0.0

CVE-2025-4085 -

An attacker with control over a content process could potentially leverage the privileged UITour actor to leak sensitive information or escalate privileges. This vulnerability affects Firefox < 138 and Thunderbird < 138.

πŸ“… Published: April 29, 2025, 1:13 p.m. πŸ”„ Last Modified: April 30, 2025, 3:56 a.m.

0.0

CVE-2025-4084 -

Due to insufficient escaping of the special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. *This bug only affects Firefox for Windows. Other versions of Firefox are unaffected.* This…

πŸ“… Published: April 29, 2025, 1:13 p.m. πŸ”„ Last Modified: April 30, 2025, 3:56 a.m.

0.0

CVE-2025-4083 -

A process isolation vulnerability in Firefox stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level document's process instead of the intended frame, potentially enabling a sandbox escape. This vulnerability affects Firefox < 138, Firefox ESR < 128…

πŸ“… Published: April 29, 2025, 1:13 p.m. πŸ”„ Last Modified: April 29, 2025, 2:15 p.m.

0.0

CVE-2025-4082 -

Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vulnerabilities, could be used to escalate privileges. *This bug only affects Firefox for macOS. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 138, …

πŸ“… Published: April 29, 2025, 1:13 p.m. πŸ”„ Last Modified: April 30, 2025, 3:56 a.m.

8.8

CVSS3.1

CVE-2025-2817 -

Mozilla Firefox's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking behavior. By injecting code into the user-privileged process, an attacker could bypass intended access controls, allowing SYSTEM-level file operatio…

πŸ“… Published: April 29, 2025, 1:13 p.m. πŸ”„ Last Modified: April 30, 2025, 3:56 a.m.

4.8

CVSS4.0

CVE-2025-4061 - code-projects Clothing Store Management System add_item stack-based overflow

A vulnerability, which was classified as critical, was found in code-projects Clothing Store Management System up to 1.0. Affected is the function add_item. The manipulation of the argument st.productname leads to stack-based buffer overflow. Attacking locally is a requirement. The exploit has been…

πŸ“… Published: April 29, 2025, 1 p.m. πŸ”„ Last Modified: April 29, 2025, 2:15 p.m.

6.9

CVSS4.0

CVE-2025-4060 - PHPGurukul Notice Board System category.php sql injection

A vulnerability, which was classified as critical, has been found in PHPGurukul Notice Board System 1.0. This issue affects some unknown processing of the file /category.php. The manipulation of the argument catname leads to sql injection. The attack may be initiated remotely. The exploit has been …

πŸ“… Published: April 29, 2025, 12:31 p.m. πŸ”„ Last Modified: April 29, 2025, 1:52 p.m.

4.8

CVSS4.0

CVE-2025-4059 - code-projects Prison Management System Prison_Mgmt_Sys addrecord stack-based overflow

A vulnerability classified as critical was found in code-projects Prison Management System 1.0. This vulnerability affects the function addrecord of the component Prison_Mgmt_Sys. The manipulation of the argument filename leads to stack-based buffer overflow. An attack has to be approached locally.…

πŸ“… Published: April 29, 2025, noon πŸ”„ Last Modified: April 29, 2025, 1:52 p.m.

5.3

CVSS3.1

CVE-2025-3891 - Mod_auth_openidc: dos via empty post in mod_auth_openidc with oidcpreservepost enabled

A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability.

πŸ“… Published: April 29, 2025, 11:56 a.m. πŸ”„ Last Modified: April 29, 2025, 1:52 p.m.

0.0

CVE-2024-58099 - vmxnet3: Fix packet corruption in vmxnet3_xdp_xmit_frame

In the Linux kernel, the following vulnerability has been resolved: vmxnet3: Fix packet corruption in vmxnet3_xdp_xmit_frame Andrew and Nikolay reported connectivity issues with Cilium's service load-balancing in case of vmxnet3. If a BPF program for native XDP adds an encapsulation header such …

πŸ“… Published: April 29, 2025, 11:45 a.m. πŸ”„ Last Modified: April 29, 2025, 1:52 p.m.
Total resulsts: 291774
Page 7 of 29,178
Β« previous page Β» next page
Filters