8.8
CVE-2025-32438 - Local privilege escalation in make-initrd-ng
make-initrd-ng is a tool for copying binaries and their dependencies. Local privilege escalation affecting all NixOS users. With systemd.shutdownRamfs.enable enabled (the default) a local user is able to create a program that will be executed by root during shutdown. Patches exist for NixOS 24.11 aโฆ
6.7
CVE-2025-1122 -
Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 15753.50.0 stable on Cr50 Boards allows an attacker with root access to gain persistence and Bypass operating system verification via exploiting the NV_Read functionality during the Challenge-Response process.
6.7
CVE-2025-1292 - TPM2 Out-Of-Bounds Write Leading to Potential Operating System Verification Bypass in ChromeOS
Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 122.0.6261.132 stable on Cr50 Boards allows an attacker with root access to gain persistence and bypass operating system verification via exploiting the NV_Read functionality during the Challenge-Response process.
6.5
CVE-2025-32439 - pleezer allows resource exhaustion through uncollected hook script processes
pleezer is a headless Deezer Connect player. Hook scripts in pleezer can be triggered by various events like track changes and playback state changes. In versions before 0.16.0, these scripts were spawned without proper process cleanup, leaving zombie processes in the system's process table. Even dโฆ
0.0
CVE-2025-34998 -
This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.
0.0
CVE-2025-34993 -
This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.
0.0
CVE-2025-34995 -
This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.
0.0
CVE-2025-35002 -
This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.
0.0
CVE-2025-34996 -
This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.
0.0
CVE-2025-34984 -
This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.