0.0

CVE-2025-2722 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: The code maintainer explains that "[the] call is invalid [because] p_n_param is an input-output parameter indicatin…

πŸ“… Published: March 25, 2025, 12:31 a.m. πŸ”„ Last Modified: April 22, 2025, 1:15 p.m.

0.0

CVE-2025-2721 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: The code maintainer explains that "[the] call is invalid [as] the buffer pointed to by "data" must have "len" valid…

πŸ“… Published: March 25, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 1:15 p.m.

7.5

CVSS3.1

CVE-2024-44903 -

SQL Injection can occur in the SirsiDynix Horizon Information Portal (IPAC20) through 3.25_9382; however, a patch is available from the vendor. This is in ipac.jsp in a SELECT WHERE statement, in a part of the uri= variable in the second part of the full= inner variable.

πŸ“… Published: March 25, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-25374 -

In NASA cFS (Core Flight System) Aquila, it is possible to put the onboard software in a state that will prevent the launch of any external application, causing a platform denial of service.

πŸ“… Published: March 25, 2025, midnight πŸ”„ Last Modified: April 30, 2026, 6:57 p.m.

4.3

CVSS3.1

CVE-2025-2786 - Tempo-operator: serviceaccount token exposure leading to token and subject access reviews in opensh…

A flaw was found in Tempo Operator, where it creates a ServiceAccount, ClusterRole, and ClusterRoleBinding when a user deploys a TempoStack or TempoMonolithic instance. This flaw allows a user with full access to their namespace to extract the ServiceAccount token and use it to submit TokenReview a…

πŸ“… Published: March 25, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-48818 -

An issue in IIT Bombay, Mumbai, India Bodhitree of cs101 version allows a remote attacker to execute arbitrary code.

πŸ“… Published: March 25, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7

CVSS3.1

CVE-2025-2784 - Libsoup: heap buffer over-read in `skip_insignificant_space` when sniffing content

A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_insight_whitespace() function. Libsoup clients may read one byte out-of-bounds in response to a crafted HTTP response by an HTTP server.

πŸ“… Published: March 25, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 9:15 a.m.

4.3

CVSS3.1

CVE-2025-30741 -

Pixelfed before 0.12.5 allows anyone to follow private accounts and see private posts on other Fediverse servers. This affects users elsewhere in the Fediverse, if they otherwise have any followers from a Pixelfed instance.

πŸ“… Published: March 25, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2025-27833 - Ghostscript: Buffer overflow with long TTF font name

An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs for a long TTF font name to pdf/pdf_fmap.c.

πŸ“… Published: March 25, 2025, midnight πŸ”„ Last Modified: April 1, 2025, 4:44 p.m.

9.8

CVSS3.1

CVE-2025-27832 - Ghostscript: NPDL device: Compression buffer overflow

An issue was discovered in Artifex Ghostscript before 10.05.0. The NPDL device has a Compression buffer overflow for contrib/japanese/gdevnpdl.c.

πŸ“… Published: March 25, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:18 p.m.
Total resulsts: 348435
Page 6153 of 34,844
Β« previous page Β» next page
Filters