Количество 26 125
Количество 26 125
CVE-2025-24983
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
CVE-2025-24928
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted DTD. NOTE: this is similar to CVE-2017-9047.
CVE-2025-24912
hostapd fails to process crafted RADIUS packets properly. When hostapd authenticates wi-fi devices with RADIUS authentication, an attacker in the position between the hostapd and the RADIUS server may inject crafted RADIUS packets and force RADIUS authentications to fail.
CVE-2025-24898
rust openssl ssl::select_next_proto use after free
CVE-2025-2486
UEFI Shell accessible in AAVMF with Secure Boot enabled on Ubuntu
CVE-2025-24855
numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is related to xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs, and xsltComputeSortResultInternal.
CVE-2025-2476
Chromium: CVE-2025-2476 Use after free in Lens
CVE-2025-24528
In MIT Kerberos 5 (aka krb5) before 1.22 (with incremental propagation), there is an integer overflow for a large update size to resize() in kdb_log.c. An authenticated attacker can cause an out-of-bounds write and kadmind daemon crash.
CVE-2025-24514
Kubernetes: Vulnerability in Kubernetes NGINX Ingress Controller
CVE-2025-24513
Kubernetes: Vulnerability in Kubernetes NGINX Ingress Controller
CVE-2025-24294
The attack vector is a potential Denial of Service (DoS). The vulnerability is caused by an insufficient check on the length of a decompressed domain name within a DNS packet. An attacker can craft a malicious DNS packet containing a highly compressed domain name. When the resolv library parses such a packet, the name decompression process consumes a large amount of CPU resources, as the library does not limit the resulting length of the name. This resource consumption can cause the application thread to become unresponsive, resulting in a Denial of Service condition.
CVE-2025-24201
Chromium: CVE-2025-24201 Out of bounds write in GPU on Mac
CVE-2025-24084
Windows Subsystem for Linux (WSL2) Kernel Remote Code Execution Vulnerability
CVE-2025-24083
Microsoft Office Remote Code Execution Vulnerability
CVE-2025-24082
Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-24081
Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-24080
Microsoft Office Remote Code Execution Vulnerability
CVE-2025-24079
Microsoft Word Remote Code Execution Vulnerability
CVE-2025-24078
Microsoft Word Remote Code Execution Vulnerability
CVE-2025-24077
Microsoft Word Remote Code Execution Vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2025-24983 Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | CVSS3: 7 | 1% Низкий | больше 1 года назад | |
CVE-2025-24928 libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted DTD. NOTE: this is similar to CVE-2017-9047. | CVSS3: 7.8 | 0% Низкий | больше 1 года назад | |
CVE-2025-24912 hostapd fails to process crafted RADIUS packets properly. When hostapd authenticates wi-fi devices with RADIUS authentication, an attacker in the position between the hostapd and the RADIUS server may inject crafted RADIUS packets and force RADIUS authentications to fail. | CVSS3: 3.7 | 1% Низкий | больше 1 года назад | |
CVE-2025-24898 rust openssl ssl::select_next_proto use after free | 1% Низкий | 6 месяцев назад | ||
CVE-2025-2486 UEFI Shell accessible in AAVMF with Secure Boot enabled on Ubuntu | 0% Низкий | 9 месяцев назад | ||
CVE-2025-24855 numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is related to xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs, and xsltComputeSortResultInternal. | CVSS3: 7.8 | 0% Низкий | больше 1 года назад | |
CVE-2025-2476 Chromium: CVE-2025-2476 Use after free in Lens | 1% Низкий | больше 1 года назад | ||
CVE-2025-24528 In MIT Kerberos 5 (aka krb5) before 1.22 (with incremental propagation), there is an integer overflow for a large update size to resize() in kdb_log.c. An authenticated attacker can cause an out-of-bounds write and kadmind daemon crash. | CVSS3: 7.1 | 1% Низкий | 7 месяцев назад | |
CVE-2025-24514 Kubernetes: Vulnerability in Kubernetes NGINX Ingress Controller | 32% Средний | больше 1 года назад | ||
CVE-2025-24513 Kubernetes: Vulnerability in Kubernetes NGINX Ingress Controller | 4% Низкий | больше 1 года назад | ||
CVE-2025-24294 The attack vector is a potential Denial of Service (DoS). The vulnerability is caused by an insufficient check on the length of a decompressed domain name within a DNS packet. An attacker can craft a malicious DNS packet containing a highly compressed domain name. When the resolv library parses such a packet, the name decompression process consumes a large amount of CPU resources, as the library does not limit the resulting length of the name. This resource consumption can cause the application thread to become unresponsive, resulting in a Denial of Service condition. | CVSS3: 7.5 | 1% Низкий | 6 месяцев назад | |
CVE-2025-24201 Chromium: CVE-2025-24201 Out of bounds write in GPU on Mac | 4% Низкий | больше 1 года назад | ||
CVE-2025-24084 Windows Subsystem for Linux (WSL2) Kernel Remote Code Execution Vulnerability | CVSS3: 8.4 | 1% Низкий | больше 1 года назад | |
CVE-2025-24083 Microsoft Office Remote Code Execution Vulnerability | CVSS3: 7.8 | 1% Низкий | больше 1 года назад | |
CVE-2025-24082 Microsoft Excel Remote Code Execution Vulnerability | CVSS3: 7.8 | 1% Низкий | больше 1 года назад | |
CVE-2025-24081 Microsoft Excel Remote Code Execution Vulnerability | CVSS3: 7.8 | 1% Низкий | больше 1 года назад | |
CVE-2025-24080 Microsoft Office Remote Code Execution Vulnerability | CVSS3: 7.8 | 1% Низкий | больше 1 года назад | |
CVE-2025-24079 Microsoft Word Remote Code Execution Vulnerability | CVSS3: 7.8 | 1% Низкий | больше 1 года назад | |
CVE-2025-24078 Microsoft Word Remote Code Execution Vulnerability | CVSS3: 7 | 1% Низкий | больше 1 года назад | |
CVE-2025-24077 Microsoft Word Remote Code Execution Vulnerability | CVSS3: 7.8 | 1% Низкий | больше 1 года назад |
Уязвимостей на страницу