CVE-2025-3155
- EPSS 0.13%
- Veröffentlicht 03.04.2025 14:15:46
- Zuletzt bearbeitet 12.08.2025 21:15:30
A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.
CVE-2024-40635
- EPSS 0.01%
- Veröffentlicht 17.03.2025 21:32:37
- Zuletzt bearbeitet 02.10.2025 01:51:43
containerd is an open-source container runtime. A bug was found in containerd prior to versions 1.6.38, 1.7.27, and 2.0.4 where containers launched with a User set as a `UID:GID` larger than the maximum 32-bit signed integer can cause an overflow con...
CVE-2025-27363
- EPSS 67.14%
- Veröffentlicht 11.03.2025 13:28:31
- Zuletzt bearbeitet 07.05.2025 16:00:55
An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed...
CVE-2025-24813
- EPSS 94.18%
- Veröffentlicht 10.03.2025 16:44:03
- Zuletzt bearbeitet 08.08.2025 17:56:59
Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat. This issue affects Apache Tomcat: from 1...
CVE-2025-26699
- EPSS 0.42%
- Veröffentlicht 06.03.2025 19:15:27
- Zuletzt bearbeitet 03.10.2025 00:32:38
An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The django.utils.text.wrap() method and wordwrap template filter are subject to a potential denial-of-service attack when used with very long strings.
CVE-2025-27516
- EPSS 0.12%
- Veröffentlicht 05.03.2025 21:15:20
- Zuletzt bearbeitet 22.09.2025 18:49:36
Jinja is an extensible templating engine. Prior to 3.1.6, an oversight in how the Jinja sandboxed environment interacts with the |attr filter allows an attacker that controls the content of a template to execute arbitrary Python code. To exploit the ...
CVE-2025-26466
- EPSS 46.32%
- Veröffentlicht 28.02.2025 22:15:40
- Zuletzt bearbeitet 27.05.2025 16:15:31
A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a queue of packages. It is only freed when the server/client key exchange has finished. A malicious cli...
CVE-2024-55581
- EPSS 0.07%
- Veröffentlicht 26.02.2025 22:15:14
- Zuletzt bearbeitet 07.04.2025 18:39:22
When AdaCore Ada Web Server 25.0.0 is linked with GnuTLS, the default behaviour of AWS.Client is vulnerable to a man-in-the-middle attack because of lack of verification of an HTTPS server's certificate (unless the using program specifies a TLS confi...
CVE-2025-0838
- EPSS 0.17%
- Veröffentlicht 21.02.2025 15:15:11
- Zuletzt bearbeitet 30.07.2025 18:10:35
There exists a heap buffer overflow vulnerable in Abseil-cpp. The sized constructors, reserve(), and rehash() methods of absl::{flat,node}hash{set,map} did not impose an upper bound on their size argument. As a result, it was possible for a caller to...
CVE-2025-26465
- EPSS 58.35%
- Veröffentlicht 18.02.2025 19:15:29
- Zuletzt bearbeitet 26.09.2025 07:15:41
A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in spec...