4.3

CVSS3.1

CVE-2025-58480 -

Heap-based buffer overflow in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.

๐Ÿ“… Published: Dec. 2, 2025, 1:24 a.m. ๐Ÿ”„ Last Modified: Dec. 5, 2025, 7:09 p.m.

4.3

CVSS3.1

CVE-2025-58479 -

Out-of-bounds read in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.

๐Ÿ“… Published: Dec. 2, 2025, 1:24 a.m. ๐Ÿ”„ Last Modified: Dec. 5, 2025, 7:09 p.m.

4.3

CVSS3.1

CVE-2025-58478 -

Out-of-bounds write in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.

๐Ÿ“… Published: Dec. 2, 2025, 1:24 a.m. ๐Ÿ”„ Last Modified: Dec. 5, 2025, 7:09 p.m.

4.3

CVSS3.1

CVE-2025-58477 -

Out-of-bounds write in parsing IFD tag in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.

๐Ÿ“… Published: Dec. 2, 2025, 1:24 a.m. ๐Ÿ”„ Last Modified: Dec. 5, 2025, 7:12 p.m.

4.2

CVSS3.1

CVE-2025-58476 -

Out-of-bounds read vulnerability in bootloader prior to SMR Dec-2025 Release 1 allows physical attackers to access out-of-bounds memory.

๐Ÿ“… Published: Dec. 2, 2025, 1:24 a.m. ๐Ÿ”„ Last Modified: Dec. 5, 2025, 7:13 p.m.

5.6

CVSS3.1

CVE-2025-58475 -

Improper input validation in libsec-ril.so prior to SMR Dec-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

๐Ÿ“… Published: Dec. 2, 2025, 1:24 a.m. ๐Ÿ”„ Last Modified: Dec. 5, 2025, 7:14 p.m.

6.2

CVSS3.1

CVE-2025-21080 -

Improper export of android application components in Dynamic Lockscreen prior to SMR Dec-2025 Release 1 allows local attackers to access files with Dynamic Lockscreen's privilege.

๐Ÿ“… Published: Dec. 2, 2025, 1:23 a.m. ๐Ÿ”„ Last Modified: Dec. 5, 2025, 8:10 p.m.

5.7

CVSS3.1

CVE-2025-21072 -

Out-of-bounds write in decoding metadata in fingerprint trustlet prior to SMR Dec-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

๐Ÿ“… Published: Dec. 2, 2025, 1:23 a.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 4:57 p.m.

9.8

CVSS3.1

CVE-2025-60854 -

A vulnerability has been found in D-Link R15 (AX1500) 1.20.01 and below. By manipulating the model name parameter during a password change request in the web administrator page, it is possible to trigger a command injection in httpd.

๐Ÿ“… Published: Dec. 2, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 6, 2025, midnight

3.5

CVSS3.1

CVE-2025-65858 -

A Stored Cross-Site Scripting (XSS) vulnerability in Calibre-Web v0.6.25 allows attackers to inject malicious JavaScript into the 'username' field during user creation. The payload is stored unsanitized and later executed when the /ajax/listusers endpoint is accessed.

๐Ÿ“… Published: Dec. 2, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 23, 2025, 1:08 p.m.
Total resulsts: 345165
Page 2458 of 34,517
ยซ previous page ยป next page
Filters