5.4

CVSS3.1

CVE-2025-12908 -

Insufficient validation of untrusted input in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)

πŸ“… Published: Nov. 7, 2025, 11:23 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

8.8

CVSS3.1

CVE-2025-12907 -

Insufficient validation of untrusted input in Devtools in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to execute arbitrary code via user action in Devtools. (Chromium security severity: Low)

πŸ“… Published: Nov. 7, 2025, 11:23 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

5.4

CVSS3.1

CVE-2025-12906 -

Inappropriate implementation in Permissions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

πŸ“… Published: Nov. 7, 2025, 11:23 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

5.4

CVSS3.1

CVE-2025-12905 -

Inappropriate implementation in Downloads in Google Chrome on Windows prior to 140.0.7339.80 allowed a remote attacker to bypass Mark of the Web via a crafted HTML page. (Chromium security severity: Low)

πŸ“… Published: Nov. 7, 2025, 11:23 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

5.3

CVSS4.0

CVE-2025-64485 - CVAT: Mounted share file overwrite via crafted request

CVAT is an open source interactive video and image annotation tool for computer vision. In versions 2.4.0 through 2.48.1, a malicious CVAT user with at least the User global role may create files in the root of the mounted file share, or overwrite existing files. If no file share is mounted, the us…

πŸ“… Published: Nov. 7, 2025, 11:21 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

6.5

CVSS3.1

CVE-2025-64433 - KubeVirt Arbitrary Container File Read

KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.5.3 and 1.6.1, a vulnerability was discovered that allows a VM to read arbitrary files from the virt-launcher pod's file system. This issue stems from improper symlink handling when mounting PVC disks into a VM. Specifically…

πŸ“… Published: Nov. 7, 2025, 11:07 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

5

CVSS3.1

CVE-2025-64437 - KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes

KubeVirt is a virtual machine management add-on for Kubernetes. In versions before 1.5.3 and 1.6.1, the virt-handler does not verify whether the launcher-sock is a symlink or a regular file. This oversight can be exploited, for example, to change the ownership of arbitrary files on the host node to…

πŸ“… Published: Nov. 7, 2025, 11:04 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

6.9

CVSS4.0

CVE-2025-64436 - KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes

KubeVirt is a virtual machine management add-on for Kubernetes. In 1.5.0 and earlier, the permissions granted to the virt-handler service account, such as the ability to update VMI and patch nodes, could be abused to force a VMI migration to an attacker-controlled node. This vulnerability could oth…

πŸ“… Published: Nov. 7, 2025, 10:59 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

5.3

CVSS3.1

CVE-2025-64435 - KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation

KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.7.0-beta.0, a logic flaw in the virt-controller allows an attacker to disrupt the control over a running VMI by creating a pod with the same labels as the legitimate virt-launcher pod associated with the VMI. This can mislea…

πŸ“… Published: Nov. 7, 2025, 10:57 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

4.7

CVSS3.1

CVE-2025-64434 - KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing

KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.5.3 and 1.6.1, due to the peer verification logic in virt-handler (via verifyPeerCert), an attacker who compromises a virt-handler instance, could exploit these shared credentials to impersonate virt-api and execute privileg…

πŸ“… Published: Nov. 7, 2025, 10:54 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.
Total resulsts: 318233
Page 85 of 31,824
Β« previous page Β» next page
Filters