Search

Found 24,505 results in 1468ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2025-47914 unknown FIX debian debian sles 7mo ago SSH Agent servers do not validate the size of messages when processing new identity requests, which may cause the program to panic if the message is malformed due to an out of bounds read.
CVE-2025-58181 unknown FIX debian debian sles 7mo ago SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.
CVE-2025-12119 unknown FIX debian debian 7mo ago A mongoc_bulk_operation_t may read invalid memory if large options are passed.
CVE-2025-13223 unknown 1.5 KEVFIX debian debian 7mo ago Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2025-65015 unknown FIX debian debian 7mo ago joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In versions from 1.3.3 to before 1.3.5 and from 1.4.0 to before 1.4.2, the …
CVE-2025-11230 high 8.0 FIX rheldebian debian sles 7mo ago Important: haproxy security update
CVE-2025-65073 unknown FIX debian debian 7mo ago OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization.
CVE-2025-13033 high 7.5 7.5 FIX debian debian 7mo ago A vulnerability was identified in the email parsing library due to improper handling of specially formatted recipient email addresses. An attacker can exploit this flaw by crafting a recipient addres…
CVE-2025-64507 unknown FIX debian debian 7mo ago Incus is a system container and virtual machine manager. An issue in versions prior to 6.0.6 and 6.19.0 affects any Incus user in an environment where an unprivileged user may have root access to a c…
CVE-2025-9230 high 7.5 7.5 FIX rocky rhel sles 7mo ago Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summary: This out-of-bounds read may trigge…
CVE-2025-13020 high 8.0 FIX rocky rheldebian debian 7mo ago Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5.
CVE-2025-13019 high 8.0 FIX rocky rheldebian debian 7mo ago Same-origin policy bypass in the DOM: Workers component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5.
CVE-2025-13018 high 8.0 FIX rocky rheldebian debian 7mo ago Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5.
CVE-2025-13017 high 8.0 FIX rocky rheldebian debian 7mo ago Same-origin policy bypass in the DOM: Notifications component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5.
CVE-2025-13016 high 8.0 FIX rocky rheldebian debian 7mo ago Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5.
CVE-2025-13015 high 8.0 FIX rocky rheldebian debian 7mo ago Spoofing issue in Firefox. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, and Firefox ESR 115.30.
CVE-2025-13014 high 8.0 FIX rocky rheldebian debian 7mo ago Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Firefox ESR 115.30, Thunderbird 145, and Thunderbird 140.5.
CVE-2025-13013 high 8.0 FIX rocky rheldebian debian 7mo ago Mitigation bypass in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Firefox ESR 115.30, Thunderbird 145, and Thunderbird 140.5.
CVE-2025-13012 high 8.0 FIX rocky rheldebian debian 7mo ago Race condition in the Graphics component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Firefox ESR 115.30, Thunderbird 145, and Thunderbird 140.5.
CVE-2025-64500 unknown FIX debian debian 7mo ago Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Symfony's HttpFoundation component defines an object-oriented layer for the HTTP specification. Start…
CVE-2025-63396 unknown debian debian 7mo ago An issue was discovered in PyTorch v2.5 and v2.7.1. Omission of profiler.stop() can cause torch.profiler.profile (PythonTracer) to crash or hang during finalization, leading to a Denial of Service (D…
CVE-2025-40163 unknown FIX slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: sched/deadline: Stop dl_server before CPU goes offline IBM CI tool reported kernel warning[1] when running a CPU removal operatio…
CVE-2025-59089 high 8.0 rocky rheldebian debian 7mo ago RHSA-2025:21140: idm:DL1 security update (Important)
CVE-2025-59088 high 8.0 rocky rheldebian debian 7mo ago RHSA-2025:21140: idm:DL1 security update (Important)
CVE-2025-62168 high 8.0 FIX rocky rhel sles 7mo ago RHSA-2025:19107: squid:4 security update (Important)
CVE-2025-21863 high 7.8 7.8 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2025-21796 high 7.8 7.8 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2025-21739 high 7.8 7.8 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2025-21702 high 7.0 7.0 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2025-21647 high 7.1 7.1 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2025-11561 high 8.0 FIX rhel rocky sles 7mo ago RHSA-2025:19610: sssd security update (Important)
CVE-2024-58072 high 7.8 7.8 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2024-58014 high 7.1 7.1 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2024-56672 high 7.0 7.0 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2024-46744 high 7.8 7.8 FIX rhel sles rocky 7mo ago Moderate: kernel security update
CVE-2023-52356 high 7.5 7.5 FIX rhel rocky sles libtiff 7mo ago Moderate: libtiff security update
CVE-2025-8677 high 8.0 FIX rheldebian debian sles 7mo ago Important: bind security update
CVE-2025-40780 high 8.0 FIX rhel rockydebian debian 7mo ago Important: bind9.18 security update
CVE-2025-40778 high 8.0 FIX rhel rockydebian debian 7mo ago Important: bind9.18 security update
CVE-2025-12875 high 7.8 7.8 FIX slesdebian debian mruby 7mo ago A weakness has been identified in mruby 3.4.0. This vulnerability affects the function ary_fill_exec of the file mrbgems/mruby-array-ext/src/array.c. Executing a manipulation of the argument start/le…
CVE-2025-67897 unknown FIX debian debian 7mo ago In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted me…
CVE-2025-52881 high 8.0 FIX rocky rhel sles aws 7mo ago RHSA-2025:23543: container-tools:rhel8 security update (Important)
CVE-2025-52565 high 8.0 FIX rocky rhel sles aws 7mo ago RHSA-2025:21232: container-tools:rhel8 security update (Important)
CVE-2025-31133 high 8.0 FIX rocky rhel sles aws 7mo ago RHSA-2025:21232: container-tools:rhel8 security update (Important)
CVE-2025-11277 high 7.8 7.8 FIX debian debian rhel sles assimp 7mo ago Moderate: qt5-qt3d security update
CVE-2025-12745 high 7.8 7.8 debian debian bellard 7mo ago A weakness has been identified in QuickJS up to eb2c89087def1829ed99630cb14b549d7a98408c. This affects the function js_array_buffer_slice of the file quickjs.c. This manipulation causes buffer over-r…
CVE-2025-64459 unknown 1.0 EXPFIX debian debian 7mo ago Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects.
CVE-2025-64458 unknown FIX debian debian 7mo ago Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows
CVE-2025-4945 high 8.0 FIX rhel rockydebian debian 7mo ago RHSA-2025:19714: libsoup security update (Important)
CVE-2025-11021 high 8.0 FIX rhel rocky sles 7mo ago RHSA-2025:19714: libsoup security update (Important)
CVE-2025-62231 high 8.0 FIX rhel rocky sles 7mo ago A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If an attacker sends sp…
CVE-2025-62230 high 8.0 FIX rhel rocky sles 7mo ago A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources…
CVE-2025-62229 high 8.0 FIX rhel rocky sles 7mo ago A flaw was found in the X.Org X server and Xwayland when processing X11 Present extension notifications. Improper error handling during notification creation can leave dangling pointers that lead to …
CVE-2025-39702 high 7.0 7.0 FIX rhel slesdebian debian 7mo ago Moderate: kernel security update
CVE-2025-57108 unknown debian debian 7mo ago Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader. The vulnerability manifests during mesh object copy operations where vector me…
CVE-2025-57107 unknown debian debian 7mo ago Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap buffer overflow vulnerability in vtkGLTFDocumentLoader. When processing specially crafted GLTF files, the copy constructor of Accesso…
CVE-2025-57106 unknown debian debian 7mo ago Kitware VTK (Visualization Toolkit) up to 9.5.0 is vulnerable to Buffer Overflow in vtkGLTFDocumentLoader. The vulnerability occurs in the BufferDataExtractionWorker template function when processing…
CVE-2025-6176 high 8.0 FIX rocky rheldebian debian 7mo ago RHSA-2026:2389: brotli security update (Important)
CVE-2025-13327 unknown FIX slesdebian debian 7mo ago A flaw was found in uv. This vulnerability allows an attacker to execute malicious code during package resolution or installation via specially crafted ZIP (Zipped Information Package) archives that …
CVE-2025-61724 unknown FIX debian debian sles 7mo ago The Reader.ReadResponse function constructs a response string through repeated string concatenation of lines. When the number of lines in a response is large, this can cause excessive CPU consumption.
CVE-2025-58188 unknown FIX debian debian sles google 7mo ago Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal method. This affects programs which validate arb…
CVE-2025-58186 unknown FIX debian debian sles 7mo ago Despite HTTP headers having a default limit of 1MB, the number of cookies that can be parsed does not have a limit. By sending a lot of very small cookies such as "a=;", an attacker can make an HTTP …
CVE-2025-58185 unknown FIX debian debian sles 7mo ago Parsing a maliciously crafted DER payload could allocate large amounts of memory, causing memory exhaustion.
CVE-2025-47912 unknown FIX debian debian sles 7mo ago The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL. RFC 3986 permits IPv6 addresses to be included within the host compon…
CVE-2025-61723 unknown FIX debian debian sles google 7mo ago The processing time for parsing some invalid inputs scales non-linearly with respect to the size of the input. This affects programs which parse untrusted PEM inputs.
CVE-2025-58189 unknown FIX debian debian sles 7mo ago When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.
CVE-2025-58187 unknown FIX debian debian sles google 7mo ago Due to the design of the name constraint checking algorithm, the processing time of some inputs scale non-linearly with respect to the size of the certificate. This affects programs which validate ar…
CVE-2025-61725 unknown FIX debian debian sles 7mo ago The ParseAddress function constructs domain-literal address components through repeated string concatenation. When parsing large domain-literal components, this can cause excessive CPU consumption.
CVE-2025-49844 high 8.0 FIX rocky rhel sles 7mo ago RHSA-2025:19238: redis:6 security update (Important)
CVE-2025-46819 high 8.0 FIX rocky rhel sles 7mo ago RHSA-2025:19238: redis:6 security update (Important)
CVE-2025-46818 high 8.0 FIX rocky rhel sles 7mo ago RHSA-2025:19238: redis:6 security update (Important)
CVE-2025-46817 high 8.0 FIX rocky rhel sles 7mo ago RHSA-2025:19238: redis:6 security update (Important)
CVE-2025-62727 unknown FIX slesdebian debian 7mo ago Starlette is a lightweight ASGI framework/toolkit. Starting in version 0.39.0 and prior to version 0.49.1 , an unauthenticated attacker can send a crafted HTTP Range header that triggers quadratic-ti…
CVE-2025-62171 unknown FIX debian debian sles 7mo ago ImageMagick is an open source software suite for displaying, converting, and editing raster image files. In ImageMagick versions prior to 7.1.2-7 and 6.9.13-32, an integer overflow vulnerability exis…
CVE-2025-40039 unknown FIX slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix race condition in RPC handle list access The 'sess->rpc_handle_list' XArray manages RPC handles within a ksmbd session…
CVE-2025-9900 high 8.0 FIX rocky rhel sles 7mo ago RHSA-2025:19906: mingw-libtiff security update (Important)
CVE-2025-8176 high 7.8 7.8 FIX rocky rhel sles libtiff 7mo ago RHSA-2025:20034: libtiff security update (Important)
CVE-2025-62594 unknown FIX debian debian sles 7mo ago ImageMagick is a software suite to create, edit, compose, or convert bitmap images. ImageMagick versions prior to 7.1.2-8 are vulnerable to denial-of-service due to unsigned integer underflow and div…
CVE-2025-12205 high 7.8 7.8 debian debian kamailio 7mo ago A vulnerability was detected in Kamailio 5.5. The affected element is the function sr_push_yy_state of the file src/core/cfg.lex of the component Configuration File Handler. The manipulation results …
CVE-2025-12204 high 7.8 7.8 debian debian kamailio 7mo ago A security vulnerability has been detected in Kamailio 5.5. Impacted is the function rve_destroy of the file src/core/rvalue.c of the component Configuration File Handler. The manipulation leads to h…
CVE-2025-12194 unknown debian debian sles 8mo ago Bouncy Castle Vulnerable to Uncontrolled Resource Consumption
CVE-2025-40022 unknown FIX slesdebian debian 8mo ago In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Fix incorrect boolean values in af_alg_ctx Commit 1b34cbbf4f01 ("crypto: af_alg - Disallow concurrent writes in …
CVE-2025-53066 high 7.5 7.5 FIX rhel slesdebian debian oracle 8mo ago Moderate: java-1.8.0-openjdk security update
CVE-2025-39849 high 7.8 7.8 FIX rhel rocky sles 8mo ago Moderate: kernel security update
CVE-2025-39841 high 7.8 7.8 FIX rhel rocky sles 8mo ago Moderate: kernel security update
CVE-2025-39817 high 7.1 7.1 FIX rhel rocky sles 8mo ago Moderate: kernel security update
CVE-2025-41254 unknown debian debian 8mo ago Spring Framework STOMP over WebSocket applications may allow attackers to send unauthorized messages
CVE-2025-59419 unknown FIX slesdebian debian 8mo ago Netty has SMTP Command Injection Vulnerability that Allows Email Forgery
CVE-2025-39997 unknown FIX slesdebian debian 8mo ago In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: fix race condition to UAF in snd_usbmidi_free The previous commit 0718a78f6a9f ("ALSA: usb-audio: Kill timer pro…
CVE-2025-39977 unknown FIX slesdebian debian 8mo ago In the Linux kernel, the following vulnerability has been resolved: futex: Prevent use-after-free during requeue-PI syzbot managed to trigger the following race: T1 …
CVE-2025-43419 high 8.0 FIX rocky rhel sles 8mo ago The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing maliciously crafted web con…
CVE-2025-43356 high 8.0 FIX rhel rocky sles 8mo ago The issue was addressed with improved handling of caches. This issue is fixed in Safari 26, iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. A website…
CVE-2025-43343 high 8.0 FIX rhel rocky sles 8mo ago The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing maliciously crafted web con…
CVE-2025-43342 high 8.0 FIX rhel rocky sles 8mo ago A correctness issue was addressed with improved checks. This issue is fixed in Safari 26, iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing …
CVE-2025-43272 high 8.0 FIX rhel rocky sles 8mo ago The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26, visionOS 26, watchOS 26. Processing maliciously crafted web content may …
CVE-2025-31277 high 9.5 KEVFIX rhel slesdebian debian 8mo ago The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously …
CVE-2025-31223 high 8.0 FIX rhel slesdebian debian 8mo ago The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted w…
CVE-2025-11715 high 8.0 FIX rocky rhelalmalinux almalinux 8mo ago Memory safety bugs present in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence of memory corruption and we presume that with enough effort…
CVE-2025-11714 high 8.0 FIX rocky rhelalmalinux almalinux 8mo ago Memory safety bugs present in Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence of memory corruption and we presume tha…
CVE-2025-11712 high 8.0 FIX rocky rhelalmalinux almalinux 8mo ago A malicious page could have used the type attribute of an OBJECT tag to override the default browser behavior when encountering a web resource served without a content-type. This could have contribut…