Search

Found 15,589 results in 1041ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2025-57108 unknown debian debian 7mo ago Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader. The vulnerability manifests during mesh object copy operations where vector me…
CVE-2025-57107 unknown debian debian 7mo ago Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap buffer overflow vulnerability in vtkGLTFDocumentLoader. When processing specially crafted GLTF files, the copy constructor of Accesso…
CVE-2025-57106 unknown debian debian 7mo ago Kitware VTK (Visualization Toolkit) up to 9.5.0 is vulnerable to Buffer Overflow in vtkGLTFDocumentLoader. The vulnerability occurs in the BufferDataExtractionWorker template function when processing…
CVE-2025-13327 unknown FIX slesdebian debian 7mo ago A flaw was found in uv. This vulnerability allows an attacker to execute malicious code during package resolution or installation via specially crafted ZIP (Zipped Information Package) archives that …
CVE-2025-61724 unknown FIX debian debian sles 7mo ago The Reader.ReadResponse function constructs a response string through repeated string concatenation of lines. When the number of lines in a response is large, this can cause excessive CPU consumption.
CVE-2025-58188 unknown FIX debian debian sles google 7mo ago Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal method. This affects programs which validate arb…
CVE-2025-58186 unknown FIX debian debian sles 7mo ago Despite HTTP headers having a default limit of 1MB, the number of cookies that can be parsed does not have a limit. By sending a lot of very small cookies such as "a=;", an attacker can make an HTTP …
CVE-2025-58185 unknown FIX debian debian sles 7mo ago Parsing a maliciously crafted DER payload could allocate large amounts of memory, causing memory exhaustion.
CVE-2025-47912 unknown FIX debian debian sles 7mo ago The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL. RFC 3986 permits IPv6 addresses to be included within the host compon…
CVE-2025-61723 unknown FIX debian debian sles google 7mo ago The processing time for parsing some invalid inputs scales non-linearly with respect to the size of the input. This affects programs which parse untrusted PEM inputs.
CVE-2025-58189 unknown FIX debian debian sles 7mo ago When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.
CVE-2025-58187 unknown FIX debian debian sles google 7mo ago Due to the design of the name constraint checking algorithm, the processing time of some inputs scale non-linearly with respect to the size of the certificate. This affects programs which validate ar…
CVE-2025-61725 unknown FIX debian debian sles 7mo ago The ParseAddress function constructs domain-literal address components through repeated string concatenation. When parsing large domain-literal components, this can cause excessive CPU consumption.
CVE-2025-62727 unknown FIX slesdebian debian 7mo ago Starlette is a lightweight ASGI framework/toolkit. Starting in version 0.39.0 and prior to version 0.49.1 , an unauthenticated attacker can send a crafted HTTP Range header that triggers quadratic-ti…
CVE-2025-62171 unknown FIX debian debian sles 7mo ago ImageMagick is an open source software suite for displaying, converting, and editing raster image files. In ImageMagick versions prior to 7.1.2-7 and 6.9.13-32, an integer overflow vulnerability exis…
CVE-2025-40039 unknown FIX slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix race condition in RPC handle list access The 'sess->rpc_handle_list' XArray manages RPC handles within a ksmbd session…
CVE-2025-62594 unknown FIX debian debian sles 7mo ago ImageMagick is a software suite to create, edit, compose, or convert bitmap images. ImageMagick versions prior to 7.1.2-8 are vulnerable to denial-of-service due to unsigned integer underflow and div…
CVE-2025-12194 unknown debian debian sles 7mo ago Bouncy Castle Vulnerable to Uncontrolled Resource Consumption
CVE-2025-40022 unknown FIX slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Fix incorrect boolean values in af_alg_ctx Commit 1b34cbbf4f01 ("crypto: af_alg - Disallow concurrent writes in …
CVE-2025-61748 low 3.7 3.7 FIX rhel slesdebian debian oracle 8mo ago RHSA-2025:18824: java-21-openjdk security update (Moderate)
CVE-2025-41254 unknown debian debian 8mo ago Spring Framework STOMP over WebSocket applications may allow attackers to send unauthorized messages
CVE-2025-59419 unknown FIX slesdebian debian 8mo ago Netty has SMTP Command Injection Vulnerability that Allows Email Forgery
CVE-2025-39997 unknown FIX slesdebian debian 8mo ago In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: fix race condition to UAF in snd_usbmidi_free The previous commit 0718a78f6a9f ("ALSA: usb-audio: Kill timer pro…
CVE-2025-39977 unknown FIX slesdebian debian 8mo ago In the Linux kernel, the following vulnerability has been resolved: futex: Prevent use-after-free during requeue-PI syzbot managed to trigger the following race: T1 …
CVE-2025-11731 low 3.1 3.1 FIX slesdebian debian 8mo ago A flaw was found in the exsltFuncResultComp() function of libxslt, which handles EXSLT <func:result> elements during stylesheet parsing. Due to improper type handling, the function may treat an XML d…
CVE-2025-62706 unknown FIX slesdebian debian 8mo ago Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JWE zip=DEF path performs unbounded DEFLATE decompression. A very small ciphertext can exp…
CVE-2025-61920 unknown FIX slesdebian debian 8mo ago Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JOSE implementation accepts unbounded JWS/JWT header and signature segments. A remote atta…
CVE-2025-11579 unknown FIX debian debian sles 8mo ago github.com/nwaples/rardecode versions <=2.1.1 fail to restrict the dictionary size when reading large RAR dictionary sizes, which allows an attacker to provide a specially crafted RAR file and cause …
CVE-2025-54286 unknown FIX debian debian 8mo ago Cross-Site Request Forgery (CSRF) in LXD-UI in Canonical LXD versions >= 5.0 on Linux allows an attacker to create and start container instances without user consent via crafted HTML form submissions…
CVE-2025-54287 unknown FIX debian debian 8mo ago Template Injection in instance snapshot creation component in Canonical LXD (>= 4.0) allows an attacker with instance configuration permissions to read arbitrary files on the host system via special…
CVE-2025-54288 unknown FIX debian debian 8mo ago Information Spoofing in devLXD Server in Canonical LXD versions 4.0 and above on Linux container platforms allows attackers with root privileges within any container to impersonate other containers a…
CVE-2025-54289 unknown FIX debian debian 8mo ago Privilege Escalation in operations API in Canonical LXD <6.5 on multiple platforms allows attacker with read permissions to hijack terminal or console sessions and execute arbitrary commands via WebS…
CVE-2025-54290 unknown FIX debian debian 8mo ago Information disclosure in image export API in Canonical LXD before 6.5 and 5.21.4 on Linux allows network attackers to determine project existence without authentication via crafted requests using wi…
CVE-2025-54293 unknown FIX debian debian 8mo ago Path Traversal in the log file retrieval function in Canonical LXD 5.0 LTS on Linux allows authenticated remote attackers to read arbitrary files on the host system via crafted log file names or symb…
CVE-2025-54291 unknown FIX debian debian 8mo ago Information disclosure in images API in Canonical LXD before 6.5 and 5.21.4 on all platforms allows unauthenticated remote attackers to determine project existence via differing HTTP status code resp…
CVE-2014-6278 unknown 2.5 KEVEXPFIX debian debian 8mo ago GNU Bash contains an OS command injection vulnerability which allows remote attackers to execute arbitrary commands via a crafted environment.
CVE-2025-59682 unknown FIX slesdebian debian 8mo ago An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. The django.utils.archive.extract() function, used by the "startapp --template" and "startproject --templa…
CVE-2025-59681 unknown FIX slesdebian debian 8mo ago An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. QuerySet.annotate(), QuerySet.alias(), QuerySet.aggregate(), and QuerySet.extra() are subject to SQL inje…
CVE-2025-32463 unknown 2.5 KEVEXPFIX slesdebian debian 8mo ago Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.
CVE-2025-59842 unknown debian debian 8mo ago jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to version 4.4.8, links generated with LaTeX typesetters in Markd…
CVE-2025-55560 unknown FIX debian debian 8mo ago An issue in pytorch v2.7.0 can lead to a Denial of Service (DoS) when a PyTorch model consists of torch.Tensor.to_sparse() and torch.Tensor.to_dense() and is compiled by Inductor.
CVE-2025-55558 unknown FIX debian debian 8mo ago A buffer overflow occurs in pytorch v2.7.0 when a PyTorch model consists of torch.nn.Conv2d, torch.nn.functional.hardshrink, and torch.Tensor.view-torch.mv() and is compiled by Inductor, leading to a…
CVE-2025-55557 unknown FIX debian debian 8mo ago A Name Error occurs in pytorch v2.7.0 when a PyTorch model consists of torch.cummin and is compiled by Inductor, leading to a Denial of Service (DoS).
CVE-2025-55554 unknown debian debian 8mo ago pytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long().
CVE-2025-55553 unknown FIX debian debian 8mo ago A syntax error in the component proxy_tensor.py of pytorch v2.7.0 allows attackers to cause a Denial of Service (DoS).
CVE-2025-55552 unknown FIX debian debian 8mo ago pytorch v2.8.0 was discovered to display unexpected behavior when the components torch.rot90 and torch.randn_like are used together.
CVE-2025-55551 unknown FIX debian debian 8mo ago An issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when performing a slice operation.
CVE-2025-46153 unknown FIX debian debian 8mo ago PyTorch before 3.7.0 has a bernoulli_p decompose function in decompositions.py even though it lacks full consistency with the eager CPU implementation, negatively affecting nn.Dropout1d, nn.Dropout2d…
CVE-2025-46152 unknown FIX debian debian 8mo ago In PyTorch before 2.7.0, bitwise_right_shift produces incorrect output for certain out-of-bounds values of the "other" argument.
CVE-2025-46150 unknown FIX debian debian 8mo ago In PyTorch before 2.7.0, when torch.compile is used, FractionalMaxPool2d has inconsistent results.
CVE-2025-46149 unknown FIX debian debian 8mo ago In PyTorch before 2.7.0, when inductor is used, nn.Fold has an assertion error.
CVE-2025-46148 unknown FIX debian debian 8mo ago In PyTorch through 2.6.0, when eager is used, nn.PairwiseDistance(p=2) produces incorrect results.
CVE-2025-8869 unknown FIX slesdebian debian 8mo ago When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for th…
CVE-2025-58457 unknown FIX debian debian 8mo ago Apache ZooKeeper: Insufficient Permission Check in AdminServer Snapshot/Restore Commands
CVE-2025-10823 low 3.3 3.3 debian debian 9mo ago A vulnerability was found in axboe fio up to 3.41. This affects the function str_buffer_pattern_cb of the file options.c. Performing manipulation results in null pointer dereference. The attack must …
CVE-2025-10585 unknown 1.5 KEVFIX debian debian 9mo ago Google Chromium contains a type confusion vulnerability in the V8 JavaScript and WebAssembly engine.
CVE-2025-47910 unknown FIX debian debian sles 9mo ago When using http.CrossOriginProtection, the AddInsecureBypassPattern method can unexpectedly bypass more requests than intended. CrossOriginProtection then skips validation, but forwards the original …
CVE-2025-59420 unknown FIX debian debian 9mo ago Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.4, Authlib’s JWS verification accepts tokens that declare unknown critical header parameters (crit), vi…
CVE-2025-9906 unknown debian debian 9mo ago Keras is vulnerable to Deserialization of Untrusted Data
CVE-2025-8671 unknown FIX debian debian sles 9mo ago A mismatch caused by client-triggered server-sent stream resets between HTTP/2 specifications and the internal architectures of some HTTP/2 implementations may result in excessive server resource con…
CVE-2025-59432 unknown FIX debian debian sles 9mo ago Timing Attack Vulnerability in SCRAM Authentication
CVE-2025-41249 unknown debian debian 9mo ago Spring Framework annotation detection mechanism may result in improper authorization
CVE-2025-48041 unknown FIX debian debian sles 9mo ago Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Flooding. This vulnerability is associated with program files lib/…
CVE-2025-48040 unknown FIX debian debian sles 9mo ago Uncontrolled Resource Consumption vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Flooding. This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.e…
CVE-2025-48039 unknown FIX debian debian sles 9mo ago Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Resource Leak Exposure. This vulnerability is associated with prog…
CVE-2025-48038 unknown FIX debian debian sles 9mo ago Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Resource Leak Exposure. This vulnerability is associated with prog…
CVE-2025-57833 unknown FIX slesdebian debian 9mo ago An issue was discovered in Django 4.2 before 4.2.24, 5.1 before 5.1.12, and 5.2 before 5.2.6. FilteredRelation is subject to SQL injection in column aliases, using a suitably crafted dictionary, with…
CVE-2025-58782 unknown debian debian 9mo ago Apache Jackrabbit: Core and JCR Commons are vulnerable to Deserialization of Untrusted Data
CVE-2025-57807 unknown FIX debian debian sles 9mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. ImageMagick versions lower than 14.8.2 include insecure functions: SeekBlob(), which permits advancing …
CVE-2025-58056 unknown FIX debian debian 9mo ago Netty vulnerable to request smuggling due to incorrect parsing of chunk extensions
CVE-2025-58057 unknown FIX slesdebian debian 9mo ago Netty's decoders vulnerable to DoS via zip bomb style attack
CVE-2025-7039 low 3.7 3.7 FIX debian debian sles 9mo ago A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temp…
CVE-2025-9784 unknown FIX debian debian 9mo ago Undertow MadeYouReset HTTP/2 DDoS Vulnerability
CVE-2025-57803 unknown FIX debian debian sles 9mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2 for ImageMagick's 32-bit build, a 32-bit integer overflow in the…
CVE-2025-55298 unknown FIX debian debian sles 9mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to ImageMagick versions 6.9.13-28 and 7.1.2-2, a format string bug vulnerability exists in Interpr…
CVE-2025-55212 unknown FIX debian debian sles 9mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2, passing a geometry string containing only a colon (":") to mont…
CVE-2025-55160 unknown FIX debian debian sles 9mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-27 and 7.1.2-1, there is undefined behavior (function-type-mismatch) in splay t…
CVE-2025-55154 unknown FIX debian debian sles 9mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-27 and 7.1.2-1, the magnified size calculations in ReadOneMNGIMage (in coders/p…
CVE-2025-55004 unknown FIX debian debian sles 9mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-1, ImageMagick is vulnerable to heap-buffer overflow read around the handling of …
CVE-2025-68469 unknown FIX debian debian sles 9mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.1-14, ImageMagick crashes when processing a crafted TIFF file. Version 7.1.1-14 fix…
CVE-2025-53019 unknown FIX debian debian sles 9mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0 and 6.9.13-26, in ImageMagick's `magick stream` command, specifying multipl…
CVE-2025-53014 unknown FIX debian debian sles 9mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Versions prior to 7.1.2-0 and 6.9.13-26 have a heap buffer overflow in the `InterpretImageFilename` func…
CVE-2025-53101 unknown FIX debian debian sles 9mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0 and 6.9.13-26, in ImageMagick's `magick mogrify` command, specifying multip…
CVE-2025-9301 low 3.3 3.3 debian debian sles 10mo ago A vulnerability was determined in cmake 4.1.20250725-gb5cce23. This affects the function cmForEachFunctionBlocker::ReplayItems of the file cmForEachCommand.cxx. This manipulation causes reachable ass…
CVE-2025-54988 unknown FIX debian debian 10mo ago Apache Tika XXE Vulnerability via Crafted XFA File Inside a PDF
CVE-2025-5115 unknown FIX debian debian sles 10mo ago Eclipse Jetty affected by MadeYouReset HTTP/2 vulnerability
CVE-2025-9165 low 2.5 2.5 FIX slesdebian debian libtiff 10mo ago A flaw has been found in LibTIFF 4.7.0. This affects the function _TIFFmallocExt/_TIFFCheckRealloc/TIFFHashSetNew/InitCCITTFax3 of the file tools/tiffcmp.c of the component tiffcmp. Executing manipul…
CVE-2025-41242 unknown debian debian 10mo ago Spring Framework MVC Applications Path Traversal Vulnerability
CVE-2025-8961 low 3.3 3.3 FIX slesdebian debian libtiff 10mo ago A weakness has been identified in LibTIFF 4.7.0. This affects the function main of the file tiffcrop.c of the component tiffcrop. Executing manipulation can lead to memory corruption. The attack can …
CVE-2025-55163 unknown FIX slesdebian debian 10mo ago Netty affected by MadeYouReset HTTP/2 DDoS vulnerability
CVE-2025-8747 unknown FIX debian debian 10mo ago Keras vulnerable to CVE-2025-1550 bypass via reuse of internal functionality
CVE-2025-8885 unknown FIX debian debian sles 10mo ago Bouncy Castle for Java on All (API modules) allows Excessive Allocation
CVE-2025-55159 unknown FIX slesdebian debian 10mo ago slab is a pre-allocated storage for a uniform data type. In version 0.4.10, the get_disjoint_mut method incorrectly checked if indices were within the slab's capacity instead of its length, allowing …
CVE-2025-8735 low 3.3 3.3 debian debian 10mo ago A vulnerability classified as problematic was found in GNU cflow up to 1.8. Affected by this vulnerability is the function yylex of the file c.c of the component Lexer. The manipulation leads to null…
CVE-2025-8732 low 3.3 3.3 debian debian sles 10mo ago A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads…
CVE-2025-54368 unknown FIX slesdebian debian 10mo ago uv is a Python package and project manager written in Rust. In versions 0.8.5 and earlier, remote ZIP archives were handled in a streamwise fashion, and file entries were not reconciled against the a…
CVE-2025-54799 unknown FIX debian debian 10mo ago Let's Encrypt client and ACME library written in Go (Lego). In versions 4.25.1 and below, the github.com/go-acme/lego/v4/acme/api package (thus the lego library and the lego cli as well) don't enforc…
CVE-2025-8534 low 2.5 2.5 FIX slesdebian debian libtiff 10mo ago A vulnerability classified as problematic was found in libtiff 4.6.0. This vulnerability affects the function PS_Lvl2page of the file tools/tiff2ps.c of the component tiff2ps. The manipulation leads …
CVE-2022-29458 low 2.5 FIX rhel sles rocky 10mo ago ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.
CVE-2025-54410 unknown debian debian sles 10mo ago Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. A firewalld vulne…