CVE-2025-1861
- EPSS 0.16%
- Veröffentlicht 30.03.2025 06:15:14
- Zuletzt bearbeitet 03.11.2025 21:18:53
In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when parsing HTTP redirect in the response to an HTTP request, there is currently limit on the location value size caused by limited size of...
CVE-2025-1736
- EPSS 0.17%
- Veröffentlicht 30.03.2025 06:15:14
- Zuletzt bearbeitet 03.11.2025 21:18:52
In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when user-supplied headers are sent, the insufficient validation of the end-of-line characters may prevent certain headers from being sent o...
CVE-2025-1734
- EPSS 0.09%
- Veröffentlicht 30.03.2025 06:15:14
- Zuletzt bearbeitet 03.11.2025 21:18:52
In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when receiving headers from HTTP server, the headers missing a colon (:) are treated as valid headers even though they are not. This may con...
CVE-2025-24928
- EPSS 0.03%
- Veröffentlicht 18.02.2025 23:15:10
- Zuletzt bearbeitet 03.11.2025 22:18:40
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted DTD. NOTE: this is similar to CVE-2017-9047.
CVE-2024-56171
- EPSS 0.04%
- Veröffentlicht 18.02.2025 22:15:12
- Zuletzt bearbeitet 03.11.2025 21:17:50
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be validated against an XML schema with certain identity...
CVE-2025-26465
- EPSS 63.39%
- Veröffentlicht 18.02.2025 19:15:29
- Zuletzt bearbeitet 03.11.2025 22:18:41
A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in spec...
CVE-2025-0167
- EPSS 0.16%
- Veröffentlicht 05.02.2025 10:15:22
- Zuletzt bearbeitet 30.07.2025 19:41:45
When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has a `de...
CVE-2024-11053
- EPSS 0.34%
- Veröffentlicht 11.12.2024 08:15:05
- Zuletzt bearbeitet 03.11.2025 21:16:04
When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an e...
CVE-2024-8932
- EPSS 0.75%
- Veröffentlicht 22.11.2024 06:15:20
- Zuletzt bearbeitet 03.11.2025 23:17:33
In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.
CVE-2024-39573
- EPSS 2.59%
- Veröffentlicht 01.07.2024 19:15:05
- Zuletzt bearbeitet 03.11.2025 22:17:06
Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to be handled by mod_proxy. Users are recommended to upgrade to version 2.4.60, which fixes this issue.