8.8

CVSS3.1

CVE-2025-1568 -

Access Control Vulnerability in Gerrit chromiumos project configuration in Google ChromeOS 131.0.6778.268 allows an attacker with a registered Gerrit account to inject malicious code into ChromeOS projects and potentially achieve Remote Code Execution and Denial of Service via editing trusted pipe…

📅 Published: April 16, 2025, 11:06 p.m. 🔄 Last Modified: April 17, 2025, 8:21 p.m.

8.8

CVSS3.1

CVE-2025-2073 -

Out-of-Bounds Read in ip_set_bitmap_ip.c in Google ChromeOS Kernel Versions 6.1, 5.15, 5.10, 5.4, 4.19. on All devices where Termina is used allows an attacker with CAP_NET_ADMIN privileges to cause memory corruption and potentially escalate privileges via crafted ipset commands.

📅 Published: April 16, 2025, 11:06 p.m. 🔄 Last Modified: April 17, 2025, 8:21 p.m.

6.5

CVSS3.1

CVE-2025-1704 -

ComponentInstaller Modification in ComponentInstaller in Google ChromeOS 124.0.6367.34 on Chromebooks allows enrolled users with local access to unenroll devices and intercept device management requests via loading components from the unencrypted stateful partition.

📅 Published: April 16, 2025, 11:06 p.m. 🔄 Last Modified: April 17, 2025, 8:21 p.m.

7.5

CVSS3.1

CVE-2025-1566 -

DNS Leak in Native System VPN in Google ChromeOS Dev Channel on ChromeOS 129.0.6668.36 allows network observers to expose plaintext DNS queries via failure to properly tunnel DNS traffic during VPN state transitions.

📅 Published: April 16, 2025, 11:06 p.m. 🔄 Last Modified: April 17, 2025, 8:21 p.m.

6.8

CVSS3.1

CVE-2025-24907 - Hitachi Vantara Pentaho Data Integration & Analytics – Path Traversal

Overview   The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory. (CWE-35)   Descriptio…

📅 Published: April 16, 2025, 10:39 p.m. 🔄 Last Modified: April 17, 2025, 8:21 p.m.

4.9

CVSS3.1

CVE-2025-24911 - Hitachi Vantara Pentaho Business Analytics Server - Improper Restriction of XML External Entity Ref…

Overview   XML documents optionally contain a Document Type Definition (DTD), which, among other features, enables the definition of XML entities. It is possible to define an entity by providing a substitution string in the form of a URI. Once the content of the URI is read, it is fed back i…

📅 Published: April 16, 2025, 10:35 p.m. 🔄 Last Modified: April 17, 2025, 8:21 p.m.

4.9

CVSS3.1

CVE-2025-24910 - Hitachi Vantara Pentaho Business Analytics Server - Improper Restriction of XML External Entity Ref…

Overview   XML documents optionally contain a Document Type Definition (DTD), which, among other features, enables the definition of XML entities. It is possible to define an entity by providing a substitution string in the form of a URI. Once the content of the URI is read, it is fed back i…

📅 Published: April 16, 2025, 10:32 p.m. 🔄 Last Modified: April 17, 2025, 8:21 p.m.

4.4

CVSS3.1

CVE-2025-24909 - Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Input During Web Pag…

Overview   The software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users. (CWE-79)   Description   Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.…

📅 Published: April 16, 2025, 10:30 p.m. 🔄 Last Modified: April 17, 2025, 8:21 p.m.

6.8

CVSS3.1

CVE-2025-24908 - Hitachi Vantara Pentaho Data Integration & Analytics – Path Traversal

Overview   The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory. (CWE-35)   Descriptio…

📅 Published: April 16, 2025, 10:27 p.m. 🔄 Last Modified: April 17, 2025, 8:21 p.m.

9.1

CVSS3.1

CVE-2025-0756 - Hitachi Vantara Pentaho Data Integration & Analytics - Improper Control of Resource Identifiers ('R…

Overview   The product receives input from an upstream component, but it does not restrict or incorrectly restricts the input before it is used as an identifier for a resource that may be outside the intended sphere of control. (CWE-99)   Description   Hitachi Vantara Pentaho D…

📅 Published: April 16, 2025, 10:23 p.m. 🔄 Last Modified: April 17, 2025, 8:21 p.m.
Total resulsts: 291078
Page 59 of 29,108
« previous page » next page
Filters