7.5
CVE-2025-46404 - lasso: Denial of service in Entr'ouvert Lasso
A denial of service vulnerability exists in the lasso_provider_verify_saml_signature functionality of Entr'ouvert Lasso 2.5.1. A specially crafted SAML response can lead to a denial of service. An attacker can send a malformed SAML response to trigger this vulnerability.
7.5
CVE-2025-46784 - lasso: Memory exhaustion in Entr'ouvert Lasso
A denial of service vulnerability exists in the lasso_node_init_from_message_with_format functionality of Entr'ouvert Lasso 2.5.1. A specially crafted SAML response can lead to a memory depletion, resulting in denial of service. An attacker can send a malformed SAML response to trigger this vulβ¦
7.5
CVE-2025-46705 - lasso: Denial of service in Entr'ouvert Lasso
A denial of service vulnerability exists in the g_assert_not_reached functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML assertion response can lead to a denial of service. An attacker can send a malformed SAML response to trigger this vulnerability.
6.7
CVE-2025-3125 - Authenticated Arbitrary File Upload in Multiple WSO2 Products via CarbonAppUploader Admin Service Lβ¦
An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper input validation in the CarbonAppUploader admin service endpoint. An authenticated attacker with appropriate privileges can upload a malicious file to a user-controlled location on the server, potentially leadinβ¦
4.2
CVE-2025-52602 - HCL BigFix Query is affected by a sensitive information disclosure vulnerability in the WebUI Queryβ¦
HCL BigFix Query is affected by a sensitive information disclosure in the WebUI Query application. Β An HTTP GET endpoint request returns discoverable responses that may disclose: group names, active user names (or IDs). Β An attacker can use that information to target individuals with phishing or oβ¦
0.0
CVE-2025-64478 -
Not used
0.0
CVE-2025-64475 -
Not used
0.0
CVE-2025-64477 -
Not used
0.0
CVE-2025-64480 -
Not used
0.0
CVE-2025-64479 -
Not used