VulnSea

Tagged “csaf”

CVEs tagged csaf, newest first.

3138 CVEsRSS

CVE-2025-6021High· 7.5PoC
1y ago

A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow

A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafte…

▾ Midnightxmlsoft · libxml2EPSS 1.4%via NVD
CVE-2025-22874High· 7.5
1y ago

crypto/x509: Usage of ExtKeyUsageAny disables policy validation in crypto/x509 (CVE-2025-22874)

A flaw was found in Go's crypto/x509 package. This vulnerability allows improper certificate validation, bypassing policy constraints via using ExtKeyUsageAny in VerifyOptions.KeyUsages.

▾ TwilightRed Hat · Red Hat OpenShift Container Platform 4.20EPSS 0.37%via CSAF
CVE-2025-5914High· 7.8PoC
1y ago

A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function

A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a…

▾ Midnightlibarchive · libarchiveEPSS 0.44%via NVD
CVE-2025-20278Medium· 6.0
1y ago

Cisco Unified Communications Products Command Injection Vulnerability (CVE-2025-20278)

A vulnerability in the CLI of multiple Cisco Unified Communications products could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device as the root user. This vuln…

▾ SunlitCisco · Cisco Unified Communications ManagerEPSS 0.18%via CSAF
CVE-2025-20129Medium· 4.3
1y ago

Cisco Customer Collaboration Platform Information Disclosure Vulnerability (CVE-2025-20129)

A vulnerability in the web-based chat interface of Cisco Customer Collaboration Platform (CCP), formerly Cisco SocialMiner, could allow an unauthenticated, remote attacker to persuade users to disclose sensitive data. This vulnerability…

▾ SunlitCisco · Cisco SocialMinerEPSS 0.34%via CSAF
CVE-2025-5278Medium· 4.4
1y ago

A flaw was found in GNU Coreutils

A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key fo…

▾ SunlitRed Hat · coreutilsEPSS 0.29%via NVD
CVE-2025-5222High· 7.0PoC
1y ago

A stack buffer overflow was found in Internationl components for unicode (ICU )

A stack buffer overflow was found in Internationl components for unicode (ICU ). While running the genrb binary, the 'subtag' struct overflowed at the SRBRoot::addTag function. This issue may lead to memory corruption and local arbitrary…

▾ Midnightunicode · international_components_for_unicodeEPSS 0.43%via NVD
CVE-2025-20112Medium· 5.1
1y ago

Cisco Unified Communications Products Privilege Escalation Vulnerability (CVE-2025-20112)

A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability is due to excessive perm…

▾ SunlitCisco · Cisco Unified Communications ManagerEPSS 0.14%via CSAF
CVE-2025-20196Medium· 5.3
1y ago

Cisco IOx Application Hosting Environment Denial of Service Vulnerbility

A vulnerability in the Cisco IOx application hosting environment of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the Cisco IOx application hosting environment to stop responding, res…

▾ SunlitCisco · Cisco IOS XE SoftwareEPSS 0.40%via CSAF
CVE-2025-20151Medium· 4.3
1y ago

Cisco IOS and IOS XE Software SNMPv3 Configuration Restriction Vulnerability (CVE-2025-20151)

A vulnerability in the implementation of the Simple Network Management Protocol Version 3 (SNMPv3) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to poll an affected device using SNMP,…

▾ SunlitCisco · IOSEPSS 0.39%via CSAF
CVE-2025-4373Medium· 4.8
1y ago

A flaw was found in GLib, which is vulnerable to an integer overflow in the g_string_insert_unichar() function

A flaw was found in GLib, which is vulnerable to an integer overflow in the g_string_insert_unichar() function. When the position at which to insert the character is large, the position will overflow, leading to a buffer underwrite.

▾ SunlitRed Hat · glibEPSS 0.61%via NVD
CVE-2025-3910Medium· 5.4
1y ago

A flaw was found in Keycloak

A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication.

▾ Sunlitredhat · build_of_keycloakEPSS 0.44%via NVD
CVE-2025-3501High· 8.2
1y ago

A flaw was found in Keycloak

A flaw was found in Keycloak. By setting a verification policy to 'ALL', the trust store certificate verification is skipped, which is unintended.

▾ TwilightRed Hat · keycloakEPSS 0.46%via NVD
CVE-2025-32912Medium· 6.5
1y ago

A flaw was found in libsoup, where SoupAuthDigest is vulnerable to a NULL pointer dereference

A flaw was found in libsoup, where SoupAuthDigest is vulnerable to a NULL pointer dereference. The HTTP server may cause the libsoup client to crash.

▾ SunlitRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.45%via NVD
CVE-2025-32910Medium· 6.5
1y ago

A flaw was found in libsoup, where soup_auth_digest_authenticate() is vulnerable to a NULL pointer dereference

A flaw was found in libsoup, where soup_auth_digest_authenticate() is vulnerable to a NULL pointer dereference. This issue may cause the libsoup client to crash.

▾ SunlitRed Hat · libsoupEPSS 0.45%via NVD
CVE-2025-32909Medium· 5.3
1y ago

A flaw was found in libsoup

A flaw was found in libsoup. SoupContentSniffer may be vulnerable to a NULL pointer dereference in the sniff_mp4 function. The HTTP server may cause the libsoup client to crash.

▾ SunlitRed Hat · libsoupEPSS 0.52%via NVD
CVE-2025-2842Medium· 4.3
1y ago

A flaw was found in the Tempo Operator

A flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab functionality is enabled in a Tempo instance managed by the Tempo Operator, the Operator creates a ClusterRoleBinding for the Service Account of the Tempo instance to…

▾ SunlitRed Hat · tempo-operatorEPSS 0.38%via NVD
CVE-2025-2786Medium· 4.3
1y ago

A flaw was found in Tempo Operator, where it creates a ServiceAccount, ClusterRole, and ClusterRoleBinding when a user deploys a TempoStack or TempoMonolithic instance

A flaw was found in Tempo Operator, where it creates a ServiceAccount, ClusterRole, and ClusterRoleBinding when a user deploys a TempoStack or TempoMonolithic instance. This flaw allows a user with full access to their namespace to extra…

▾ SunlitRed Hat · tempo-operatorEPSS 0.36%via NVD
CVE-2022-49738High· 7.1
1y ago

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to do sanity check on i_extra_isize in is_alive() syzbot found a f2fs bug: BUG: KASAN: slab-out-of-bounds in data_blkaddr fs/f2fs/f2fs.h:2891 [inline] BUG: …

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to do sanity check on i_extra_isize in is_alive() syzbot found a f2fs bug: BUG: KASAN: slab-out-of-bounds in data_blkaddr fs/f2fs/f2fs.h:2891 [inline] BUG: …

▾ Twilightlinux · linux_kernelEPSS 0.19%via NVD
CVE-2025-21889High· 7.8⚖ disputed
1y ago

In the Linux kernel, the following vulnerability has been resolved: perf/core: Add RCU read lock protection to perf_iterate_ctx() The perf_iterate_ctx() function performs RCU list traversal but currently lacks RCU read lock protection.…

In the Linux kernel, the following vulnerability has been resolved: perf/core: Add RCU read lock protection to perf_iterate_ctx() The perf_iterate_ctx() function performs RCU list traversal but currently lacks RCU read lock protection.…

▾ Twilightlinux · linux_kernelEPSS 0.20%via NVD
CVE-2025-21884High· 7.8⚖ disputed
1y ago

In the Linux kernel, the following vulnerability has been resolved: net: better track kernel sockets lifetime While kernel sockets are dismantled during pernet_operations->exit(), their freeing can be delayed by any tx packets still he…

In the Linux kernel, the following vulnerability has been resolved: net: better track kernel sockets lifetime While kernel sockets are dismantled during pernet_operations->exit(), their freeing can be delayed by any tx packets still he…

▾ Twilightlinux · linux_kernelEPSS 0.21%via NVD
CVE-2025-21876High· 8.8⚖ disputed
1y ago

In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Fix suspicious RCU usage Commit <d74169ceb0d2> ("iommu/vt-d: Allocate DMAR fault interrupts locally") moved the call to enable_drhd_fault_handling() to a c…

In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Fix suspicious RCU usage Commit <d74169ceb0d2> ("iommu/vt-d: Allocate DMAR fault interrupts locally") moved the call to enable_drhd_fault_handling() to a c…

▾ Twilightlinux · linux_kernelEPSS 0.21%via NVD
CVE-2025-21868High· 7.5⚖ disputed
1y ago

In the Linux kernel, the following vulnerability has been resolved: net: allow small head cache usage with large MAX_SKB_FRAGS values Sabrina reported the following splat: WARNING: CPU: 0 PID: 1 at net/core/dev.c:6935 netif_napi_a…

In the Linux kernel, the following vulnerability has been resolved: net: allow small head cache usage with large MAX_SKB_FRAGS values Sabrina reported the following splat: WARNING: CPU: 0 PID: 1 at net/core/dev.c:6935 netif_napi_a…

▾ Twilightlinux · linux_kernelEPSS 0.38%via NVD
CVE-2025-2559Medium· 4.9
1y ago

A flaw was found in Keycloak

A flaw was found in Keycloak. When the configuration uses JWT tokens for authentication, the tokens are cached until expiration. If a client uses JWT tokens with an excessively long expiration time, for example, 24 or 48 hours, the cache…

▾ SunlitRed Hat · keycloakEPSS 0.69%via NVD
CVE-2024-40635Medium· 4.6PoC
1y ago

containerd: containerd has an integer overflow in User ID handling (CVE-2024-40635)

A flaw was found in containerd package. Containers launched with a User set as a UID:GID larger than the maximum 32-bit signed integer can cause an overflow condition where the container ultimately runs as root (UID 0). This issue could ca…

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.22EPSS 0.29%via CSAF
CVE-2024-8176High· 7.5PoC
1y ago

A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents

A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML document with deeply nested entity references, libexpat can be forced to recurse ind…

▾ MidnightRed Hat · libexpatEPSS 1.3%via NVD
CVE-2025-21826High· 7.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: reject mismatching sum of field_len with set key length The field length description provides the length of each separated key field in the conca…

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: reject mismatching sum of field_len with set key length The field length description provides the length of each separated key field in the conca…

▾ Twilightlinux · linux_kernelEPSS 0.20%via NVD
CVE-2025-27516Medium· 7.3
1y ago

Jinja2 vulnerable to sandbox breakout through attr filter selecting format method

Jinja2 vulnerable to sandbox breakout through attr filter selecting format method

▾ Sunlitjinja2 · jinja2EPSS 0.50%via OSV
CVE-2025-23368High· 8.1
1y ago

A flaw was found in Wildfly Elytron integration

A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks via CLI.

▾ Twilightredhat · wildfly_coreEPSS 0.89%via NVD
CVE-2025-21789High· 7.3
1y ago

In the Linux kernel, the following vulnerability has been resolved: LoongArch: csum: Fix OoB access in IP checksum code for negative lengths Commit 69e3a6aa6be2 ("LoongArch: Add checksum optimization for 64-bit system") would cause an …

In the Linux kernel, the following vulnerability has been resolved: LoongArch: csum: Fix OoB access in IP checksum code for negative lengths Commit 69e3a6aa6be2 ("LoongArch: Add checksum optimization for 64-bit system") would cause an …

▾ Twilightlinux · linux_kernelEPSS 0.23%via NVD
CVEs tagged “csaf” — page 99 · VulnSea