CVE-2025-14512
- EPSS 0.59%
- Veröffentlicht 11.12.2025 07:16:00
- Zuletzt bearbeitet 07.10.2026 11:10:00
A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when processing malicious file or remote filesystem attribu...
CVE-2025-14087
- EPSS 0.84%
- Veröffentlicht 10.12.2025 09:01:34
- Zuletzt bearbeitet 02.10.2026 03:16:37
A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciously crafted i...
CVE-2025-62230
- EPSS 0.26%
- Veröffentlicht 30.10.2025 05:19:40
- Zuletzt bearbeitet 01.07.2026 15:13:56
A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can c...
CVE-2025-62231
- EPSS 0.28%
- Veröffentlicht 30.10.2025 05:15:39
- Zuletzt bearbeitet 01.07.2026 15:17:04
A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If an attacker sends specially crafted input data, the value calculation m...
CVE-2025-9784
- EPSS 2.33%
- Veröffentlicht 02.09.2025 13:37:59
- Zuletzt bearbeitet 06.10.2026 17:17:11
A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload b...
CVE-2025-31277
- EPSS 1.48%
- Veröffentlicht 29.07.2025 23:29:31
- Zuletzt bearbeitet 21.09.2026 17:17:25
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption.
CVE-2025-8283
- EPSS 0.29%
- Veröffentlicht 28.07.2025 18:16:07
- Zuletzt bearbeitet 01.09.2026 13:18:05
A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When creating a co...
CVE-2025-7519
- EPSS 0.18%
- Veröffentlicht 14.07.2025 13:35:21
- Zuletzt bearbeitet 01.09.2026 12:17:32
A flaw was found in polkit. When processing an XML policy with 32 or more nested elements in depth, an out-of-bounds write can be triggered. This issue can lead to a crash or other unexpected behavior, and arbitrary code execution is not discarded. T...
CVE-2025-7424
- EPSS 1.2%
- Veröffentlicht 10.07.2025 14:05:41
- Zuletzt bearbeitet 01.09.2026 12:17:31
A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which can lead to type confusion during XML transformations. This vulnerability allows an attacker to crash the application or corrupt m...
CVE-2025-32990
- EPSS 0.72%
- Veröffentlicht 10.07.2025 09:41:46
- Zuletzt bearbeitet 01.09.2026 12:17:19
A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL point...