Логотип exploitDog
source:"redhat"
Консоль
Логотип exploitDog

exploitDog

source:"redhat"

Количество 41 119

Количество 41 119

redhat логотип

CVE-2025-5962

6 месяцев назад

A flaw was found in the Lightspeed history service. Insufficient access controls allow a local, unprivileged user to access and manipulate the chat history of another user on the same system. By abusing inter-process communication calls to the history service, an attacker can view, delete, or inject arbitrary history entries, including misleading or malicious commands. This can be used to deceive another user into executing harmful actions, posing a risk of privilege misuse or unauthorized command execution through social engineering.

CVSS3: 7.7
EPSS: Низкий
redhat логотип

CVE-2025-59589

3 месяца назад

No description is available for this CVE.

EPSS: Низкий
redhat логотип

CVE-2025-59588

3 месяца назад

No description is available for this CVE.

EPSS: Низкий
redhat логотип

CVE-2025-59528

3 месяца назад

No description is available for this CVE.

EPSS: Высокий
redhat логотип

CVE-2025-59526

3 месяца назад

No description is available for this CVE.

EPSS: Низкий
redhat логотип

CVE-2025-59518

3 месяца назад

In LemonLDAP::NG before 2.16.7 and 2.17 through 2.21 before 2.21.3, OS command injection can occur in the Safe jail. It does not Localize _ during rule evaluation. Thus, an administrator who can edit a rule evaluated by the Safe jail can execute commands on the server.

CVSS3: 8
EPSS: Низкий
redhat логотип

CVE-2025-59476

3 месяца назад

Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not restrict or transform the characters that can be inserted from user-specified content in log messages, allowing attackers able to control log message contents to insert line break characters, followed by forged log messages that may mislead administrators reviewing log output.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2025-59475

3 месяца назад

Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check for the authenticated user profile dropdown menu, allowing attackers without Overall/Read permission to obtain limited information about the Jenkins configuration by listing available options in this menu (e.g., whether Credentials Plugin is installed).

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2025-59474

3 месяца назад

Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check in the sidepanel of a page intentionally accessible to users lacking Overall/Read permission, allowing attackers without Overall/Read permission to list agent names through its sidepanel executors widget.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2025-59436

3 месяца назад

The ip (aka node-ip) package through 2.0.1 (in NPM) might allow SSRF because the IP address value 017700000001 is improperly categorized as globally routable via isPublic. NOTE: this issue exists because of an incomplete fix for CVE-2024-29415.

CVSS3: 3.2
EPSS: Низкий
redhat логотип

CVE-2025-59434

3 месяца назад

No description is available for this CVE.

EPSS: Низкий
redhat логотип

CVE-2025-59432

3 месяца назад

No description is available for this CVE.

CVSS3: 6.8
EPSS: Низкий
redhat логотип

CVE-2025-59420

3 месяца назад

No description is available for this CVE.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2025-59418

3 месяца назад

No description is available for this CVE.

EPSS: Низкий
redhat логотип

CVE-2025-59375

3 месяца назад

libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2025-59331

3 месяца назад

is-arrayish checks if an object can be used like an Array. On 8 September 2025, an npm publishing account for is-arrayish was taken over after a phishing attack. Version 0.3.3 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency transactions to the attacker's own addresses from within browser environments. Local environments, server environments, command line applications, etc. are not affected. If the package was used in a browser context (e.g. a direct <script> inclusion, or via a bundling tool such as Babel, Rollup, Vite, Next.js, etc.) there is a chance the malware still exists and such bundles will need to be rebuilt. The malware seemingly only targets cryptocurrency transactions and wallets such as MetaMask. See references below for more information on the payload. npm removed the offending package from the registry over the course of the day on 8 September, preventing further downloads from...

EPSS: Низкий
redhat логотип

CVE-2025-59330

3 месяца назад

error-ex allows error subclassing and stack customization. On 8 September 2025, an npm publishing account for error-ex was taken over after a phishing attack. Version 1.3.3 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency transactions to the attacker's own addresses from within browser environments. Local environments, server environments, command line applications, etc. are not affected. If the package was used in a browser context (e.g. a direct <script> inclusion, or via a bundling tool such as Babel, Rollup, Vite, Next.js, etc.) there is a chance the malware still exists and such bundles will need to be rebuilt. The malware seemingly only targets cryptocurrency transactions and wallets such as MetaMask. npm removed the offending package from the registry over the course of the day on 8 September, preventing further downloads from npm proper. On 13 September, the package owner published new...

EPSS: Низкий
redhat логотип

CVE-2025-5918

7 месяцев назад

A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition.

CVSS3: 3.9
EPSS: Низкий
redhat логотип

CVE-2025-5917

7 месяцев назад

A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes for file names. This can lead to a 1-byte write overflow. While seemingly small, such an overflow can corrupt adjacent memory, leading to unpredictable program behavior, crashes, or in specific circumstances, could be leveraged as a building block for more sophisticated exploitation.

CVSS3: 2.8
EPSS: Низкий
redhat логотип

CVE-2025-5916

7 месяцев назад

A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content bytes. An attacker could craft a malicious WARC archive to induce this overflow, potentially leading to unpredictable program behavior, memory corruption, or a denial-of-service condition within applications that process such archives using libarchive.

CVSS3: 3.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2025-5962

A flaw was found in the Lightspeed history service. Insufficient access controls allow a local, unprivileged user to access and manipulate the chat history of another user on the same system. By abusing inter-process communication calls to the history service, an attacker can view, delete, or inject arbitrary history entries, including misleading or malicious commands. This can be used to deceive another user into executing harmful actions, posing a risk of privilege misuse or unauthorized command execution through social engineering.

CVSS3: 7.7
0%
Низкий
6 месяцев назад
redhat логотип
CVE-2025-59589

No description is available for this CVE.

0%
Низкий
3 месяца назад
redhat логотип
CVE-2025-59588

No description is available for this CVE.

0%
Низкий
3 месяца назад
redhat логотип
CVE-2025-59528

No description is available for this CVE.

79%
Высокий
3 месяца назад
redhat логотип
CVE-2025-59526

No description is available for this CVE.

0%
Низкий
3 месяца назад
redhat логотип
CVE-2025-59518

In LemonLDAP::NG before 2.16.7 and 2.17 through 2.21 before 2.21.3, OS command injection can occur in the Safe jail. It does not Localize _ during rule evaluation. Thus, an administrator who can edit a rule evaluated by the Safe jail can execute commands on the server.

CVSS3: 8
0%
Низкий
3 месяца назад
redhat логотип
CVE-2025-59476

Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not restrict or transform the characters that can be inserted from user-specified content in log messages, allowing attackers able to control log message contents to insert line break characters, followed by forged log messages that may mislead administrators reviewing log output.

CVSS3: 5.3
0%
Низкий
3 месяца назад
redhat логотип
CVE-2025-59475

Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check for the authenticated user profile dropdown menu, allowing attackers without Overall/Read permission to obtain limited information about the Jenkins configuration by listing available options in this menu (e.g., whether Credentials Plugin is installed).

CVSS3: 4.3
0%
Низкий
3 месяца назад
redhat логотип
CVE-2025-59474

Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check in the sidepanel of a page intentionally accessible to users lacking Overall/Read permission, allowing attackers without Overall/Read permission to list agent names through its sidepanel executors widget.

CVSS3: 5.3
0%
Низкий
3 месяца назад
redhat логотип
CVE-2025-59436

The ip (aka node-ip) package through 2.0.1 (in NPM) might allow SSRF because the IP address value 017700000001 is improperly categorized as globally routable via isPublic. NOTE: this issue exists because of an incomplete fix for CVE-2024-29415.

CVSS3: 3.2
0%
Низкий
3 месяца назад
redhat логотип
CVE-2025-59434

No description is available for this CVE.

0%
Низкий
3 месяца назад
redhat логотип
CVE-2025-59432

No description is available for this CVE.

CVSS3: 6.8
0%
Низкий
3 месяца назад
redhat логотип
CVE-2025-59420

No description is available for this CVE.

CVSS3: 7.5
0%
Низкий
3 месяца назад
redhat логотип
CVE-2025-59418

No description is available for this CVE.

0%
Низкий
3 месяца назад
redhat логотип
CVE-2025-59375

libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.

CVSS3: 7.5
0%
Низкий
3 месяца назад
redhat логотип
CVE-2025-59331

is-arrayish checks if an object can be used like an Array. On 8 September 2025, an npm publishing account for is-arrayish was taken over after a phishing attack. Version 0.3.3 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency transactions to the attacker's own addresses from within browser environments. Local environments, server environments, command line applications, etc. are not affected. If the package was used in a browser context (e.g. a direct <script> inclusion, or via a bundling tool such as Babel, Rollup, Vite, Next.js, etc.) there is a chance the malware still exists and such bundles will need to be rebuilt. The malware seemingly only targets cryptocurrency transactions and wallets such as MetaMask. See references below for more information on the payload. npm removed the offending package from the registry over the course of the day on 8 September, preventing further downloads from...

0%
Низкий
3 месяца назад
redhat логотип
CVE-2025-59330

error-ex allows error subclassing and stack customization. On 8 September 2025, an npm publishing account for error-ex was taken over after a phishing attack. Version 1.3.3 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency transactions to the attacker's own addresses from within browser environments. Local environments, server environments, command line applications, etc. are not affected. If the package was used in a browser context (e.g. a direct <script> inclusion, or via a bundling tool such as Babel, Rollup, Vite, Next.js, etc.) there is a chance the malware still exists and such bundles will need to be rebuilt. The malware seemingly only targets cryptocurrency transactions and wallets such as MetaMask. npm removed the offending package from the registry over the course of the day on 8 September, preventing further downloads from npm proper. On 13 September, the package owner published new...

0%
Низкий
3 месяца назад
redhat логотип
CVE-2025-5918

A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition.

CVSS3: 3.9
0%
Низкий
7 месяцев назад
redhat логотип
CVE-2025-5917

A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes for file names. This can lead to a 1-byte write overflow. While seemingly small, such an overflow can corrupt adjacent memory, leading to unpredictable program behavior, crashes, or in specific circumstances, could be leveraged as a building block for more sophisticated exploitation.

CVSS3: 2.8
0%
Низкий
7 месяцев назад
redhat логотип
CVE-2025-5916

A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content bytes. An attacker could craft a malicious WARC archive to induce this overflow, potentially leading to unpredictable program behavior, memory corruption, or a denial-of-service condition within applications that process such archives using libarchive.

CVSS3: 3.9
0%
Низкий
7 месяцев назад

Уязвимостей на страницу