8.8

CVSS3.1

CVE-2025-13481 - IBM Aspera Orchestrator Command Injection

IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.

๐Ÿ“… Published: Dec. 11, 2025, 7:47 p.m. ๐Ÿ”„ Last Modified: Dec. 11, 2025, 8:34 p.m.

5.3

CVSS3.1

CVE-2025-13211 - IBM Aspera Orchestrator Denial of Service

IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow an authenticated user to cause a denial of service in the email service due to improper control of interaction frequency.

๐Ÿ“… Published: Dec. 11, 2025, 7:45 p.m. ๐Ÿ”„ Last Modified: Dec. 11, 2025, 8:34 p.m.

5.5

CVSS3.1

CVE-2024-42197 - HCL Workload Scheduler is vulnerable to plain text storage of a password

HCL Workload Scheduler stores user credentials in plain text which can be read by a local user.

๐Ÿ“… Published: Dec. 11, 2025, 7:40 p.m. ๐Ÿ”„ Last Modified: Dec. 12, 2025, 8:49 a.m.

5.1

CVSS3.1

CVE-2025-36938 -

In U-Boot of append_uint32_le(), there is a possible fault injection due to a logic error in the code. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

๐Ÿ“… Published: Dec. 11, 2025, 7:35 p.m. ๐Ÿ”„ Last Modified: Dec. 12, 2025, 8:49 a.m.

0.0

CVE-2025-36937 -

In AudioDecoder::HandleProduceRequest of audio_decoder.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

๐Ÿ“… Published: Dec. 11, 2025, 7:35 p.m. ๐Ÿ”„ Last Modified: Dec. 12, 2025, 8:49 a.m.

0.0

CVE-2025-36936 -

In GetTachyonCommand of tachyon_server_common.h, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

๐Ÿ“… Published: Dec. 11, 2025, 7:35 p.m. ๐Ÿ”„ Last Modified: Dec. 12, 2025, 8:49 a.m.

0.0

CVE-2025-36935 -

In trusty_ffa_mem_reclaim of shared-mem-smcall.c, there is a possible memory corruption due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

๐Ÿ“… Published: Dec. 11, 2025, 7:35 p.m. ๐Ÿ”„ Last Modified: Dec. 12, 2025, 8:49 a.m.

6.7

CVSS3.1

CVE-2025-36934 -

In bigo_worker_thread of private/google-modules/video/gchips/bigo.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

๐Ÿ“… Published: Dec. 11, 2025, 7:35 p.m. ๐Ÿ”„ Last Modified: Dec. 12, 2025, 8:49 a.m.

0.0

CVE-2025-36932 -

In tracepoint_msg_handler of cpm/google/lib/tracepoint/tracepoint_ipc.c, there is a possible memory overwrite due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

๐Ÿ“… Published: Dec. 11, 2025, 7:35 p.m. ๐Ÿ”„ Last Modified: Dec. 12, 2025, 8:49 a.m.

7.8

CVSS3.1

CVE-2025-36931 -

In GetHostAddress of gxp_buffer.h, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

๐Ÿ“… Published: Dec. 11, 2025, 7:35 p.m. ๐Ÿ”„ Last Modified: Dec. 12, 2025, 8:49 a.m.
Total resulsts: 322292
Page 46 of 32,230
ยซ previous page ยป next page
Filters