6.5
CVE-2025-15338 - Tanium addressed an incorrect default permissions vulnerability in Partner Integration.
Tanium addressed an incorrect default permissions vulnerability in Partner Integration.
6.5
CVE-2025-15336 - Tanium addressed an incorrect default permissions vulnerability in Performance.
Tanium addressed an incorrect default permissions vulnerability in Performance.
6.5
CVE-2025-15337 - Tanium addressed an incorrect default permissions vulnerability in Patch.
Tanium addressed an incorrect default permissions vulnerability in Patch.
4.3
CVE-2025-15342 - Tanium addressed an improper access controls vulnerability in Reputation.
Tanium addressed an improper access controls vulnerability in Reputation.
3.7
CVE-2025-15323 - Tanium addressed an improper certificate validation vulnerability in Tanium Appliance.
Tanium addressed an improper certificate validation vulnerability in Tanium Appliance.
6.5
CVE-2025-15343 - Tanium addressed an incorrect default permissions vulnerability in Enforce.
Tanium addressed an incorrect default permissions vulnerability in Enforce.
3.1
CVE-2025-15289 - Tanium addressed an improper access controls vulnerability in Interact.
Tanium addressed an improper access controls vulnerability in Interact.
5.3
CVE-2025-58190 - Infinite parsing loop in golang.org/x/net
The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.
7.4
CVE-2025-68121 - Unexpected session resumption in crypto/tls
During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returneβ¦
5.3
CVE-2025-47911 - Quadratic parsing complexity in golang.org/x/net/html
The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.