CVE-2025-30722
- EPSS 0.06%
- Veröffentlicht 15.04.2025 20:31:15
- Zuletzt bearbeitet 03.11.2025 20:18:15
Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Difficult to exploit vulnerability allows low privileged attacker with net...
CVE-2025-31672
- EPSS 0.27%
- Veröffentlicht 09.04.2025 11:59:33
- Zuletzt bearbeitet 15.07.2025 19:08:21
Improper Input Validation vulnerability in Apache POI. The issue affects the parsing of OOXML format files like xlsx, docx and pptx. These file formats are basically zip files and it is possible for malicious users to add zip entries with duplicate n...
CVE-2025-24928
- EPSS 0.03%
- Veröffentlicht 18.02.2025 23:15:10
- Zuletzt bearbeitet 03.11.2025 22:18:40
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted DTD. NOTE: this is similar to CVE-2017-9047.
CVE-2024-56171
- EPSS 0.04%
- Veröffentlicht 18.02.2025 22:15:12
- Zuletzt bearbeitet 03.11.2025 21:17:50
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be validated against an XML schema with certain identity...
CVE-2025-26465
- EPSS 63.39%
- Veröffentlicht 18.02.2025 19:15:29
- Zuletzt bearbeitet 03.11.2025 22:18:41
A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in spec...
CVE-2025-1181
- EPSS 0.35%
- Veröffentlicht 11.02.2025 08:15:31
- Zuletzt bearbeitet 21.05.2025 20:35:11
A vulnerability classified as critical was found in GNU Binutils 2.43. This vulnerability affects the function _bfd_elf_gc_mark_rsec of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. The attack can be initiat...
CVE-2025-1178
- EPSS 0.3%
- Veröffentlicht 11.02.2025 07:15:29
- Zuletzt bearbeitet 21.05.2025 20:35:24
A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. Affected by this vulnerability is the function bfd_putl64 of the file libbfd.c of the component ld. The manipulation leads to memory corruption. The attack can be la...
CVE-2025-24970
- EPSS 0.35%
- Veröffentlicht 10.02.2025 22:15:38
- Zuletzt bearbeitet 05.09.2025 17:20:12
Netty, an asynchronous, event-driven network application framework, has a vulnerability starting in version 4.1.91.Final and prior to version 4.1.118.Final. When a special crafted packet is received via SslHandler it doesn't correctly handle validati...
- EPSS 32.63%
- Veröffentlicht 25.01.2025 05:15:09
- Zuletzt bearbeitet 27.10.2025 17:05:15
7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the targe...
CVE-2025-21502
- EPSS 0.08%
- Veröffentlicht 21.01.2025 21:15:15
- Zuletzt bearbeitet 18.06.2025 19:07:57
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u431-perf, 11.0.25, 17.0.13, 21.0.5, 23.0.1; Ora...