CVE-2025-14542
- EPSS 0.05%
- Veröffentlicht 13.12.2025 09:59:41
- Zuletzt bearbeitet 15.12.2025 18:22:13
The vulnerability arises when a client fetches a tools’ JSON specification, known as a Manual, from a remote Manual Endpoint. While a provider may initially serve a benign manual (e.g., one defining an HTTP tool call), earning the clients’ trust, a m...
CVE-2025-55346
- EPSS 0.03%
- Veröffentlicht 14.08.2025 09:49:52
- Zuletzt bearbeitet 14.08.2025 16:15:41
User-controlled input flows to an unsafe implementation of a dynamic Function constructor, allowing network attackers to run arbitrary unsandboxed JS code in the context of the host, by sending a simple POST request.
CVE-2025-55345
- EPSS 0.27%
- Veröffentlicht 13.08.2025 08:55:14
- Zuletzt bearbeitet 13.08.2025 20:15:32
Using Codex CLI in workspace-write mode inside a malicious context (repo, directory, etc) could lead to arbitrary file overwrite and potentially remote code execution due to symlinks being followed outside the allowed current working directory.
CVE-2025-6514
- EPSS 1.05%
- Veröffentlicht 09.07.2025 12:41:44
- Zuletzt bearbeitet 10.07.2025 13:17:30
mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the authorization_endpoint response URL
CVE-2018-25110
- EPSS 0.27%
- Veröffentlicht 23.05.2025 14:53:43
- Zuletzt bearbeitet 13.08.2025 15:42:28
Marked prior to version 0.3.17 is vulnerable to a Regular Expression Denial of Service (ReDoS) attack due to catastrophic backtracking in several regular expressions used for parsing HTML tags and markdown links. An attacker can exploit this vulnerab...
CVE-2017-13091
- EPSS 0.1%
- Veröffentlicht 13.07.2018 20:29:02
- Zuletzt bearbeitet 21.11.2024 03:10:57
The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), as well as the management of access rights for such IP, including improperly specified padding in CBC mode allows use of an EDA tool as a de...
CVE-2017-13092
- EPSS 0.1%
- Veröffentlicht 13.07.2018 20:29:02
- Zuletzt bearbeitet 21.11.2024 03:10:57
The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), as well as the management of access rights for such IP, including improperly specified HDL syntax allows use of an EDA tool as a decryption ...
CVE-2017-13093
- EPSS 0.1%
- Veröffentlicht 13.07.2018 20:29:02
- Zuletzt bearbeitet 21.11.2024 03:10:57
The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), as well as the management of access rights for such IP, including modification of encrypted IP cyphertext to insert hardware trojans. The me...
CVE-2017-13094
- EPSS 0.04%
- Veröffentlicht 13.07.2018 20:29:02
- Zuletzt bearbeitet 21.11.2024 03:10:57
The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), as well as the management of access rights for such IP, including modification of the encryption key and insertion of hardware trojans in an...
CVE-2017-13095
- EPSS 0.1%
- Veröffentlicht 13.07.2018 20:29:02
- Zuletzt bearbeitet 21.11.2024 03:10:57
The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), as well as the management of access rights for such IP, including modification of a license-deny response to a license grant. The methods ar...