7.7

CVSS4.0

CVE-2025-27138 - DataEase has an improper authentication vulnerability

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, there is a flaw in the authentication in the io.dataease.auth.filter.TokenFilter class, which may cause the risk of unauthorized access. The vulnerability has been fixed in v2.10.6. No known worka…

πŸ“… Published: March 13, 2025, 4:49 p.m. πŸ”„ Last Modified: March 21, 2025, 3:22 p.m.

7.8

CVSS3.1

CVE-2025-1432 - 3DM File Parsing Use-After-Free Vulnerability

A maliciously crafted 3DM file, when parsed through Autodesk AutoCAD, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

πŸ“… Published: March 13, 2025, 4:49 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

7.8

CVSS3.1

CVE-2025-1431 - SLDPRT File Parsing Out-of-Bounds Read Vulnerability

A maliciously crafted SLDPRT file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

πŸ“… Published: March 13, 2025, 4:48 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

7.8

CVSS3.1

CVE-2025-1430 - SLDPRT File Parsing Memory Corruption Vulnerability

A maliciously crafted SLDPRT file, when parsed through Autodesk AutoCAD, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

πŸ“… Published: March 13, 2025, 4:48 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

0.0

CVE-2024-12858 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. *** Duplicate of CVE-2025-22880 ***

πŸ“… Published: March 13, 2025, 4:47 p.m. πŸ”„ Last Modified: April 2, 2025, 3:15 p.m.

7.8

CVSS3.1

CVE-2025-1429 - MODEL File Parsing Heap-Based Buffer Overflow Vulnerability

A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

πŸ“… Published: March 13, 2025, 4:47 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

7.8

CVSS3.1

CVE-2025-1428 - CATPRODUCT File Parsing Out-of-Bounds Read Vulnerability

A maliciously crafted CATPART file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

πŸ“… Published: March 13, 2025, 4:46 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

7.8

CVSS3.1

CVE-2025-1427 - CATPRODUCT File Parsing Uninitialized Variable Vulnerability

A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

πŸ“… Published: March 13, 2025, 4:46 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

7.3

CVSS4.0

CVE-2025-27103 - Dataease Mysql JDBC Connection Parameters Not Being Verified Leads to Arbitrary File Read Vulnerabi…

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, a bypass for the patch for CVE-2024-55953 allows authenticated users to read and deserialize arbitrary files through the background JDBC connection. The vulnerability has been fixed in v2.10.6. No…

πŸ“… Published: March 13, 2025, 4:44 p.m. πŸ”„ Last Modified: March 28, 2025, 7:55 p.m.

7.3

CVSS4.0

CVE-2025-24974 - DataEase Mysql JDBC Connection Parameters Not Being Verified Leads to Arbitrary File Read Vulnerabi…

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, authenticated users can read and deserialize arbitrary files through the background JDBC connection. The vulnerability has been fixed in v2.10.6. No known workarounds are available.

πŸ“… Published: March 13, 2025, 4:37 p.m. πŸ”„ Last Modified: March 21, 2025, 3:40 p.m.
Total resulsts: 343970
Page 5827 of 34,397
Β« previous page Β» next page
Filters