7.1
CVE-2024-57255 -
An integer overflow in sqfs_resolve_symlink in Das U-Boot before 2025.01-rc1 occurs via a crafted squashfs filesystem with an inode size of 0xffffffff, resulting in a malloc of zero and resultant memory overwrite.
5.9
CVE-2025-26466 - Openssh: denial-of-service in openssh
A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a queue of packages. It is only freed when the server/client key exchange has finished. A malicious client may keep sending such packages, leading to anβ¦
6.5
CVE-2025-25469 -
FFmpeg git-master before commit d5873b was discovered to contain a memory leak in the component libavutil/iamf.c.
6.5
CVE-2025-25468 -
FFmpeg git-master before commit d5873b was discovered to contain a memory leak in the component libavutil/mem.c.
7.1
CVE-2024-57258 -
Integer overflows in memory allocation in Das U-Boot before 2025.01-rc1 occur for a crafted squashfs filesystem via sbrk, via request2size, or because ptrdiff_t is mishandled on x86_64.
7.5
CVE-2025-25475 - dcmtk: NULL Pointer Dereference in DCMTK dcrleccd.cc Leading to DoS
A NULL pointer dereference in the component /libsrc/dcrleccd.cc of DCMTK v3.6.9+ DEV allows attackers to cause a Denial of Service (DoS) via a crafted DICOM file.
4.2
CVE-2025-26058 -
Webkul QloApps v1.6.1 exposes authentication tokens in URLs during redirection. When users access the admin panel or other protected areas, the application appends sensitive authentication tokens directly to the URL.
5.3
CVE-2025-25472 - dcmtk: Buffer Overflow in DCMTK Leading to DoS
A buffer overflow in DCMTK git master v3.6.9+ DEV allows attackers to cause a Denial of Service (DoS) via a crafted DCM file.
7.8
CVE-2025-24928 - libxml2: Stack-based buffer overflow in xmlSnprintfElements of libxml2
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted DTD. NOTE: this is similar to CVE-2017-9047.
7.8
CVE-2024-56171 - libxml2: Use-After-Free in libxml2
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be useβ¦