CVE-2025-30691
- EPSS 0.04%
- Veröffentlicht 15.04.2025 20:31:03
- Zuletzt bearbeitet 23.06.2025 17:54:13
Vulnerability in Oracle Java SE (component: Compiler). Supported versions that are affected are Oracle Java SE: 21.0.6, 24; Oracle GraalVM for JDK: 21.0.6 and 24. Difficult to exploit vulnerability allows unauthenticated attacker with network acces...
CVE-2025-29768
- EPSS 0.1%
- Veröffentlicht 13.03.2025 17:15:37
- Zuletzt bearbeitet 18.08.2025 14:14:27
Vim, a text editor, is vulnerable to potential data loss with zip.vim and special crafted zip files in versions prior to 9.1.1198. The impact is medium because a user must be made to view such an archive with Vim and then press 'x' on such a strange ...
CVE-2025-24813
- EPSS 94.18%
- Veröffentlicht 10.03.2025 16:44:03
- Zuletzt bearbeitet 08.08.2025 17:56:59
Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat. This issue affects Apache Tomcat: from 1...
CVE-2025-1215
- EPSS 0.13%
- Veröffentlicht 12.02.2025 19:15:10
- Zuletzt bearbeitet 13.08.2025 17:28:19
A vulnerability classified as problematic was found in vim up to 9.1.1096. This vulnerability affects unknown code of the file src/main.c. The manipulation of the argument --log leads to memory corruption. It is possible to launch the attack on the l...
CVE-2025-0665
- EPSS 5.13%
- Veröffentlicht 05.02.2025 10:15:22
- Zuletzt bearbeitet 30.07.2025 19:41:22
libcurl would wrongly close the same eventfd file descriptor twice when taking down a connection channel after having completed a threaded name resolve.
CVE-2025-0167
- EPSS 0.08%
- Veröffentlicht 05.02.2025 10:15:22
- Zuletzt bearbeitet 30.07.2025 19:41:45
When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has a `de...
CVE-2025-21502
- EPSS 0.04%
- Veröffentlicht 21.01.2025 21:15:15
- Zuletzt bearbeitet 18.06.2025 19:07:57
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u431-perf, 11.0.25, 17.0.13, 21.0.5, 23.0.1; Ora...
CVE-2025-22134
- EPSS 0.02%
- Veröffentlicht 13.01.2025 21:15:14
- Zuletzt bearbeitet 14.08.2025 17:43:55
When switching to other buffers using the :all command and visual mode still being active, this may cause a heap-buffer overflow, because Vim does not properly end visual mode and therefore may try to access beyond the end of a line in a buffer. In P...
CVE-2024-56337
- EPSS 28.59%
- Veröffentlicht 20.12.2024 16:15:24
- Zuletzt bearbeitet 08.08.2025 12:15:27
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97. The following versions were EOL at the t...
CVE-2024-54677
- EPSS 7.24%
- Veröffentlicht 17.12.2024 13:15:18
- Zuletzt bearbeitet 08.08.2025 12:15:27
Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 th...