4.8

CVSS4.0

CVE-2025-1373 - FFmpeg MOV Parser mov.c mov_read_trak null pointer dereference

A vulnerability was found in FFmpeg up to 7.1. It has been rated as problematic. Affected by this issue is the function mov_read_trak of the file libavformat/mov.c of the component MOV Parser. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The …

📅 Published: Feb. 17, 2025, 3:31 a.m. 🔄 Last Modified: June 3, 2025, 5:53 p.m.

4.8

CVSS4.0

CVE-2025-1372 - GNU elfutils eu-readelf readelf.c print_string_section buffer overflow

A vulnerability was found in GNU elfutils 0.192. It has been declared as critical. Affected by this vulnerability is the function dump_data_section/print_string_section of the file readelf.c of the component eu-readelf. The manipulation of the argument z/x leads to buffer overflow. An attack has to…

📅 Published: Feb. 17, 2025, 3 a.m. 🔄 Last Modified: Nov. 4, 2025, 8:19 p.m.

5.2

CVSS3.0

CVE-2025-26700 -

Authentication bypass using an alternate path or channel issue exists in ”RoboForm Password Manager" App for Android versions prior to 9.7.4, which may allow an attacker with access to a device where the application is installed to bypass the lock screen and obtain sensitive information.

📅 Published: Feb. 17, 2025, 2:59 a.m. 🔄 Last Modified: Feb. 18, 2025, 3:56 p.m.

4.8

CVSS4.0

CVE-2025-1371 - GNU elfutils eu-read readelf.c handle_dynamic_symtab null pointer dereference

A vulnerability has been found in GNU elfutils 0.192 and classified as problematic. This vulnerability affects the function handle_dynamic_symtab of the file readelf.c of the component eu-read. The manipulation leads to null pointer dereference. Attacking locally is a requirement. The exploit has b…

📅 Published: Feb. 17, 2025, 2:31 a.m. 🔄 Last Modified: Nov. 4, 2025, 8:13 p.m.

4.8

CVSS4.0

CVE-2025-1370 - MicroWorld eScan Antivirus Autoscan USB epsdaemon sprintf os command injection

A vulnerability, which was classified as critical, has been found in MicroWorld eScan Antivirus 7.0.32 on Linux. Affected by this issue is the function sprintf of the file epsdaemon of the component Autoscan USB. The manipulation leads to os command injection. An attack has to be approached locally…

📅 Published: Feb. 17, 2025, 2 a.m. 🔄 Last Modified: June 27, 2025, 5:45 p.m.

2

CVSS4.0

CVE-2025-1369 - MicroWord eScan Antivirus USB Password os command injection

A vulnerability classified as critical was found in MicroWord eScan Antivirus 7.0.32 on Linux. Affected by this vulnerability is an unknown functionality of the component USB Password Handler. The manipulation leads to os command injection. The attack needs to be approached locally. The complexity …

📅 Published: Feb. 17, 2025, 1:31 a.m. 🔄 Last Modified: June 27, 2025, 5:45 p.m.

4.6

CVSS4.0

CVE-2025-1368 - MicroWord eScan Antivirus mwav.conf ReadConfiguration buffer overflow

A vulnerability was found in MicroWord eScan Antivirus 7.0.32 on Linux. It has been declared as problematic. This vulnerability affects the function ReadConfiguration of the file /opt/MicroWorld/etc/mwav.conf. The manipulation of the argument BasePath leads to buffer overflow. Local access is requi…

📅 Published: Feb. 17, 2025, 1 a.m. 🔄 Last Modified: June 27, 2025, 5:45 p.m.

4.8

CVSS4.0

CVE-2025-1367 - MicroWord eScan Antivirus USB Password sprintf buffer overflow

A vulnerability was found in MicroWord eScan Antivirus 7.0.32 on Linux. It has been classified as critical. This affects the function sprintf of the component USB Password Handler. The manipulation leads to buffer overflow. An attack has to be approached locally. The vendor was contacted early abou…

📅 Published: Feb. 17, 2025, 12:31 a.m. 🔄 Last Modified: June 27, 2025, 5:46 p.m.

4.8

CVSS4.0

CVE-2025-1366 - MicroWord eScan Antivirus VirusPopUp strcpy stack-based overflow

A vulnerability was found in MicroWord eScan Antivirus 7.0.32 on Linux and classified as critical. Affected by this issue is the function strcpy of the component VirusPopUp. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. The exploit has been disclo…

📅 Published: Feb. 17, 2025, midnight 🔄 Last Modified: Oct. 9, 2025, 8:44 p.m.

5.4

CVSS3.1

CVE-2025-1391 - Keycloak-services: improper authorization in keycloak organization mapper allows unauthorized organ…

A flaw was found in the Keycloak organization feature, which allows the incorrect assignment of an organization to a user if their username or email matches the organization’s domain pattern. This issue occurs at the mapper level, leading to misrepresentation in tokens. If an application relies on …

📅 Published: Feb. 17, 2025, midnight 🔄 Last Modified: Nov. 20, 2025, 7:58 p.m.
Total resulsts: 343887
Page 6186 of 34,389
« previous page » next page
Filters