_region() In __iodyn_find_io_region(), pcmcia_make_resource() is assigne…
CVE-2025-39845 medium 5.5 5.5 FIX slesdebian debian linux-kernel 9mo ago In the Linux kernel, the following vulnerability has been resolved: x86/mm/64: define ARCH_PAGE_TABLE_SYNC_MASK and arch_sync_kernel_mappings() Define ARCH_PAGE_TABLE_SYNC_MASK and arch_sync_kernel…
CVE-2025-39844 medium 5.5 5.5 FIX slesdebian debian linux-kernel 9mo ago In the Linux kernel, the following vulnerability has been resolved: mm: move page table sync declarations to linux/pgtable.h During our internal testing, we started observing intermittent boot fail…
CVE-2025-39842 medium 5.5 5.5 FIX slesdebian debian linux-kernel 9mo ago In the Linux kernel, the following vulnerability has been resolved: ocfs2: prevent release journal inode after journal shutdown Before calling ocfs2_delete_osb(), ocfs2_journal_shutdown() has alrea…
CVE-2025-39838 medium 5.5 5.5 FIX slesdebian debian linux-kernel 9mo ago In the Linux kernel, the following vulnerability has been resolved: cifs: prevent NULL pointer dereference in UTF16 conversion There can be a NULL pointer dereference bug here. NULL is passed to __…
CVE-2025-9906 unknown debian debian 9mo ago Keras is vulnerable to Deserialization of Untrusted Data
CVE-2025-8671 unknown FIX debian debian sles 9mo ago A mismatch caused by client-triggered server-sent stream resets between HTTP/2 specifications and the internal architectures of some HTTP/2 implementations may result in excessive server resource con…
CVE-2025-6395 medium 6.5 6.5 FIX rhel rockydebian debian 9mo ago RHSA-2025:17415: gnutls security, bug fix, and enhancement update (Moderate)
CVE-2025-58767 medium 5.5 FIX rocky rhel sles 9mo ago RHSA-2025:23062: ruby:3.3 security update (Moderate)
CVE-2025-5399 medium 5.5 FIX arch archdebian debian sles 9mo ago Due to a mistake in libcurl's WebSocket code, a malicious server can send a particularly crafted packet which makes libcurl get trapped in an endless busy-loop. There is no other way for the applica…
CVE-2025-53023 medium 5.5 FIX rocky rheldebian debian 9mo ago RHSA-2025:16861: mysql:8.0 security update (Moderate)
CVE-2025-50104 medium 5.5 FIX rocky rheldebian debian 9mo ago Moderate: mysql:8.4 security update
CVE-2025-50102 medium 5.5 FIX rocky rheldebian debian 9mo ago Moderate: mysql:8.4 security update
CVE-2025-50101 medium 5.5 FIX rocky rheldebian debian 9mo ago Moderate: mysql:8.4 security update
CVE-2025-50100 medium 5.5 FIX rocky rheldebian debian 9mo ago Moderate: mysql:8.4 security update
CVE-2025-50099 medium 5.5 FIX rocky rheldebian debian 9mo ago Moderate: mysql:8.4 security update
CVE-2025-50098 medium 5.5 FIX rocky rheldebian debian 9mo ago Moderate: mysql:8.4 security update
CVE-2025-50097 medium 5.5 FIX rocky rheldebian debian 9mo ago Moderate: mysql:8.4 security update
CVE-2025-50096 medium 5.5 FIX rocky rheldebian debian 9mo ago Moderate: mysql:8.4 security update
CVE-2025-50094 medium 5.5 FIX rocky rheldebian debian 9mo ago Moderate: mysql:8.4 security update
CVE-2025-50093 medium 5.5 FIX rocky rheldebian debian 9mo ago Moderate: mysql:8.4 security update
CVE-2025-50092 medium 5.5 FIX rocky rheldebian debian 9mo ago Moderate: mysql:8.4 security update
CVE-2025-50091 medium 5.5 FIX rocky rheldebian debian 9mo ago Moderate: mysql:8.4 security update
CVE-2025-50088 medium 5.5 FIX rocky rheldebian debian 9mo ago Moderate: mysql:8.4 security update
CVE-2025-50087 medium 5.5 FIX rocky rheldebian debian 9mo ago Moderate: mysql:8.4 security update
CVE-2025-50086 medium 5.5 FIX rocky rheldebian debian 9mo ago Moderate: mysql:8.4 security update
CVE-2025-50085 medium 5.5 FIX rocky rheldebian debian 9mo ago Moderate: mysql:8.4 security update
CVE-2025-50084 medium 5.5 FIX rocky rheldebian debian 9mo ago Moderate: mysql:8.4 security update
CVE-2025-50083 medium 5.5 FIX rocky rheldebian debian 9mo ago Moderate: mysql:8.4 security update
CVE-2025-50082 medium 5.5 FIX rocky rheldebian debian 9mo ago Moderate: mysql:8.4 security update
CVE-2025-50081 medium 5.5 FIX rocky rheldebian debian 9mo ago Moderate: mysql:8.4 security update
CVE-2025-50080 medium 5.5 FIX rocky rheldebian debian 9mo ago Moderate: mysql:8.4 security update