8.8
CVE-2025-4919 - Out-of-bounds access when optimizing linear sums
An attacker was able to perform an out-of-bounds read or write on a JavaScript object by confusing array index sizes. This vulnerability was fixed in Firefox 138.0.4, Firefox ESR 128.10.1, Firefox ESR 115.23.1, Thunderbird 128.10.2, and Thunderbird 138.0.2.
9.8
CVE-2025-4918 - Out-of-bounds access when resolving Promise objects
An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object. This vulnerability was fixed in Firefox 138.0.4, Firefox ESR 128.10.1, Firefox ESR 115.23.1, Thunderbird 128.10.2, and Thunderbird 138.0.2.
0.0
CVE-2025-4921 -
Duplicate ofΒ CVE-2025-4919
0.0
CVE-2025-4920 -
Duplicate ofΒ CVE-2025-4918
6.9
CVE-2025-4837 - projectworlds Student Project Allocation System make_group_sql.php sql injection
A vulnerability classified as critical has been found in projectworlds Student Project Allocation System 1.0. This affects an unknown part of the file /make_group_sql.php. The manipulation of the argument mem1/mem2/mem3 leads to sql injection. It is possible to initiate the attack remotely. The expβ¦
6.9
CVE-2025-4836 - Projectworlds Life Insurance Management System deleteAgent.php sql injection
A vulnerability was found in Projectworlds Life Insurance Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /deleteAgent.php. The manipulation of the argument agent_id leads to sql injection. The attack may be launched remotely. Tβ¦
8.7
CVE-2025-4835 - TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formWlanRedirect buffer overflow
A vulnerability was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formWlanRedirect of the component HTTP POST Request Handler. The manipulation of the argument redireβ¦
8.7
CVE-2025-4834 - TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formSetLg buffer overflow
A vulnerability was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. It has been classified as critical. Affected is an unknown function of the file /boafrm/formSetLg of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. Iβ¦
0.0
CVE-2024-13965 -
wrong year
0.0
CVE-2024-13964 -
wrong year