Search and browse vulnerability records from NVD
Showing 50 of 46308 CVEs
| CVE ID | Severity | Description | EPSS | Published | |
|---|---|---|---|---|---|
| 6.4 MEDIUM |
Out-of-bounds write in secfr trustlet prior to SMR Apr-2025 Release 1 allows local privileged attackers to cause memory corruption. |
0.1% | 2025-04-08 | ||
| 4.4 MEDIUM |
Improper Verification of Intent by Broadcast Receiver in DeviceIdService prior to SMR Apr-2025 Release 1 allows local attackers to reset OAID. |
0.1% | 2025-04-08 | ||
| 6.2 MEDIUM |
Improper access control in InputManager to SMR Apr-2025 Release 1 allows local attackers to access the scancode of specific input device. |
0.1% | 2025-04-08 | ||
| 5.4 MEDIUM |
Improper authorization in wireless download protocol in Galaxy Watch prior to SMR Apr-2025 Release 1 allows physical attackers to update device unique identifier of Watch devices. |
0.1% | 2025-04-08 | ||
| 5.5 MEDIUM |
Improper access control in SamsungContacts prior to SMR Apr-2025 Release 1 allows local attackers to access protected data in SamsungContacts. |
0.1% | 2025-04-08 | ||
| 8.8 HIGH |
Improper access control in HDCP trustlet prior to SMR Apr-2025 Release 1 allows local attackers with shell privilege to escalate their privileges to root. |
0.1% | 2025-04-08 | ||
| 6.3 MEDIUM |
A vulnerability was found in Nothings stb up to f056911. It has been rated as critical. Affected by this issue is the function stb_dupreplace. The manipulation leads to integer overflow. The attack may be launched remotely. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way. |
0.2% | 2025-04-08 | ||
| 6.3 MEDIUM |
A vulnerability was found in Nothings stb up to f056911. It has been declared as critical. Affected by this vulnerability is the function stbhw_build_tileset_from_image. The manipulation of the argument h_count/v_count leads to out-of-bounds read. The attack can be launched remotely. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The vendor was contacted early about this disclosure but did not respond in any way. |
0.2% | 2025-04-08 | ||
| 4.3 MEDIUM |
A vulnerability was found in Nothings stb up to f056911. It has been classified as problematic. Affected is the function stbhw_build_tileset_from_image of the component Header Array Handler. The manipulation of the argument w leads to out-of-bounds read. It is possible to launch the attack remotely. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way. |
0.2% | 2025-04-08 | ||
| 5.6 MEDIUM |
In libxml2 before 2.13.8 and 2.14.x before 2.14.2, out-of-bounds memory access can occur in the Python API (Python bindings) because of an incorrect return value. This occurs in xmlPythonFileRead and xmlPythonFileReadRaw because of a difference between bytes and characters. |
0.2% | 2025-04-08 | ||
| 6.3 MEDIUM |
A vulnerability classified as critical was found in lenve VBlog up to 1.0.0. Affected by this vulnerability is the function configure of the file blogserver/src/main/java/org/sang/config/WebSecurityConfig.java. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. |
0.3% | 2025-04-08 | ||
| 8.6 HIGH |
The DB chooser functionality inΒ Jalios JPlatform 10 SP6 before 10.0.6 improperly neutralizes special elements used in an SQL command allows for unauthenticated users to trigger SQL Injection. This issue affects JPlatform before 10.0.6 and a PatchPlugin release 10.0.6 was issued 2023-02-06. |
0.5% | 2025-04-07 | ||
| 6.3 MEDIUM |
A vulnerability, which was classified as critical, was found in zhangyanbo2007 youkefu 4.2.0. This affects an unknown part of the file WebIMController.java of the component File Upload. The manipulation of the argument ID leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. |
0.7% | 2025-04-07 | ||
| 5.5 MEDIUM |
libvips is a demand-driven, horizontally threaded image processing library. The heifsave operation could incorrectly determine the presence of an alpha channel in an input when it was not possible to determine the colour interpretation, known internally within libvips as "multiband". There aren't many ways to create a "multiband" input, but it is possible with a well-crafted TIFF image. If a "multiband" TIFF input image had 4 channels and HEIF-based output was requested, this led to libvips creating a 3 channel HEIF image without an alpha channel but then attempting to write 4 channels of data. This caused a heap buffer overflow, which could crash the process. This vulnerability is fixed in 8.16.1. |
0.1% | 2025-04-07 | ||
| 6.2 MEDIUM |
Buffer Overflow vulnerability in libbpf 1.5.0 allows a local attacker to execute arbitrary code via the bpf_object__init_prog` function of libbpf. This has been disputed by third parties who assert that "no one in their sane mind should be passing untrusted ELF files into libbpf while running under root." |
0.1% | 2025-04-07 | ||
| 5.5 MEDIUM |
An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the cfl_list_size in cfl_list.h:165. |
0.1% | 2025-04-07 | ||
|
CVE-2025-3248
KEV
|
9.8 CRITICAL |
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code. |
92.1% | 2025-04-07 | |
| 5.5 MEDIUM |
tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js prior to 1.20.1, where the addOrUpdate function, used for applying custom texts, did not properly validate input. This allowed an attacker with direct access to the site's source code or a CMS plugin to manipulate JavaScript object prototypes, leading to potential security risks such as data corruption or unintended code execution. An attacker with high privileges could exploit this vulnerability to modify object prototypes, affecting core JavaScript behavior, cause application crashes or unexpected behavior, or potentially introduce further security vulnerabilities depending on the application's architecture. This vulnerability is fixed in 1.20.1. |
1.3% | 2025-04-07 | ||
| 5.5 MEDIUM |
tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js prior to 1.20.1, where user-controlled inputs for element dimensions (width and height) were not properly validated. This allowed an attacker with direct access to the site's source code or a CMS plugin to set values like 100%;height:100%;position:fixed;, potentially covering the entire viewport and facilitating clickjacking attacks. An attacker with high privileges could exploit this vulnerability to overlay malicious UI elements on top of legitimate content, trick users into interacting with hidden elements (clickjacking), or disrupt the intended functionality and accessibility of the website. This vulnerability is fixed in 1.20.1. |
0.2% | 2025-04-07 | ||
| 6.5 MEDIUM |
Graylog is a free and open log management platform. Starting with 6.1, HTTP Inputs can be configured to check if a specified header is present and has a specified value to authenticate HTTP-based ingestion. Unfortunately, even though in cases of a missing header or a wrong value the correct HTTP response (401) is returned, the message will be ingested nonetheless. To mitigate the vulnerability, disable http-based inputs and allow only authenticated pull-based inputs. This vulnerability is fixed in 6.1.9. |
0.1% | 2025-04-07 | ||
| 6.3 MEDIUM |
A vulnerability was found in xxyopen Novel-Plus 5.1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /novel/friendLink/list. The manipulation of the argument sort leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. |
0.2% | 2025-04-07 | ||
| 2.7 LOW |
Dell Unisphere for PowerMax, version(s) prior to 10.2.0.9 and PowerMax version(s) prior to PowerMax 9.2.4.15, contain an Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection. |
0.3% | 2025-04-07 | ||
| 5.9 MEDIUM |
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a non-privileged user process to make valid GPU processing operations, including via WebGL or WebGPU, to access a limited amount outside of buffer bounds.This issue affects Bifrost GPU Userspace Driver: from r0p0 through r49p2, from r50p0 through r51p0; Valhall GPU Userspace Driver: from r19p0 through r49p2, from r50p0 through r53p0; Arm 5th Gen GPU Architecture Userspace Driver: from r41p0 through r49p2, from r50p0 through r53p0. |
0.1% | 2025-04-07 | ||
| 7.5 HIGH |
Transient DOS may occur while parsing SSID in action frames. |
0.5% | 2025-04-07 | ||
| 7.8 HIGH |
Memory corruption may occur while reading board data via IOCTL call when the WLAN driver copies the content to the provided output buffer. |
0.1% | 2025-04-07 | ||
| 7.8 HIGH |
Memory corruption while IOCTL call is invoked from user-space to read board data. |
0.1% | 2025-04-07 | ||
| 7.5 HIGH |
Transient DOS may occur while parsing extended IE in beacon. |
0.5% | 2025-04-07 | ||
| 7.5 HIGH |
Transient DOS may occur while parsing EHT operation IE or EHT capability IE. |
0.5% | 2025-04-07 | ||
| 7.5 HIGH |
Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session. |
0.4% | 2025-04-07 | ||
| 7.5 HIGH |
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request. |
0.4% | 2025-04-07 | ||
| 7.5 HIGH |
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session. |
0.4% | 2025-04-07 | ||
| 6.7 MEDIUM |
Memory corruption while processing multiple IOCTL calls from HLOS to DSP. |
0.0% | 2025-04-07 | ||
| 8.2 HIGH |
Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesn`t adhere to RFC standards. |
0.3% | 2025-04-07 | ||
| 6.2 MEDIUM |
Cryptographic issue occurs during PIN/password verification using Gatekeeper, where RPMB writes can be dropped on verification failure, potentially leading to a user throttling bypass. |
0.1% | 2025-04-07 | ||
| 7.7 HIGH |
Information disclosure while creating MQ channels. |
0.1% | 2025-04-07 | ||
| 6.6 MEDIUM |
Memory corruption while processing IOCTL calls to add route entry in the HW. |
0.1% | 2025-04-07 | ||
| 6.6 MEDIUM |
Memory corruption while accessing MSM channel map and mixer functions. |
0.1% | 2025-04-07 | ||
| 6.6 MEDIUM |
Memory corruption while invoking IOCTL map buffer request from userspace. |
0.1% | 2025-04-07 | ||
| 7.8 HIGH |
Memory corruption while handling file descriptor during listener registration/de-registration. |
0.1% | 2025-04-07 | ||
| 7.1 HIGH |
Cryptographic issues while generating an asymmetric key pair for RKP use cases. |
0.1% | 2025-04-07 | ||
| 5.5 MEDIUM |
There may be information disclosure during memory re-allocation in TZ Secure OS. |
0.1% | 2025-04-07 | ||
| 7.5 HIGH |
Memory corruption while assigning memory from the source DDR memory(HLOS) to ADSP. |
0.1% | 2025-04-07 | ||
| 6.5 MEDIUM |
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01519028; Issue ID: MSV-2768. |
0.3% | 2025-04-07 | ||
| 3.3 LOW |
in OpenHarmony v5.0.2 and prior versions allow a local attacker case DOS through missing release of memory. |
0.1% | 2025-04-07 | ||
| 3.3 LOW |
in OpenHarmony v5.0.2 and prior versions allow a local attacker case DOS through missing release of memory. |
0.1% | 2025-04-07 | ||
| 3.3 LOW |
in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds write. |
0.1% | 2025-04-07 | ||
| 6.5 MEDIUM |
in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through integer overflow. |
0.1% | 2025-04-07 | ||
| 3.3 LOW |
in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read. |
0.1% | 2025-04-07 | ||
| 3.3 LOW |
in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read. |
0.1% | 2025-04-07 | ||
| 3.3 LOW |
in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read. |
0.1% | 2025-04-07 |