9

CVSS3.1

CVE-2025-32911 - Libsoup: double free on soup_message_headers_get_content_disposition() through "soup-message-head…

A use-after-free type vulnerability was found in libsoup, in the soup_message_headers_get_content_disposition() function. This flaw allows a malicious HTTP client to cause memory corruption in the libsoup server.

πŸ“… Published: April 14, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 9:15 a.m.

7.5

CVSS3.1

CVE-2025-32913 - Libsoup: null pointer dereference in soup_message_headers_get_content_disposition when "filename" …

A flaw was found in libsoup, where the soup_message_headers_get_content_disposition() function is vulnerable to a NULL pointer dereference. This flaw allows a malicious HTTP peer to crash a libsoup client or server that uses this function.

πŸ“… Published: April 14, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 9:15 a.m.

7.5

CVSS3.1

CVE-2025-32908 - Libsoup: denial of service on libsoup through http/2 server

A flaw was found in libsoup. The HTTP/2 server in libsoup may not fully validate the values of pseudo-headers :scheme, :authority, and :path, which may allow a user to cause a denial of service (DoS).

πŸ“… Published: April 14, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 9:06 a.m.

7.5

CVSS3.1

CVE-2025-32906 - Libsoup: out of bounds reads in soup_headers_parse_request()

A flaw was found in libsoup, where the soup_headers_parse_request() function may be vulnerable to an out-of-bound read. This flaw allows a malicious user to use a specially crafted HTTP request to crash the HTTP server.

πŸ“… Published: April 14, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 9:15 a.m.

6.5

CVSS3.1

CVE-2025-32912 - Libsoup: null pointer dereference in client when server omits the "nonce" parameter in an unauthor…

A flaw was found in libsoup, where SoupAuthDigest is vulnerable to a NULL pointer dereference. The HTTP server may cause the libsoup client to crash.

πŸ“… Published: April 14, 2025, midnight πŸ”„ Last Modified: Nov. 6, 2025, 11:08 p.m.

5.3

CVSS3.1

CVE-2025-32907 - Libsoup: denial of service in server when client requests a large amount of overlapping ranges wit…

A flaw was found in libsoup. The implementation of HTTP range requests is vulnerable to a resource consumption attack. This flaw allows a malicious client to request the same range many times in a single HTTP request, causing the server to use large amounts of memory. This does not allow for a full…

πŸ“… Published: April 14, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 8:35 a.m.

4.8

CVSS3.1

CVE-2025-29720 -

Dify v1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_files.RemoteFileUploadApi.

πŸ“… Published: April 14, 2025, midnight πŸ”„ Last Modified: June 18, 2025, 1:40 p.m.

7.4

CVSS3.1

CVE-2025-32914 - Libsoup: oob read on libsoup through function "soup_multipart_new_from_message" in soup-multipart.…

A flaw was found in libsoup, where the soup_multipart_new_from_message() function is vulnerable to an out-of-bounds read. This flaw allows a malicious HTTP client to induce the libsoup server to read out of bounds.

πŸ“… Published: April 14, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 9:15 a.m.

0.0

CVE-2025-32930 -

DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA.

πŸ“… Published: April 14, 2025, midnight πŸ”„ Last Modified: April 14, 2025, 3:15 p.m.

5.3

CVSS3.1

CVE-2025-32909 - Libsoup: null pointer dereference on libsoup through function "sniff_mp4" in soup-content-sniffer.c

A flaw was found in libsoup. SoupContentSniffer may be vulnerable to a NULL pointer dereference in the sniff_mp4 function. The HTTP server may cause the libsoup client to crash.

πŸ“… Published: April 14, 2025, midnight πŸ”„ Last Modified: Nov. 6, 2025, 11:08 p.m.
Total resulsts: 342218
Page 5201 of 34,222
Β« previous page Β» next page
Filters