6.9
CVE-2024-10604 - Identifiable Header Values In Fuchsia Leading To Tracking of The User
Vulnerabilities in the algorithms used by Fuchsia to populate network protocol header fields, specifically the TCP ISN, TCP timestamp, TCP and UDP source ports, and IPv4/IPv6 fragment ID allow for these values to be guessed under circumstances
6.3
CVE-2024-10603 -
Weaknesses in the generation of TCP/UDP source ports and some other header values in Google's gVisor allowed them to be predicted by an external attacker in some circumstances.
6.3
CVE-2024-10026 - Improved Seeding and Hashing In gVisor
A weak hashing algorithm and small sizes of seeds/secrets in Google's gVisor allowed for a remote attacker to calculate a local IP address and a per-boot identifier that could aid in tracking of a device in certain circumstances.
6.9
CVE-2025-0681 - New Rock Technologies Cloud Connected Devices Improper Neutralization of Wildcards or Matching Symโฆ
The Cloud MQTT service of the affected products supports wildcard topic subscription which could allow an attacker to obtain sensitive information from tapping the service communications.
9.3
CVE-2025-0680 - New Rock Technologies Cloud Connected Devices has a Improper Neutralization of Special Elements useโฆ
Affected products contain a vulnerability in the device cloud rpc command handling process that could allow remote attackers to take control over arbitrary devices connected to the cloud.
7.8
CVE-2024-44142 -
The issue was addressed with improved bounds checks. This issue is fixed in GarageBand 10.4.12. Processing a maliciously crafted image may lead to arbitrary code execution.
8.9
CVE-2025-24507 -
This vulnerability allows appliance compromise at boot time.
5.3
CVE-2025-24506 -
A specific authentication strategy allows to learn ids of PAM users associated with certain authentication types.
8.8
CVE-2025-24505 -
This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected PAM system by uploading a specially crafted upgrade file.
5.3
CVE-2025-24504 -
An improper input validation the CSRF filter results in unsanitized user input written to the application logs.