4.2

CVSS3.1

CVE-2025-26603 - heap-use-after-free in function str_to_reg in vim/vim

Vim is a greatly improved version of the good old UNIX editor Vi. Vim allows to redirect screen messages using the `:redir` ex command to register, variables and files. It also allows to show the contents of registers using the `:registers` or `:display` ex command. When redirecting the output of `…

πŸ“… Published: Feb. 18, 2025, 7:04 p.m. πŸ”„ Last Modified: Aug. 18, 2025, 6:23 p.m.

7

CVSS3.1

CVE-2025-25305 - SSL validation for outgoing requests in Home Assistant Core and used libs not correct

Home Assistant Core is an open source home automation that puts local control and privacy first. Affected versions are subject to a potential man-in-the-middle attacks due to missing SSL certificate verification in the project codebase and used third-party libraries. In the past, `aiohttp-session`/…

πŸ“… Published: Feb. 18, 2025, 6:53 p.m. πŸ”„ Last Modified: Feb. 18, 2025, 7:23 p.m.

8.7

CVSS4.0

CVE-2025-25284 - Path Traversal and Local File Read via VRT (Virtual Format) in ZOO-Project WPS Implementation

The ZOO-Project is an open source processing platform, released under MIT/X11 Licence. A vulnerability in ZOO-Project's WPS (Web Processing Service) implementation allows unauthorized access to files outside the intended directory through path traversal. Specifically, the Gdal_Translate service, wh…

πŸ“… Published: Feb. 18, 2025, 6:42 p.m. πŸ”„ Last Modified: Feb. 18, 2025, 7:29 p.m.

9.1

CVSS3.1

CVE-2025-24895 - SAML Response Signature Verification Bypass in CIE.AspNetCore.Authentication

CIE.AspNetCore.Authentication is an AspNetCore Remote Authenticator for CIE 3.0. Authentication using Spid and CIE is based on the SAML2 standard which provides two entities: 1. Identity Provider (IDP): the system that authenticates users and provides identity information (SAML affirmation) to the …

πŸ“… Published: Feb. 18, 2025, 6:39 p.m. πŸ”„ Last Modified: Feb. 18, 2025, 7:39 p.m.

9.1

CVSS3.1

CVE-2025-24894 - SAML Response Signature Verification Bypass in SPID.AspNetCore.Authentication

SPID.AspNetCore.Authentication is an AspNetCore Remote Authenticator for SPID. Authentication using Spid and CIE is based on the SAML2 standard which provides two entities: Identity Provider (IDP): the system that authenticates users and provides identity information (SAML affirmation) to the Servi…

πŸ“… Published: Feb. 18, 2025, 6:39 p.m. πŸ”„ Last Modified: Feb. 18, 2025, 7:46 p.m.

5.3

CVSS4.0

CVE-2025-21608 - Forged packets over MQTT can show up in direct messages in Meshtastic firmware

Meshtastic is an open source mesh networking solution. In affected firmware versions crafted packets over MQTT are able to appear as a DM in client to a node even though they were not decoded with PKC. This issue has been addressed in version 2.5.19 and all users are advised to upgrade. There are n…

πŸ“… Published: Feb. 18, 2025, 6:17 p.m. πŸ”„ Last Modified: Sept. 23, 2025, 7:20 p.m.

6.1

CVSS3.1

CVE-2025-0690 - Grub2: read: integer overflow may lead to out-of-bounds write

The read command is used to read the keyboard input from the user, while reads it keeps the input length in a 32-bit integer value which is further used to reallocate the line buffer to accept the next character. During this process, with a line big enough it's possible to make this variable to ove…

πŸ“… Published: Feb. 18, 2025, 6 p.m. πŸ”„ Last Modified: Feb. 25, 2026, 8:32 p.m.

6.4

CVSS3.1

CVE-2025-0684 - Grub2: reiserfs: integer overflow when handling symlinks may lead to heap based out-of-bounds write…

A flaw was found in grub2. When performing a symlink lookup from a reiserfs filesystem, grub's reiserfs fs module uses user-controlled parameters from the filesystem geometry to determine the internal buffer size, however, it improperly checks for integer overflows. A maliciouly crafted filesystem …

πŸ“… Published: Feb. 18, 2025, 6 p.m. πŸ”„ Last Modified: Nov. 20, 2025, 8 p.m.

7.8

CVSS3.1

CVE-2025-0678 - Grub2: squash4: integer overflow may lead to heap based out-of-bounds write when reading data

A flaw was found in grub2. When reading data from a squash4 filesystem, grub's squash4 fs module uses user-controlled parameters from the filesystem geometry to determine the internal buffer size, however, it improperly checks for integer overflows. A maliciously crafted filesystem may lead some of…

πŸ“… Published: Feb. 18, 2025, 6 p.m. πŸ”„ Last Modified: Nov. 20, 2025, 7:59 p.m.

7.6

CVSS3.1

CVE-2025-0624 - Grub2: net: out-of-bounds write in grub_net_search_config_file()

A flaw was found in grub2. During the network boot process, when trying to search for the configuration file, grub copies data from a user controlled environment variable into an internal buffer using the grub_strcpy() function. During this step, it fails to consider the environment variable length…

πŸ“… Published: Feb. 18, 2025, 6 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:08 p.m.
Total resulsts: 344676
Page 6246 of 34,468
Β« previous page Β» next page
Filters