5.3

CVSS4.0

CVE-2025-7070 - IROAD Dashcam Q9 MFA Pairing Request allocation of resources

A vulnerability has been found in IROAD Dashcam Q9 up to 20250624 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component MFA Pairing Request Handler. The manipulation leads to allocation of resources. The attack needs to be done within the local n…

πŸ“… Published: July 4, 2025, 9:32 p.m. πŸ”„ Last Modified: July 4, 2025, 10:15 p.m.

4.8

CVSS4.0

CVE-2025-7069 - HDF5 H5FSsection.c H5FS__sect_link_size heap-based overflow

A vulnerability, which was classified as problematic, was found in HDF5 1.14.6. Affected is the function H5FS__sect_link_size of the file src/H5FSsection.c. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to…

πŸ“… Published: July 4, 2025, 9:02 p.m. πŸ”„ Last Modified: July 4, 2025, 9:15 p.m.

4.8

CVSS4.0

CVE-2025-7068 - HDF5 H5FL.c H5FL__malloc memory leak

A vulnerability, which was classified as problematic, has been found in HDF5 1.14.6. This issue affects the function H5FL__malloc of the file src/H5FL.c. The manipulation leads to memory leak. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.

πŸ“… Published: July 4, 2025, 8:32 p.m. πŸ”„ Last Modified: July 4, 2025, 9:15 p.m.

4.8

CVSS4.0

CVE-2025-7067 - HDF5 H5FScache.c H5FS__sinfo_serialize_node_cb heap-based overflow

A vulnerability classified as problematic was found in HDF5 1.14.6. This vulnerability affects the function H5FS__sinfo_serialize_node_cb of the file src/H5FScache.c. The manipulation leads to heap-based buffer overflow. Local access is required to approach this attack. The exploit has been disclos…

πŸ“… Published: July 4, 2025, 6:02 p.m. πŸ”„ Last Modified: July 4, 2025, 6:15 p.m.

0.0

CVE-2025-53485 - SecurePoll: Unauthorized access to SetTranslationHandler allows arbitrary text changes

SetTranslationHandler.php does not validate that the user is an election admin, allowing any (even unauthenticated) user to change election-related translation text. While partially broken in newer MediaWiki versions, the check is still missing. This issue affects Mediawiki - SecurePoll extensi…

πŸ“… Published: July 4, 2025, 5:39 p.m. πŸ”„ Last Modified: July 4, 2025, 6:15 p.m.

0.0

CVE-2025-53484 - SecurePoll: Multiple locations vulnerable to Cross-Site Scripting (XSS) via unescaped input

User-controlled inputs are improperly escaped in: * VotePage.php (poll option input) * ResultPage::getPagesTab() and getErrorsTab() (user-controllable page names) This allows attackers to inject JavaScript and compromise user sessions under certain conditions. This is…

πŸ“… Published: July 4, 2025, 5:34 p.m. πŸ”„ Last Modified: July 4, 2025, 6:15 p.m.

0.0

CVE-2025-53483 - SecurePoll: Multiple admin actions vulnerable to Cross-Site Request Forgery

ArchivePage.php, UnarchivePage.php, and VoterEligibilityPage#executeClear() do not validate request methods or CSRF tokens, allowing attackers to trigger sensitive actions if an admin visits a malicious site. This issue affects Mediawiki - SecurePoll extension: from 1.39.X before 1.39.13, from …

πŸ“… Published: July 4, 2025, 5:28 p.m. πŸ”„ Last Modified: July 4, 2025, 6:15 p.m.

0.0

CVE-2025-53482 - IPInfo: Message key XSS through several IPInfo messages in infobox and popup

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - IPInfo Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - IPInfo Extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, fr…

πŸ“… Published: July 4, 2025, 4:01 p.m. πŸ”„ Last Modified: July 4, 2025, 4:15 p.m.

0.0

CVE-2025-53481 - Denial of service vector on ipinfo/v0/norevision

Uncontrolled Resource Consumption vulnerability in Wikimedia Foundation Mediawiki - IPInfo Extension allows Excessive Allocation.This issue affects Mediawiki - IPInfo Extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2.

πŸ“… Published: July 4, 2025, 3:47 p.m. πŸ”„ Last Modified: July 4, 2025, 4:15 p.m.

0.0

CVE-2025-38232 - NFSD: fix race between nfsd registration and exports_proc

In the Linux kernel, the following vulnerability has been resolved: NFSD: fix race between nfsd registration and exports_proc As of now nfsd calls create_proc_exports_entry() at start of init_nfsd and cleanup by remove_proc_entry() at last of exit_nfsd. Which causes kernel OOPs if there is race …

πŸ“… Published: July 4, 2025, 1:37 p.m. πŸ”„ Last Modified: July 4, 2025, 2:15 p.m.
Total resulsts: 300585
Page 8 of 30,059
Β« previous page Β» next page
Filters