9.3

CVSS3.1

CVE-2025-54574 - Squid's URN Handling can lead to Buffer Overflow

Squid is a caching proxy for the Web. In versions 6.3 and below, Squid is vulnerable to a heap buffer overflow and possible remote code execution attack when processing URN due to incorrect buffer management. This has been fixed in version 6.4. To work around this issue, disable URN access permissi…

📅 Published: Aug. 1, 2025, 6:02 p.m. 🔄 Last Modified: Nov. 5, 2025, 5:15 p.m.

5.5

CVSS4.0

CVE-2025-53012 - MaterialX's Lack of Import Depth Limit Leads to DoS (Denial-Of-Service) Via Stack Exhaustion

MaterialX is an open standard for the exchange of rich material and look-development content across applications and renderers. In version 1.39.2, nested imports of MaterialX files can lead to a crash via stack memory exhaustion, due to the lack of a limit on the "import chain" depth. When parsing …

📅 Published: Aug. 1, 2025, 6 p.m. 🔄 Last Modified: Nov. 6, 2025, 10:03 p.m.

3.7

CVSS3.1

CVE-2025-6011 - Timing Side-Channel in Vault’s Userpass Auth Method

A timing side channel in Vault and Vault Enterprise’s (“Vault”) userpass auth method allowed an attacker to distinguish between existing and non-existing users, and potentially enumerate valid usernames for Vault’s Userpass auth method. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1…

📅 Published: Aug. 1, 2025, 6 p.m. 🔄 Last Modified: Aug. 13, 2025, 6:10 p.m.

2

CVSS4.0

CVE-2025-53011 - MaterialX is Vulnerable to NULL Pointer Dereference due to Unchecked implGraphOutput

MaterialX is an open standard for the exchange of rich material and look-development content across applications and renderers. In version 1.39.2, when parsing shader nodes in a MTLX file, the MaterialXCore code accesses a potentially null pointer, which can lead to crashes with maliciously crafted…

📅 Published: Aug. 1, 2025, 5:58 p.m. 🔄 Last Modified: Aug. 20, 2025, 9:24 p.m.

2

CVSS4.0

CVE-2025-53010 - MaterialX's unchecked nodeGraph->getOutput return is vulnerable to NULL Pointer Dereference

MaterialX is an open standard for the exchange of rich material and look-development content across applications and renderers. In version 1.39.2, when parsing shader nodes in a MTLX file, the MaterialXCore code accesses a potentially null pointer, which can lead to crashes with maliciously crafted…

📅 Published: Aug. 1, 2025, 5:58 p.m. 🔄 Last Modified: Aug. 20, 2025, 9:24 p.m.

5.5

CVSS4.0

CVE-2025-53009 - MaterialX Stack Overflow via Lack of MTLX XML Parsing Recursion Limit

MaterialX is an open standard for the exchange of rich material and look-development content across applications and renderers. In versions 1.39.2 and below, when parsing an MTLX file with multiple nested nodegraph implementations, the MaterialX XML parsing logic can potentially crash due to stack …

📅 Published: Aug. 1, 2025, 5:57 p.m. 🔄 Last Modified: Aug. 20, 2025, 9:24 p.m.

6.5

CVSS3.1

CVE-2025-49832 - Asterisk is Vulnerable to Remote DoS and possible RCE Attacks During Memory Allocation

Asterisk is an open source private branch exchange and telephony toolkit. In versions up to and including 18.26.2, between 20.00.0 and 20.15.0, 20.7-cert6, 21.00.0, 22.00.0 through 22.5.0, there is a remote DoS and possible RCE condition in `asterisk/res/res_stir_shaken /verification.c` that can be…

📅 Published: Aug. 1, 2025, 5:57 p.m. 🔄 Last Modified: Aug. 4, 2025, 3:06 p.m.

5.3

CVSS3.1

CVE-2025-6004 - Vault Userpass and LDAP User Lockout Bypass

Vault and Vault Enterprise’s (“Vault”) user lockout feature could be bypassed for Userpass and LDAP authentication methods. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.

📅 Published: Aug. 1, 2025, 5:56 p.m. 🔄 Last Modified: Aug. 13, 2025, 6:10 p.m.

6.8

CVSS3.1

CVE-2025-6037 - Vault Certificate Auth Method Did Not Validate Common Name For Non-CA Certificates

Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certificate as [+trusted certificate+|https://developer.hashicorp.com/vault/api-docs/auth/cert#certificate]. In this configuration, an attacker may be able t…

📅 Published: Aug. 1, 2025, 5:52 p.m. 🔄 Last Modified: Feb. 26, 2026, 5:50 p.m.

0.0

CVE-2025-53815 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2025. Notes: none.

📅 Published: Aug. 1, 2025, 5:50 p.m. 🔄 Last Modified: March 16, 2026, 5:16 p.m.
Total resulsts: 349182
Page 4436 of 34,919
« previous page » next page
Filters