Логотип exploitDog
source:"msrc"
Консоль
Логотип exploitDog

exploitDog

source:"msrc"

Количество 19 519

Количество 19 519

msrc логотип

CVE-2025-6965

24 дня назад

Integer Truncation on SQLite

CVSS3: 9.8
EPSS: Низкий
msrc логотип

CVE-2025-69652

19 дней назад

GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate into DWARF attribute parsing routines. When certain malformed attributes result in an unexpected data length of zero, byte_get_little_endian() triggers a fatal abort. No evidence of memory corruption or code execution was observed; the impact is limited to denial of service.

EPSS: Низкий
msrc логотип

CVE-2025-69651

19 дней назад

GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service.

EPSS: Низкий
msrc логотип

CVE-2025-69650

19 дней назад

GNU Binutils thru 2.46 readelf contains a double free vulnerability when processing a crafted ELF binary with malformed relocation data. During GOT relocation handling, dump_relocations may return early without initializing the all_relocations array. As a result, process_got_section_contents() may pass an uninitialized r_symbol pointer to free(), leading to a double free and terminating the program with SIGABRT. No evidence of exploitable memory corruption or code execution was observed; the impact is limited to denial of service.

EPSS: Низкий
msrc логотип

CVE-2025-69649

19 дней назад

GNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a crafted ELF binary with malformed header fields. During relocation processing, an invalid or null section pointer may be passed into display_relocations(), resulting in a segmentation fault (SIGSEGV) and abrupt termination. No evidence of memory corruption beyond the null pointer dereference, nor any possibility of code execution, was observed.

EPSS: Низкий
msrc логотип

CVE-2025-69648

15 дней назад

EPSS: Низкий
msrc логотип

CVE-2025-69647

15 дней назад

EPSS: Низкий
msrc логотип

CVE-2025-69646

19 дней назад

Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis.

EPSS: Низкий
msrc логотип

CVE-2025-69645

19 дней назад

Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). The issue was observed in binutils 2.44. A local attacker can trigger the crash by supplying a malicious input file.

EPSS: Низкий
msrc логотип

CVE-2025-69644

19 дней назад

An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually interrupted. This issue affects versions prior to the upstream fix and allows a local attacker to cause excessive resource consumption by supplying a malicious input file.

EPSS: Низкий
msrc логотип

CVE-2025-69299

около 1 месяца назад

WordPress Oxygen theme <= 6.0.8 - Server Side Request Forgery (SSRF) vulnerability

EPSS: Низкий
msrc логотип

CVE-2025-69277

3 месяца назад

libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group.

CVSS3: 4.5
EPSS: Низкий
msrc логотип

CVE-2025-69195

3 месяца назад

Wget2: gnu wget2: memory corruption and crash via filename sanitization logic with attacker-controlled urls

CVSS3: 7.6
EPSS: Низкий
msrc логотип

CVE-2025-69194

3 месяца назад

Wget2: arbitrary file write via metalink path traversal in gnu wget2

CVSS3: 8.8
EPSS: Низкий
msrc логотип

CVE-2025-68973

3 месяца назад

In GnuPG through 2.4.8, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted input. (For ExtendedLTS, 2.2.51 and later are fixed versions.)

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2025-68972

3 месяца назад

In GnuPG through 2.4.8, if a signed message has \f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an "invalid armor" message is printed during verification). This is related to use of \f as a marker to denote truncation of a long plaintext line.

CVSS3: 5.9
EPSS: Низкий
msrc логотип

CVE-2025-68823

2 месяца назад

ublk: fix deadlock when reading partition table

EPSS: Низкий
msrc логотип

CVE-2025-68822

около 1 месяца назад

Input: alps - fix use-after-free bugs caused by dev3_register_work

EPSS: Низкий
msrc логотип

CVE-2025-68819

2 месяца назад

media: dvb-usb: dtv5100: fix out-of-bounds in dtv5100_i2c_msg()

CVSS3: 9.8
EPSS: Низкий
msrc логотип

CVE-2025-68818

2 месяца назад

scsi: Revert "scsi: qla2xxx: Perform lockless command completion in abort path"

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVE-2025-6965

Integer Truncation on SQLite

CVSS3: 9.8
0%
Низкий
24 дня назад
msrc логотип
CVE-2025-69652

GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate into DWARF attribute parsing routines. When certain malformed attributes result in an unexpected data length of zero, byte_get_little_endian() triggers a fatal abort. No evidence of memory corruption or code execution was observed; the impact is limited to denial of service.

0%
Низкий
19 дней назад
msrc логотип
CVE-2025-69651

GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service.

0%
Низкий
19 дней назад
msrc логотип
CVE-2025-69650

GNU Binutils thru 2.46 readelf contains a double free vulnerability when processing a crafted ELF binary with malformed relocation data. During GOT relocation handling, dump_relocations may return early without initializing the all_relocations array. As a result, process_got_section_contents() may pass an uninitialized r_symbol pointer to free(), leading to a double free and terminating the program with SIGABRT. No evidence of exploitable memory corruption or code execution was observed; the impact is limited to denial of service.

0%
Низкий
19 дней назад
msrc логотип
CVE-2025-69649

GNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a crafted ELF binary with malformed header fields. During relocation processing, an invalid or null section pointer may be passed into display_relocations(), resulting in a segmentation fault (SIGSEGV) and abrupt termination. No evidence of memory corruption beyond the null pointer dereference, nor any possibility of code execution, was observed.

0%
Низкий
19 дней назад
msrc логотип
0%
Низкий
15 дней назад
msrc логотип
0%
Низкий
15 дней назад
msrc логотип
CVE-2025-69646

Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis.

0%
Низкий
19 дней назад
msrc логотип
CVE-2025-69645

Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). The issue was observed in binutils 2.44. A local attacker can trigger the crash by supplying a malicious input file.

0%
Низкий
19 дней назад
msrc логотип
CVE-2025-69644

An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually interrupted. This issue affects versions prior to the upstream fix and allows a local attacker to cause excessive resource consumption by supplying a malicious input file.

0%
Низкий
19 дней назад
msrc логотип
CVE-2025-69299

WordPress Oxygen theme <= 6.0.8 - Server Side Request Forgery (SSRF) vulnerability

0%
Низкий
около 1 месяца назад
msrc логотип
CVE-2025-69277

libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group.

CVSS3: 4.5
0%
Низкий
3 месяца назад
msrc логотип
CVE-2025-69195

Wget2: gnu wget2: memory corruption and crash via filename sanitization logic with attacker-controlled urls

CVSS3: 7.6
0%
Низкий
3 месяца назад
msrc логотип
CVE-2025-69194

Wget2: arbitrary file write via metalink path traversal in gnu wget2

CVSS3: 8.8
0%
Низкий
3 месяца назад
msrc логотип
CVE-2025-68973

In GnuPG through 2.4.8, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted input. (For ExtendedLTS, 2.2.51 and later are fixed versions.)

CVSS3: 7.8
0%
Низкий
3 месяца назад
msrc логотип
CVE-2025-68972

In GnuPG through 2.4.8, if a signed message has \f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an "invalid armor" message is printed during verification). This is related to use of \f as a marker to denote truncation of a long plaintext line.

CVSS3: 5.9
0%
Низкий
3 месяца назад
msrc логотип
CVE-2025-68823

ublk: fix deadlock when reading partition table

0%
Низкий
2 месяца назад
msrc логотип
CVE-2025-68822

Input: alps - fix use-after-free bugs caused by dev3_register_work

0%
Низкий
около 1 месяца назад
msrc логотип
CVE-2025-68819

media: dvb-usb: dtv5100: fix out-of-bounds in dtv5100_i2c_msg()

CVSS3: 9.8
0%
Низкий
2 месяца назад
msrc логотип
CVE-2025-68818

scsi: Revert "scsi: qla2xxx: Perform lockless command completion in abort path"

CVSS3: 5.5
0%
Низкий
2 месяца назад

Уязвимостей на страницу