7.8

CVSS3.1

CVE-2025-27835 - Ghostscript: Buffer overflow when converting glyphs to unicode

An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs when converting glyphs to Unicode in psi/zbfont.c.

๐Ÿ“… Published: March 25, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 3, 2025, 8:18 p.m.

7.8

CVSS3.1

CVE-2025-27830 - Ghostscript: Buffer overflow during serialization of DollarBlend in font

An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs during serialization of DollarBlend in a font, for base/write_t1.c and psi/zfapi.c.

๐Ÿ“… Published: March 25, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 3, 2025, 8:18 p.m.

4.3

CVSS3.1

CVE-2025-30741 -

Pixelfed before 0.12.5 allows anyone to follow private accounts and see private posts on other Fediverse servers. This affects users elsewhere in the Fediverse, if they otherwise have any followers from a Pixelfed instance.

๐Ÿ“… Published: March 25, 2025, midnight ๐Ÿ”„ Last Modified: July 12, 2025, 3:26 p.m.

6.1

CVSS3.1

CVE-2024-55029 -

NASA Fprime v3.4.3 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities.

๐Ÿ“… Published: March 25, 2025, midnight ๐Ÿ”„ Last Modified: April 3, 2025, 5:33 p.m.

7.8

CVSS3.1

CVE-2025-27834 - Ghostscript: Buffer overflow caused by an oversized Type 4 function in a PDF

An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs via an oversized Type 4 function in a PDF document to pdf/pdf_func.c.

๐Ÿ“… Published: March 25, 2025, midnight ๐Ÿ”„ Last Modified: April 1, 2025, 4:44 p.m.

8.8

CVSS3.1

CVE-2025-29635 -

A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function, triggering remote command execution.

๐Ÿ“… Published: March 25, 2025, midnight ๐Ÿ”„ Last Modified: April 3, 2025, 5:35 p.m.

9.8

CVSS3.1

CVE-2025-25373 -

The Memory Management Module of NASA cFS (Core Flight System) Aquila has insecure permissions, which can be exploited to gain an RCE on the platform.

๐Ÿ“… Published: March 25, 2025, midnight ๐Ÿ”„ Last Modified: April 3, 2025, 3:24 p.m.

9.8

CVSS3.1

CVE-2025-27832 - Ghostscript: NPDL device: Compression buffer overflow

An issue was discovered in Artifex Ghostscript before 10.05.0. The NPDL device has a Compression buffer overflow for contrib/japanese/gdevnpdl.c.

๐Ÿ“… Published: March 25, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 3, 2025, 8:18 p.m.

7.5

CVSS3.1

CVE-2024-44903 -

SQL Injection can occur in the SirsiDynix Horizon Information Portal (IPAC20) through 3.25_9382; however, a patch is available from the vendor. This is in ipac.jsp in a SELECT WHERE statement, in a part of the uri= variable in the second part of the full= inner variable.

๐Ÿ“… Published: March 25, 2025, midnight ๐Ÿ”„ Last Modified: March 27, 2025, 4:45 p.m.

3.3

CVSS3.1

CVE-2025-2720 - libgsf: GNOME libgsf gsf_base64_encode_simple uninitialized variable

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: According to the code maintainer the call of the POC is invalid because the buffer pointed to by "data" must have "โ€ฆ

๐Ÿ“… Published: March 24, 2025, 11:31 p.m. ๐Ÿ”„ Last Modified: March 27, 2025, 6:15 a.m.
Total resulsts: 343983
Page 5710 of 34,399
ยซ previous page ยป next page
Filters