Latest CVE Feed
-
7.5
HIGHCVE-2025-25475
A NULL pointer dereference in the component /libsrc/dcrleccd.cc of DCMTK v3.6.9+ DEV allows attackers to cause a Denial of Service (DoS) via a crafted DICOM file.... Read more
Affected Products :- Published: Feb. 18, 2025
- Modified: Feb. 20, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2025-25474
DCMTK v3.6.9+ DEV was discovered to contain a buffer overflow via the component /dcmimgle/diinpxt.h.... Read more
Affected Products :- Published: Feb. 18, 2025
- Modified: Feb. 20, 2025
- Vuln Type: Memory Corruption
-
5.3
MEDIUMCVE-2025-25473
FFmpeg git master before commit c08d30 was discovered to contain a NULL pointer dereference via the component libavformat/mov.c.... Read more
Affected Products :- Published: Feb. 18, 2025
- Modified: Feb. 20, 2025
- Vuln Type: Memory Corruption
-
5.3
MEDIUMCVE-2025-25472
A buffer overflow in DCMTK git master v3.6.9+ DEV allows attackers to cause a Denial of Service (DoS) via a crafted DCM file.... Read more
Affected Products :- Published: Feb. 18, 2025
- Modified: Feb. 20, 2025
- Vuln Type: Memory Corruption
-
4.3
MEDIUMCVE-2025-25471
FFmpeg git master before commit fd1772 was discovered to contain a NULL pointer dereference via the component libavformat/mov.c.... Read more
Affected Products :- Published: Feb. 18, 2025
- Modified: Feb. 20, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-24928
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted DTD. NOTE: this is similar to CVE-2017-9047.... Read more
Affected Products : libxml2- Published: Feb. 18, 2025
- Modified: Mar. 21, 2025
- Vuln Type: Memory Corruption
-
5.3
MEDIUMCVE-2025-22920
A heap buffer overflow vulnerability in FFmpeg before commit 4bf784c allows attackers to trigger a memory corruption via supplying a crafted media file in avformat when processing tile grid group streams. This can lead to a Denial of Service (DoS).... Read more
Affected Products :- Published: Feb. 18, 2025
- Modified: Feb. 19, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2025-22919
A reachable assertion in FFmpeg git-master commit N-113007-g8d24a28d06 allows attackers to cause a Denial of Service (DoS) via opening a crafted AAC file.... Read more
Affected Products : ffmpeg- Published: Feb. 18, 2025
- Modified: Feb. 19, 2025
- Vuln Type: Denial of Service
-
7.1
HIGHCVE-2024-57259
sqfs_search_dir in Das U-Boot before 2025.01-rc1 exhibits an off-by-one error and resultant heap memory corruption for squashfs directory listing because the path separator is not considered in a size calculation.... Read more
Affected Products : u-boot- Published: Feb. 18, 2025
- Modified: Feb. 19, 2025
- Vuln Type: Memory Corruption
-
7.1
HIGHCVE-2024-57258
Integer overflows in memory allocation in Das U-Boot before 2025.01-rc1 occur for a crafted squashfs filesystem via sbrk, via request2size, or because ptrdiff_t is mishandled on x86_64.... Read more
Affected Products : u-boot- Published: Feb. 18, 2025
- Modified: Feb. 19, 2025
- Vuln Type: Memory Corruption
-
2.0
LOWCVE-2024-57257
A stack consumption issue in sqfs_size in Das U-Boot before 2025.01-rc1 occurs via a crafted squashfs filesystem with deep symlink nesting.... Read more
Affected Products : u-boot- Published: Feb. 18, 2025
- Modified: Feb. 19, 2025
- Vuln Type: Denial of Service
-
7.1
HIGHCVE-2024-57256
An integer overflow in ext4fs_read_symlink in Das U-Boot before 2025.01-rc1 occurs for zalloc (adding one to an le32 variable) via a crafted ext4 filesystem with an inode size of 0xffffffff, resulting in a malloc of zero and resultant memory overwrite.... Read more
Affected Products : u-boot- Published: Feb. 18, 2025
- Modified: Feb. 19, 2025
- Vuln Type: Memory Corruption
-
7.1
HIGHCVE-2024-57255
An integer overflow in sqfs_resolve_symlink in Das U-Boot before 2025.01-rc1 occurs via a crafted squashfs filesystem with an inode size of 0xffffffff, resulting in a malloc of zero and resultant memory overwrite.... Read more
Affected Products : u-boot- Published: Feb. 18, 2025
- Modified: Feb. 19, 2025
- Vuln Type: Memory Corruption
-
7.1
HIGHCVE-2024-57254
An integer overflow in sqfs_inode_size in Das U-Boot before 2025.01-rc1 occurs in the symlink size calculation via a crafted squashfs filesystem.... Read more
Affected Products : u-boot- Published: Feb. 18, 2025
- Modified: Feb. 19, 2025
- Vuln Type: Memory Corruption
-
6.4
MEDIUMCVE-2024-13743
The Wonder Video Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wonderplugin_video shortcode in all versions up to, and including, 2.2 due to insufficient input sanitization and output escaping on user supplied at... Read more
Affected Products : wonder_video_embed- Published: Feb. 18, 2025
- Modified: Feb. 18, 2025
- Vuln Type: Cross-Site Scripting
-
5.7
MEDIUMCVE-2025-25896
A buffer overflow vulnerability was discovered in D-Link DSL-3782 v1.01 via the destination, netmask, and gateway parameters. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.... Read more
- Published: Feb. 18, 2025
- Modified: May. 02, 2025
- Vuln Type: Memory Corruption
-
8.0
HIGHCVE-2025-25895
An OS command injection vulnerability was discovered in D-Link DSL-3782 v1.01 via the public_type parameter. This vulnerability allows attackers to execute arbitrary operating system (OS) commands via a crafted packet.... Read more
- Published: Feb. 18, 2025
- Modified: May. 02, 2025
- Vuln Type: Injection
-
8.0
HIGHCVE-2025-25894
An OS command injection vulnerability was discovered in D-Link DSL-3782 v1.01 via the samba_wg and samba_nbn parameters. This vulnerability allows attackers to execute arbitrary operating system (OS) commands via a crafted packet.... Read more
- Published: Feb. 18, 2025
- Modified: May. 02, 2025
- Vuln Type: Injection
-
8.0
HIGHCVE-2025-25893
An OS command injection vulnerability was discovered in D-Link DSL-3782 v1.01 via the inIP, insPort, inePort, exsPort, exePort, and protocol parameters. This vulnerability allows attackers to execute arbitrary operating system (OS) commands via a crafted ... Read more
- Published: Feb. 18, 2025
- Modified: May. 02, 2025
- Vuln Type: Injection
-
5.7
MEDIUMCVE-2025-25892
A buffer overflow vulnerability was discovered in D-Link DSL-3782 v1.01 via the sstartip, sendip, dstartip, and dendip parameters. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.... Read more
- Published: Feb. 18, 2025
- Modified: May. 02, 2025
- Vuln Type: Memory Corruption