CVE-2024-55581
- EPSS 0.24%
- Veröffentlicht 26.02.2025 22:15:14
- Zuletzt bearbeitet 07.04.2025 18:39:22
When AdaCore Ada Web Server 25.0.0 is linked with GnuTLS, the default behaviour of AWS.Client is vulnerable to a man-in-the-middle attack because of lack of verification of an HTTPS server's certificate (unless the using program specifies a TLS confi...
CVE-2022-49063
- EPSS 0.02%
- Veröffentlicht 26.02.2025 07:00:43
- Zuletzt bearbeitet 18.11.2025 15:08:43
In the Linux kernel, the following vulnerability has been resolved: ice: arfs: fix use-after-free when freeing @rx_cpu_rmap The CI testing bots triggered the following splat: [ 718.203054] BUG: KASAN: use-after-free in free_irq_cpu_rmap+0x53/0x80...
CVE-2025-0838
- EPSS 0.13%
- Veröffentlicht 21.02.2025 15:15:11
- Zuletzt bearbeitet 30.07.2025 18:10:35
There exists a heap buffer overflow vulnerable in Abseil-cpp. The sized constructors, reserve(), and rehash() methods of absl::{flat,node}hash{set,map} did not impose an upper bound on their size argument. As a result, it was possible for a caller to...
CVE-2025-25472
- EPSS 0.22%
- Veröffentlicht 18.02.2025 23:15:10
- Zuletzt bearbeitet 04.11.2025 20:31:41
A buffer overflow in DCMTK git master v3.6.9+ DEV allows attackers to cause a Denial of Service (DoS) via a crafted DCM file.
CVE-2025-25474
- EPSS 0.21%
- Veröffentlicht 18.02.2025 23:15:10
- Zuletzt bearbeitet 04.11.2025 20:33:27
DCMTK v3.6.9+ DEV was discovered to contain a buffer overflow via the component /dcmimgle/diinpxt.h.
CVE-2025-25475
- EPSS 0.2%
- Veröffentlicht 18.02.2025 23:15:10
- Zuletzt bearbeitet 04.11.2025 20:40:26
A NULL pointer dereference in the component /libsrc/dcrleccd.cc of DCMTK v3.6.9+ DEV allows attackers to cause a Denial of Service (DoS) via a crafted DICOM file.
CVE-2025-22921
- EPSS 0.16%
- Veröffentlicht 18.02.2025 22:15:18
- Zuletzt bearbeitet 12.01.2026 13:08:11
FFmpeg git-master,N-113007-g8d24a28d06 was discovered to contain a segmentation violation via the component /libavcodec/jpeg2000dec.c.
CVE-2025-26465
- EPSS 61.22%
- Veröffentlicht 18.02.2025 19:15:29
- Zuletzt bearbeitet 12.05.2026 13:16:40
A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in spec...
CVE-2025-23419
- EPSS 2.86%
- Veröffentlicht 05.02.2025 18:15:33
- Zuletzt bearbeitet 27.01.2026 13:30:41
When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. This vulnerability arises when TLS Session Tickets ht...
CVE-2025-0781
- EPSS 0.04%
- Veröffentlicht 28.01.2025 17:15:25
- Zuletzt bearbeitet 06.08.2025 19:25:13
An attacker can bypass the sandboxing of Nasal scripts and arbitrarily write to any file path that the user has permission to modify at the operating-system level.