8.5

CVSS4.0

CVE-2025-3286 - Local Code Execution Vulnerability in Arena®

A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data.  If exploited a threat actor can disclose information and execute arbitra…

📅 Published: April 8, 2025, 3:28 p.m. 🔄 Last Modified: July 14, 2025, 7:13 p.m.

8.5

CVSS4.0

CVE-2025-3285 - Local Code Execution Vulnerability in Arena®

A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data.  If exploited a threat actor can disclose information and execute arbitra…

📅 Published: April 8, 2025, 3:26 p.m. 🔄 Last Modified: July 14, 2025, 7:13 p.m.

8.5

CVSS4.0

CVE-2025-2829 - Local Code Execution Vulnerability in Arena®

A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to write outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data.  If exploited a threat actor can disclose information and execute arbit…

📅 Published: April 8, 2025, 3:24 p.m. 🔄 Last Modified: July 14, 2025, 7:13 p.m.

3.8

CVSS3.1

CVE-2025-32026 - Element Web could load a malicious instance of Element Call leaking media encryption keys

Element Web is a Matrix web client built using the Matrix React SDK. Element Web, starting from version 1.11.16 up to version 1.11.96, can be configured to load Element Call from an external URL. Under certain conditions, the external page is able to get access to the media encryption keys used for…

📅 Published: April 8, 2025, 3:22 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2025-2293 - Local Code Execution Vulnerability in Arena®

A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to write outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data.  If exploited a threat actor can disclose information and execute arbit…

📅 Published: April 8, 2025, 3:20 p.m. 🔄 Last Modified: July 14, 2025, 7:13 p.m.

8.5

CVSS4.0

CVE-2025-2288 - Local Code Execution Vulnerability in Arena®

A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to write outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data.  If exploited a threat actor can disclose information and execute arbit…

📅 Published: April 8, 2025, 3:19 p.m. 🔄 Last Modified: July 14, 2025, 7:14 p.m.

8.5

CVSS4.0

CVE-2025-2287 - Local Code Execution Vulnerability in Arena®

A local code execution vulnerability exists in the Rockwell Automation Arena®  due to an uninitialized pointer. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerabili…

📅 Published: April 8, 2025, 3:16 p.m. 🔄 Last Modified: July 14, 2025, 7:14 p.m.

8.5

CVSS4.0

CVE-2025-2286 - Local Code Execution Vulnerability in Arena®

A local code execution vulnerability exists in the Rockwell Automation Arena®  due to an uninitialized pointer. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerabili…

📅 Published: April 8, 2025, 3:16 p.m. 🔄 Last Modified: July 14, 2025, 7:13 p.m.

8.5

CVSS4.0

CVE-2025-2285 - Local Code Execution Vulnerability in Arena®

A local code execution vulnerability exists in the Rockwell Automation Arena®  due to an uninitialized pointer. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerabili…

📅 Published: April 8, 2025, 3:15 p.m. 🔄 Last Modified: July 14, 2025, 7:14 p.m.

6.9

CVSS4.0

CVE-2025-32025 - bep/imagemeta allows a potentially large memory allocation in PNG and WebP parsing

bep/imagemeta is a Go library for reading EXIF, IPTC and XMP image meta data from JPEG, TIFF, PNG, and WebP files. The buffer created for parsing metadata for PNG and WebP images was only bounded by their input data type, which could lead to potentially large memory allocation, and unreasonably hig…

📅 Published: April 8, 2025, 3:13 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 5967 of 34,919
« previous page » next page
Filters