Количество 18
Количество 18
ELSA-2025-7433
ELSA-2025-7433: nodejs:22 security update (IMPORTANT)
ELSA-2025-4459
ELSA-2025-4459: nodejs:22 security update (IMPORTANT)

CVE-2025-3277
An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used to allocate a buffer. When SQLite then writes the resulting string to the buffer, it uses the original, untruncated size and thus a wild Heap Buffer overflow of size ~4GB can be triggered. This can result in arbitrary code execution.

CVE-2025-3277
An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used to allocate a buffer. When SQLite then writes the resulting string to the buffer, it uses the original, untruncated size and thus a wild Heap Buffer overflow of size ~4GB can be triggered. This can result in arbitrary code execution.

CVE-2025-3277
An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used to allocate a buffer. When SQLite then writes the resulting string to the buffer, it uses the original, untruncated size and thus a wild Heap Buffer overflow of size ~4GB can be triggered. This can result in arbitrary code execution.
CVE-2025-3277
An integer overflow can be triggered in SQLite\u2019s `concat_ws()` fu ...

CVE-2025-31498
c-ares is an asynchronous resolver library. From 1.32.3 through 1.34.4, there is a use-after-free in read_answers() when process_answer() may re-enqueue a query either due to a DNS Cookie Failure or when the upstream server does not properly support EDNS, or possibly on TCP queries if the remote closed the connection immediately after a response. If there was an issue trying to put that new transaction on the wire, it would close the connection handle, but read_answers() was still expecting the connection handle to be available to possibly dequeue other responses. In theory a remote attacker might be able to trigger this by flooding the target with ICMP UNREACHABLE packets if they also control the upstream nameserver and can return a result with one of those conditions, this has been untested. Otherwise only a local attacker might be able to change system behavior to make send()/write() return a failure condition. This vulnerability is fixed in 1.34.5.

CVE-2025-31498
c-ares is an asynchronous resolver library. From 1.32.3 through 1.34.4, there is a use-after-free in read_answers() when process_answer() may re-enqueue a query either due to a DNS Cookie Failure or when the upstream server does not properly support EDNS, or possibly on TCP queries if the remote closed the connection immediately after a response. If there was an issue trying to put that new transaction on the wire, it would close the connection handle, but read_answers() was still expecting the connection handle to be available to possibly dequeue other responses. In theory a remote attacker might be able to trigger this by flooding the target with ICMP UNREACHABLE packets if they also control the upstream nameserver and can return a result with one of those conditions, this has been untested. Otherwise only a local attacker might be able to change system behavior to make send()/write() return a failure condition. This vulnerability is fixed in 1.34.5.

CVE-2025-31498
c-ares is an asynchronous resolver library. From 1.32.3 through 1.34.4, there is a use-after-free in read_answers() when process_answer() may re-enqueue a query either due to a DNS Cookie Failure or when the upstream server does not properly support EDNS, or possibly on TCP queries if the remote closed the connection immediately after a response. If there was an issue trying to put that new transaction on the wire, it would close the connection handle, but read_answers() was still expecting the connection handle to be available to possibly dequeue other responses. In theory a remote attacker might be able to trigger this by flooding the target with ICMP UNREACHABLE packets if they also control the upstream nameserver and can return a result with one of those conditions, this has been untested. Otherwise only a local attacker might be able to change system behavior to make send()/write() return a failure condition. This vulnerability is fixed in 1.34.5.

CVE-2025-31498
CVE-2025-31498
c-ares is an asynchronous resolver library. From 1.32.3 through 1.34.4 ...
GHSA-g2ph-wvc2-ph4v
An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used to allocate a buffer. When SQLite then writes the resulting string to the buffer, it uses the original, untruncated size and thus a wild Heap Buffer overflow of size ~4GB can be triggered. This can result in arbitrary code execution.
ELSA-2025-7426
ELSA-2025-7426: nodejs:20 security update (MODERATE)
ELSA-2025-4461
ELSA-2025-4461: nodejs:20 security update (MODERATE)

BDU:2025-04858
Уязвимость библиотеки асинхронных DNS-запросов C-ares, связанная с возможностью использования памяти после освобождения, позволяющая нарушителю вызвать отказ в обслуживании

SUSE-SU-2025:1456-1
Security update for sqlite3

SUSE-SU-2025:1455-1
Security update for sqlite3

SUSE-SU-2025:01456-1
Security update for sqlite3
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
ELSA-2025-7433 ELSA-2025-7433: nodejs:22 security update (IMPORTANT) | 29 дней назад | |||
ELSA-2025-4459 ELSA-2025-4459: nodejs:22 security update (IMPORTANT) | около 2 месяцев назад | |||
![]() | CVE-2025-3277 An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used to allocate a buffer. When SQLite then writes the resulting string to the buffer, it uses the original, untruncated size and thus a wild Heap Buffer overflow of size ~4GB can be triggered. This can result in arbitrary code execution. | 0% Низкий | 2 месяца назад | |
![]() | CVE-2025-3277 An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used to allocate a buffer. When SQLite then writes the resulting string to the buffer, it uses the original, untruncated size and thus a wild Heap Buffer overflow of size ~4GB can be triggered. This can result in arbitrary code execution. | CVSS3: 7.3 | 0% Низкий | 2 месяца назад |
![]() | CVE-2025-3277 An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used to allocate a buffer. When SQLite then writes the resulting string to the buffer, it uses the original, untruncated size and thus a wild Heap Buffer overflow of size ~4GB can be triggered. This can result in arbitrary code execution. | 0% Низкий | 2 месяца назад | |
CVE-2025-3277 An integer overflow can be triggered in SQLite\u2019s `concat_ws()` fu ... | 0% Низкий | 2 месяца назад | ||
![]() | CVE-2025-31498 c-ares is an asynchronous resolver library. From 1.32.3 through 1.34.4, there is a use-after-free in read_answers() when process_answer() may re-enqueue a query either due to a DNS Cookie Failure or when the upstream server does not properly support EDNS, or possibly on TCP queries if the remote closed the connection immediately after a response. If there was an issue trying to put that new transaction on the wire, it would close the connection handle, but read_answers() was still expecting the connection handle to be available to possibly dequeue other responses. In theory a remote attacker might be able to trigger this by flooding the target with ICMP UNREACHABLE packets if they also control the upstream nameserver and can return a result with one of those conditions, this has been untested. Otherwise only a local attacker might be able to change system behavior to make send()/write() return a failure condition. This vulnerability is fixed in 1.34.5. | 0% Низкий | 2 месяца назад | |
![]() | CVE-2025-31498 c-ares is an asynchronous resolver library. From 1.32.3 through 1.34.4, there is a use-after-free in read_answers() when process_answer() may re-enqueue a query either due to a DNS Cookie Failure or when the upstream server does not properly support EDNS, or possibly on TCP queries if the remote closed the connection immediately after a response. If there was an issue trying to put that new transaction on the wire, it would close the connection handle, but read_answers() was still expecting the connection handle to be available to possibly dequeue other responses. In theory a remote attacker might be able to trigger this by flooding the target with ICMP UNREACHABLE packets if they also control the upstream nameserver and can return a result with one of those conditions, this has been untested. Otherwise only a local attacker might be able to change system behavior to make send()/write() return a failure condition. This vulnerability is fixed in 1.34.5. | CVSS3: 7 | 0% Низкий | 2 месяца назад |
![]() | CVE-2025-31498 c-ares is an asynchronous resolver library. From 1.32.3 through 1.34.4, there is a use-after-free in read_answers() when process_answer() may re-enqueue a query either due to a DNS Cookie Failure or when the upstream server does not properly support EDNS, or possibly on TCP queries if the remote closed the connection immediately after a response. If there was an issue trying to put that new transaction on the wire, it would close the connection handle, but read_answers() was still expecting the connection handle to be available to possibly dequeue other responses. In theory a remote attacker might be able to trigger this by flooding the target with ICMP UNREACHABLE packets if they also control the upstream nameserver and can return a result with one of those conditions, this has been untested. Otherwise only a local attacker might be able to change system behavior to make send()/write() return a failure condition. This vulnerability is fixed in 1.34.5. | 0% Низкий | 2 месяца назад | |
![]() | 0% Низкий | 2 месяца назад | ||
CVE-2025-31498 c-ares is an asynchronous resolver library. From 1.32.3 through 1.34.4 ... | 0% Низкий | 2 месяца назад | ||
GHSA-g2ph-wvc2-ph4v An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used to allocate a buffer. When SQLite then writes the resulting string to the buffer, it uses the original, untruncated size and thus a wild Heap Buffer overflow of size ~4GB can be triggered. This can result in arbitrary code execution. | 0% Низкий | 2 месяца назад | ||
ELSA-2025-7426 ELSA-2025-7426: nodejs:20 security update (MODERATE) | 30 дней назад | |||
ELSA-2025-4461 ELSA-2025-4461: nodejs:20 security update (MODERATE) | около 2 месяцев назад | |||
![]() | BDU:2025-04858 Уязвимость библиотеки асинхронных DNS-запросов C-ares, связанная с возможностью использования памяти после освобождения, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7 | 0% Низкий | 2 месяца назад |
![]() | SUSE-SU-2025:1456-1 Security update for sqlite3 | около 1 месяца назад | ||
![]() | SUSE-SU-2025:1455-1 Security update for sqlite3 | около 1 месяца назад | ||
![]() | SUSE-SU-2025:01456-1 Security update for sqlite3 | 19 дней назад |
Уязвимостей на страницу