5.5
CVE-2025-46400 - Xfig: fig2dev segmentation fault in read_arcobject
In xfig diagramming tool, a segmentation fault while running fig2dev allows an attacker to availability via local input manipulation via read_arcobject function.
5.5
CVE-2025-46399 - Xfig: transfig: fig2dev segmentation fault vulnerability
A flaw was found in fig2dev. This vulnerability allows availability via local input manipulation via genge_itp_spline function.
5.5
CVE-2025-46398 - Xfig: fig2dev stack-overflow via read_objects
In xfig diagramming tool, a stack-overflow while running fig2dev allows memory corruption via local input manipulation via read_objects function.
7.8
CVE-2025-46397 - Xfig: xfig: stack-overflow allows possible code execution via local input manipulation
A flaw was found in xfig. This vulnerability allows possible code execution via local input manipulation via bezier_spline function.
7.5
CVE-2025-32818 -
A Null Pointer Dereference vulnerability in the SonicOS SSLVPN Virtual office interface allows a remote, unauthenticated attacker to crash the firewall, potentially leading to a Denial-of-Service (DoS) condition.
4.3
CVE-2025-3907 - Search API Solr - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2025-046
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Search API Solr allows Cross Site Request Forgery.This issue affects Search API Solr: from 0.0.0 before 4.3.9.
7.3
CVE-2025-3904 - Sportsleague - Critical - Unsupported - SA-CONTRIB-2025-045
Vulnerability in Drupal Sportsleague.This issue affects Sportsleague: *.*.
7.3
CVE-2025-3903 - UEditor - ηΎεΊ¦ηΌθΎε¨ - Critical - Unsupported - SA-CONTRIB-2025-044
Vulnerability in Drupal UEditor - ηΎεΊ¦ηΌθΎε¨.This issue affects UEditor - ηΎεΊ¦ηΌθΎε¨: *.*.
6.1
CVE-2025-3902 - Block Class - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-043
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Block Class allows Cross-Site Scripting (XSS).This issue affects Block Class: from 4.0.0 before 4.0.1.
6.1
CVE-2025-3901 - Bootstrap Site Alert - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-042
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Bootstrap Site Alert allows Cross-Site Scripting (XSS).This issue affects Bootstrap Site Alert: from 0.0.0 before 1.13.0, from 3.0.0 before 3.0.4.