3.2

CVSS3.1

CVE-2025-29087 - sqlite: Integer Overflow in SQLite concat_ws Function

In SQLite 3.44.0 through 3.49.0 before 3.49.1, the concat_ws() SQL function can cause memory to be written beyond the end of a malloc-allocated buffer. If the separator argument is attacker-controlled and has a large string (e.g., 2MB or more), an integer overflow occurs in calculating the size of …

πŸ“… Published: April 7, 2025, midnight πŸ”„ Last Modified: April 30, 2025, 12:43 p.m.

3.7

CVSS3.1

CVE-2025-3360 - Glibc: glib prior to 2.82.5 is vulnerable to integer overflow and buffer under-read when parsing a…

A flaw was found in GLib. An integer overflow and buffer under-read occur when parsing a long invalid ISO 8601 timestamp with the g_date_time_new_from_iso8601() function.

πŸ“… Published: April 7, 2025, midnight πŸ”„ Last Modified: Nov. 21, 2025, 7:16 a.m.

6.7

CVSS3.1

CVE-2025-28401 -

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the menuId parameter

πŸ“… Published: April 7, 2025, midnight πŸ”„ Last Modified: April 9, 2025, 5:19 p.m.

7.2

CVSS3.1

CVE-2025-28403 -

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method does not properly validate whether the requesting user has administrative privileges before allowing modifications to system configuration settings

πŸ“… Published: April 7, 2025, midnight πŸ”„ Last Modified: April 9, 2025, 4:48 p.m.

6.2

CVSS3.1

CVE-2025-29482 -

Buffer Overflow vulnerability in libheif 1.19.7 allows a local attacker to execute arbitrary code via the SAO (Sample Adaptive Offset) processing of libde265.

πŸ“… Published: April 7, 2025, midnight πŸ”„ Last Modified: April 15, 2025, 4:10 p.m.

9.8

CVSS3.1

CVE-2025-28413 -

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the SysDictTypeController component

πŸ“… Published: April 7, 2025, midnight πŸ”„ Last Modified: April 9, 2025, 2:58 p.m.

8.8

CVSS3.1

CVE-2025-28407 -

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the edit method of the /edit/{dictId} endpoint does not properly validate whether the requesting user has permission to modify the specified dictId

πŸ“… Published: April 7, 2025, midnight πŸ”„ Last Modified: April 9, 2025, 7 p.m.

9.8

CVSS3.1

CVE-2025-28411 -

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method in /tool/gen/editSave

πŸ“… Published: April 7, 2025, midnight πŸ”„ Last Modified: April 9, 2025, 6:45 p.m.

6.1

CVSS3.1

CVE-2025-29594 -

A vulnerability exists in the errorpage.php file of the CS2-WeaponPaints-Website v2.1.7 where user-controlled input is not adequately validated before being processed. Specifically, the $_GET['errorcode'] parameter can be manipulated to access unauthorized error codes, leading to Cross-Site Scripti…

πŸ“… Published: April 7, 2025, midnight πŸ”„ Last Modified: April 8, 2025, 6:13 p.m.

5.5

CVSS3.1

CVE-2025-29480 - gdal: Buffer Overflow in GDAL

Buffer Overflow vulnerability in gdal 3.10.2 allows a local attacker to cause a denial of service via the OGRSpatialReference::Release function. NOTE: the Supplier indicates that the report is invalid and could not be reproduced.

πŸ“… Published: April 7, 2025, midnight πŸ”„ Last Modified: July 24, 2025, 2:34 p.m.
Total resulsts: 343968
Page 5476 of 34,397
Β« previous page Β» next page
Filters