Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 26 091

Количество 26 091

msrc логотип

CVE-2025-7519

около 1 года назад

Polkit: xml policy file with a large number of nested elements may lead to out-of-bounds write

CVSS3: 6.7
EPSS: Низкий
msrc логотип

CVE-2025-7458

около 1 года назад

SQLite integer overflow in key info allocation may lead to information disclosure.

CVSS3: 9.1
EPSS: Низкий
msrc логотип

CVE-2025-7425

12 месяцев назад

Libxslt: heap use-after-free in libxslt caused by atype corruption in xmlattrptr

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2025-7424

12 месяцев назад

Libxslt: type confusion in xmlnode.psvi between stylesheet and source nodes

CVSS3: 7.3
EPSS: Низкий
msrc логотип

CVE-2025-7395

11 месяцев назад

Domain Name Validation Bypass with Apple Native Certificate Validation

EPSS: Низкий
msrc логотип

CVE-2025-7394

12 месяцев назад

In the OpenSSL compatibility layer implementation, the function RAND_poll() was not behaving as expected and leading to the potential for predictable values returned from RAND_bytes() after fork() is called. This can lead to weak or predictable random numbers generated in applications that are both using RAND_bytes() and doing fork() operations. This only affects applications explicitly calling RAND_bytes() after fork() and does not affect any internal TLS operations. Although RAND_bytes() documentation in OpenSSL calls out not being safe for use with fork() without first calling RAND_poll(), an additional code change was also made in wolfSSL to make RAND_bytes() behave similar to OpenSSL after a fork() call without calling RAND_poll(). Now the Hash-DRBG used gets reseeded after detecting running in a new process. If making use of RAND_bytes() and calling fork() we recommend updating to the latest version of wolfSSL. Thanks to Per Allansson from Appgate for the report.

EPSS: Низкий
msrc логотип

CVE-2025-7345

около 1 года назад

Gdk‑pixbuf: heap‑buffer‑overflow in gdk‑pixbuf

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2025-7339

11 месяцев назад

on-headers vulnerable to http response header manipulation

EPSS: Низкий
msrc логотип

CVE-2025-7207

12 месяцев назад

mruby nregs codegen.c scope_new heap-based overflow

EPSS: Низкий
msrc логотип

CVE-2025-71315

около 1 месяца назад

drm/vkms: Convert to DRM's vblank timer

EPSS: Низкий
msrc логотип

CVE-2025-71313

2 дня назад

PCI: endpoint: Add missing NULL check for alloc_workqueue()

EPSS: Низкий
msrc логотип

CVE-2025-71305

3 месяца назад

drm/display/dp_mst: Add protection against 0 vcpi

EPSS: Низкий
msrc логотип

CVE-2025-71302

3 месяца назад

drm/panthor: fix for dma-fence safe access rules

EPSS: Низкий
msrc логотип

CVE-2025-71299

3 месяца назад

spi: cadence-quadspi: Parse DT for flashes with the rest of the DT parsing

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2025-71294

3 месяца назад

drm/amdgpu: fix NULL pointer issue buffer funcs

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2025-71293

3 месяца назад

drm/amdgpu/ras: Move ras data alloc before bad page check

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2025-71290

3 месяца назад

misc: ti_fpc202: fix a potential memory leak in probe function

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2025-71289

3 месяца назад

fs/ntfs3: handle attr_set_size() errors when truncating files

EPSS: Низкий
msrc логотип

CVE-2025-71285

3 месяца назад

net: qrtr: Drop the MHI auto_queue feature for IPCR DL channels

EPSS: Низкий
msrc логотип

CVE-2025-71273

3 месяца назад

wifi: rtw88: Use devm_kmemdup() in rtw_set_supported_band()

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVE-2025-7519

Polkit: xml policy file with a large number of nested elements may lead to out-of-bounds write

CVSS3: 6.7
0%
Низкий
около 1 года назад
msrc логотип
CVE-2025-7458

SQLite integer overflow in key info allocation may lead to information disclosure.

CVSS3: 9.1
0%
Низкий
около 1 года назад
msrc логотип
CVE-2025-7425

Libxslt: heap use-after-free in libxslt caused by atype corruption in xmlattrptr

CVSS3: 7.8
0%
Низкий
12 месяцев назад
msrc логотип
CVE-2025-7424

Libxslt: type confusion in xmlnode.psvi between stylesheet and source nodes

CVSS3: 7.3
1%
Низкий
12 месяцев назад
msrc логотип
CVE-2025-7395

Domain Name Validation Bypass with Apple Native Certificate Validation

0%
Низкий
11 месяцев назад
msrc логотип
CVE-2025-7394

In the OpenSSL compatibility layer implementation, the function RAND_poll() was not behaving as expected and leading to the potential for predictable values returned from RAND_bytes() after fork() is called. This can lead to weak or predictable random numbers generated in applications that are both using RAND_bytes() and doing fork() operations. This only affects applications explicitly calling RAND_bytes() after fork() and does not affect any internal TLS operations. Although RAND_bytes() documentation in OpenSSL calls out not being safe for use with fork() without first calling RAND_poll(), an additional code change was also made in wolfSSL to make RAND_bytes() behave similar to OpenSSL after a fork() call without calling RAND_poll(). Now the Hash-DRBG used gets reseeded after detecting running in a new process. If making use of RAND_bytes() and calling fork() we recommend updating to the latest version of wolfSSL. Thanks to Per Allansson from Appgate for the report.

0%
Низкий
12 месяцев назад
msrc логотип
CVE-2025-7345

Gdk‑pixbuf: heap‑buffer‑overflow in gdk‑pixbuf

CVSS3: 7.5
1%
Низкий
около 1 года назад
msrc логотип
CVE-2025-7339

on-headers vulnerable to http response header manipulation

0%
Низкий
11 месяцев назад
msrc логотип
CVE-2025-7207

mruby nregs codegen.c scope_new heap-based overflow

0%
Низкий
12 месяцев назад
msrc логотип
CVE-2025-71315

drm/vkms: Convert to DRM's vblank timer

0%
Низкий
около 1 месяца назад
msrc логотип
CVE-2025-71313

PCI: endpoint: Add missing NULL check for alloc_workqueue()

0%
Низкий
2 дня назад
msrc логотип
CVE-2025-71305

drm/display/dp_mst: Add protection against 0 vcpi

0%
Низкий
3 месяца назад
msrc логотип
CVE-2025-71302

drm/panthor: fix for dma-fence safe access rules

0%
Низкий
3 месяца назад
msrc логотип
CVE-2025-71299

spi: cadence-quadspi: Parse DT for flashes with the rest of the DT parsing

CVSS3: 5.5
0%
Низкий
3 месяца назад
msrc логотип
CVE-2025-71294

drm/amdgpu: fix NULL pointer issue buffer funcs

CVSS3: 5.5
0%
Низкий
3 месяца назад
msrc логотип
CVE-2025-71293

drm/amdgpu/ras: Move ras data alloc before bad page check

CVSS3: 5.5
0%
Низкий
3 месяца назад
msrc логотип
CVE-2025-71290

misc: ti_fpc202: fix a potential memory leak in probe function

CVSS3: 5.5
0%
Низкий
3 месяца назад
msrc логотип
CVE-2025-71289

fs/ntfs3: handle attr_set_size() errors when truncating files

0%
Низкий
3 месяца назад
msrc логотип
CVE-2025-71285

net: qrtr: Drop the MHI auto_queue feature for IPCR DL channels

0%
Низкий
3 месяца назад
msrc логотип
CVE-2025-71273

wifi: rtw88: Use devm_kmemdup() in rtw_set_supported_band()

0%
Низкий
3 месяца назад

Уязвимостей на страницу