CVE-2025-15382High· 8.1▾ TwilightA heap buffer over-read vulnerability exists in the wolfSSH_CleanPath() function in wolfSSH. An authenticated remote attacker can trigger the issue via crafted SCP path input containing '/./' sequences, resulting in a heap over read by 1…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
A heap buffer over-read vulnerability exists in the wolfSSH_CleanPath() function in wolfSSH. An authenticated remote attacker can trigger the issue via crafted SCP path input containing '/./' sequences, resulting in a heap over read by 1 byte.
wolfssh >= 1.4.12, < 1.4.22Upgrade past the affected range:
wolfssh 1.4.22Connected by shared product, vendor, weakness, or advisory.
CVE-2025-14942Critical· 9.8wolfSSH’s key exchange state machine can be manipulated to leak the client’s password in the clear, trick the client to send a bogus signature, or trick the client into skipping user authentication
CVE-2025-11494Low· 3.3A vulnerability was found in GNU Binutils 2.45
CVE-2025-48622Medium· 5.5In ProcessArea of dng_misc_opcodes.cpp, there is a possible out of bounds read due to a buffer overflow
CVE-2025-48596High· 7.8In appendFrom of Parcel.cpp, there is a possible out of bounds read due to a missing bounds check
CVE-2025-11211High· 7.5Out of bounds read in Media in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page
CVE-2021-3506High· 7.1An out-of-bounds (OOB) memory access flaw was found in fs/f2fs/node.c in the f2fs module in the Linux kernel in versions before 5.12.0-rc4