CVE-2025-38000
- EPSS 0.03%
- Veröffentlicht 06.06.2025 13:15:39
- Zuletzt bearbeitet 16.12.2025 20:21:40
In the Linux kernel, the following vulnerability has been resolved: sch_hfsc: Fix qlen accounting bug when using peek in hfsc_enqueue() When enqueuing the first packet to an HFSC class, hfsc_enqueue() calls the child qdisc's peek() operation before...
CVE-2025-48432
- EPSS 0.15%
- Veröffentlicht 05.06.2025 00:00:00
- Zuletzt bearbeitet 15.10.2025 17:47:56
An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may l...
CVE-2024-52035
- EPSS 0.06%
- Veröffentlicht 02.06.2025 15:00:17
- Zuletzt bearbeitet 18.02.2026 14:42:16
An integer overflow vulnerability exists in the OLE Document File Allocation Table Parser functionality of catdoc 0.95. A specially crafted malformed file can lead to heap-based memory corruption. An attacker can provide a malicious file to trigger t...
CVE-2024-54028
- EPSS 0.06%
- Veröffentlicht 02.06.2025 15:00:15
- Zuletzt bearbeitet 18.02.2026 14:42:32
An integer underflow vulnerability exists in the OLE Document DIFAT Parser functionality of catdoc 0.95. A specially crafted malformed file can lead to heap-based memory corruption. An attacker can provide a malicious file to trigger this vulnerabili...
CVE-2025-49113
- EPSS 90.36%
- Veröffentlicht 02.06.2025 00:00:00
- Zuletzt bearbeitet 23.02.2026 13:24:21
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.
CVE-2025-4598
- EPSS 0.04%
- Veröffentlicht 30.05.2025 13:13:26
- Zuletzt bearbeitet 02.02.2026 10:16:05
A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, suc...
CVE-2025-37998
- EPSS 0.04%
- Veröffentlicht 29.05.2025 13:15:56
- Zuletzt bearbeitet 16.12.2025 20:21:07
In the Linux kernel, the following vulnerability has been resolved: openvswitch: Fix unsafe attribute parsing in output_userspace() This patch replaces the manual Netlink attribute iteration in output_userspace() with nla_for_each_nested(), which e...
CVE-2025-37997
- EPSS 0.03%
- Veröffentlicht 29.05.2025 13:15:55
- Zuletzt bearbeitet 16.12.2025 20:20:41
In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: fix region locking in hash types Region locking introduced in v5.6-rc4 contained three macros to handle the region locks: ahash_bucket_start(), ahash_bucket_end()...
CVE-2025-37995
- EPSS 0.04%
- Veröffentlicht 29.05.2025 13:15:54
- Zuletzt bearbeitet 16.12.2025 20:20:35
In the Linux kernel, the following vulnerability has been resolved: module: ensure that kobject_put() is safe for module type kobjects In 'lookup_or_create_module_kobject()', an internal kobject is created using 'module_ktype'. So call to 'kobject_...
CVE-2025-37994
- EPSS 0.04%
- Veröffentlicht 29.05.2025 13:15:53
- Zuletzt bearbeitet 16.12.2025 20:19:55
In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: displayport: Fix NULL pointer access This patch ensures that the UCSI driver waits for all pending tasks in the ucsi_displayport_work workqueue to finish executin...