Количество 17 873
Количество 17 873
CVE-2025-6491
NULL Pointer Dereference in PHP SOAP Extension via Large XML Namespace Prefix
CVE-2025-6442
CVE-2025-6395
Gnutls: null pointer dereference in _gnutls_figure_common_ciphersuite()
CVE-2025-62813
LZ4 through 1.10.0 allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact when the application processes untrusted LZ4 frames. For example, LZ4F_createCDict_advanced in lib/lz4frame.c mishandles NULL checks.
CVE-2025-6270
HDF5 H5FSsection.c H5FS__sect_find_node heap-based overflow
CVE-2025-6269
HDF5 H5Cimage.c H5C__reconstruct_cache_entry heap-based overflow
CVE-2025-62518
astral-tokio-tar Vulnerable to PAX Header Desynchronization
CVE-2025-62168
Squid vulnerable to information disclosure via authentication credential leakage in error handling
CVE-2025-6199
Gdk-pixbuf: uninitialized memory disclosure in gdkpixbuf gif lzw decoder
CVE-2025-61985
ssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a ProxyCommand is used.
CVE-2025-61984
ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially leading to code execution when a ProxyCommand is used. The untrusted sources are the command line and %-sequence expansion of a configuration file. (A configuration file that provides a complete literal username is not categorized as an untrusted source.)
CVE-2025-6192
Chromium: CVE-2025-6192 Use after free in Profiler
CVE-2025-6191
Chromium: CVE-2025-6191 Integer overflow in V8
CVE-2025-6170
Libxml2: stack buffer overflow in xmllint interactive shell command handling
CVE-2025-6141
GNU ncurses parse_entry.c postprocess_termcap stack-based overflow
CVE-2025-6140
spdlog pattern_formatter-inl.h scoped_padder resource consumption
CVE-2025-60711
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2025-6069
HTMLParser quadratic complexity when processing malformed inputs
CVE-2025-6052
Glib: integer overflow in g_string_maybe_expand() leading to potential buffer overflow in glib gstring
CVE-2025-6032
Podman: podman missing tls verification
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2025-6491 NULL Pointer Dereference in PHP SOAP Extension via Large XML Namespace Prefix | CVSS3: 5.9 | 0% Низкий | 3 месяца назад | |
CVSS3: 6.5 | 0% Низкий | 4 месяца назад | ||
CVE-2025-6395 Gnutls: null pointer dereference in _gnutls_figure_common_ciphersuite() | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
CVE-2025-62813 LZ4 through 1.10.0 allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact when the application processes untrusted LZ4 frames. For example, LZ4F_createCDict_advanced in lib/lz4frame.c mishandles NULL checks. | CVSS3: 5.9 | 10 дней назад | ||
CVE-2025-6270 HDF5 H5FSsection.c H5FS__sect_find_node heap-based overflow | 0% Низкий | 2 месяца назад | ||
CVE-2025-6269 HDF5 H5Cimage.c H5C__reconstruct_cache_entry heap-based overflow | 0% Низкий | 2 месяца назад | ||
CVE-2025-62518 astral-tokio-tar Vulnerable to PAX Header Desynchronization | 0% Низкий | 9 дней назад | ||
CVE-2025-62168 Squid vulnerable to information disclosure via authentication credential leakage in error handling | CVSS3: 10 | 0% Низкий | 15 дней назад | |
CVE-2025-6199 Gdk-pixbuf: uninitialized memory disclosure in gdkpixbuf gif lzw decoder | CVSS3: 3.3 | 0% Низкий | 4 месяца назад | |
CVE-2025-61985 ssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a ProxyCommand is used. | CVSS3: 3.6 | 0% Низкий | 26 дней назад | |
CVE-2025-61984 ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially leading to code execution when a ProxyCommand is used. The untrusted sources are the command line and %-sequence expansion of a configuration file. (A configuration file that provides a complete literal username is not categorized as an untrusted source.) | CVSS3: 3.6 | 0% Низкий | 26 дней назад | |
CVE-2025-6192 Chromium: CVE-2025-6192 Use after free in Profiler | 0% Низкий | 5 месяцев назад | ||
CVE-2025-6191 Chromium: CVE-2025-6191 Integer overflow in V8 | 0% Низкий | 5 месяцев назад | ||
CVE-2025-6170 Libxml2: stack buffer overflow in xmllint interactive shell command handling | CVSS3: 2.5 | 0% Низкий | 3 месяца назад | |
CVE-2025-6141 GNU ncurses parse_entry.c postprocess_termcap stack-based overflow | 0% Низкий | 2 месяца назад | ||
CVE-2025-6140 spdlog pattern_formatter-inl.h scoped_padder resource consumption | CVSS3: 3.3 | 0% Низкий | 3 месяца назад | |
CVE-2025-60711 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | CVSS3: 6.3 | 0% Низкий | 3 дня назад | |
CVE-2025-6069 HTMLParser quadratic complexity when processing malformed inputs | CVSS3: 4.3 | 0% Низкий | 4 месяца назад | |
CVE-2025-6052 Glib: integer overflow in g_string_maybe_expand() leading to potential buffer overflow in glib gstring | CVSS3: 3.7 | 0% Низкий | 2 месяца назад | |
CVE-2025-6032 Podman: podman missing tls verification | 0% Низкий | 2 месяца назад |
Уязвимостей на страницу