Latest CVE Feed
-
0.0
NACVE-2025-21691
In the Linux kernel, the following vulnerability has been resolved: cachestat: fix page cache statistics permission checking When the 'cachestat()' system call was added in commit cf264e1329fb ("cachestat: implement cachestat syscall"), it was meant to ... Read more
Affected Products : linux_kernel- Published: Feb. 10, 2025
- Modified: Feb. 10, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2025-21690
In the Linux kernel, the following vulnerability has been resolved: scsi: storvsc: Ratelimit warning logs to prevent VM denial of service If there's a persistent error in the hypervisor, the SCSI warning for failed I/O can flood the kernel log and max o... Read more
Affected Products : linux_kernel- Published: Feb. 10, 2025
- Modified: Feb. 21, 2025
- Vuln Type: Denial of Service
-
5.5
MEDIUMCVE-2025-21689
In the Linux kernel, the following vulnerability has been resolved: USB: serial: quatech2: fix null-ptr-deref in qt2_process_read_urb() This patch addresses a null-ptr-deref in qt2_process_read_urb() due to an incorrect bounds check in the following: ... Read more
Affected Products : linux_kernel- Published: Feb. 10, 2025
- Modified: Feb. 21, 2025
- Vuln Type: Memory Corruption
-
4.7
MEDIUMCVE-2025-21688
In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Assign job pointer to NULL before signaling the fence In commit e4b5ccd392b9 ("drm/v3d: Ensure job pointer is set to NULL after job completion"), we introduced a change to assi... Read more
Affected Products : linux_kernel- Published: Feb. 10, 2025
- Modified: Feb. 21, 2025
- Vuln Type: Race Condition
-
7.8
HIGHCVE-2025-21687
In the Linux kernel, the following vulnerability has been resolved: vfio/platform: check the bounds of read/write syscalls count and offset are passed from user space and not checked, only offset is capped to 40 bits, which can be used to read/write out... Read more
Affected Products : linux_kernel- Published: Feb. 10, 2025
- Modified: Mar. 13, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2024-57950
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Initialize denominator defaults to 1 [WHAT & HOW] Variables, used as denominators and maybe not assigned to other values, should be initialized to non-zero to avoid DIV... Read more
Affected Products : linux_kernel- Published: Feb. 10, 2025
- Modified: Feb. 21, 2025
- Vuln Type: Misconfiguration
-
5.3
MEDIUMCVE-2024-12243
A flaw was found in GnuTLS, which relies on libtasn1 for ASN.1 data processing. Due to an inefficient algorithm in libtasn1, decoding certain DER-encoded certificate data can take excessive time, leading to increased resource consumption. This flaw allows... Read more
- Published: Feb. 10, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Denial of Service
-
5.3
MEDIUMCVE-2024-12133
A flaw in libtasn1 causes inefficient handling of specific certificate data. When processing a large number of elements in a certificate, libtasn1 takes much longer than expected, which can slow down or even crash the system. This flaw allows an attacker ... Read more
- Published: Feb. 10, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Denial of Service
-
5.4
MEDIUMCVE-2024-11831
A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not properly sanitize certain inputs, such as regex or other JavaScript object types, allowing an attacker to inject malicious code. This c... Read more
Affected Products : enterprise_linux- Published: Feb. 10, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
3.1
LOWCVE-2025-1149
A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup of the file libiberty/xmalloc.c of the component ld. The manipulation leads to memory leak. It is possible to initiate the attack remo... Read more
Affected Products : binutils- Published: Feb. 10, 2025
- Modified: Feb. 10, 2025
- Vuln Type: Memory Corruption
-
7.3
HIGHCVE-2024-10334
A vulnerability exists in the VideONet product included in the listed System 800xA versions, where VideONet is used. An attacker who successfully exploited the vulnerability could, in the worst case scenario, stop or manipulate the video feed. This issu... Read more
Affected Products :- Published: Feb. 10, 2025
- Modified: Feb. 10, 2025
- Vuln Type: Denial of Service
-
8.1
HIGHCVE-2025-1193
Improper host validation in the certificate validation component in Devolutions Remote Desktop Manager on 2024.3.19 and earlier on Windows allows an attacker to intercept and modify encrypted communications via a man-in-the-middle attack by presenting a ... Read more
Affected Products : remote_desktop_manager- Published: Feb. 10, 2025
- Modified: Mar. 28, 2025
- Vuln Type: Misconfiguration
-
3.1
LOWCVE-2025-1148
A vulnerability was found in GNU Binutils 2.43 and classified as problematic. Affected by this issue is the function link_order_scan of the file ld/ldelfgen.c of the component ld. The manipulation leads to memory leak. The attack may be launched remotely.... Read more
Affected Products : binutils- Published: Feb. 10, 2025
- Modified: Apr. 04, 2025
- Vuln Type: Memory Corruption
-
5.3
MEDIUMCVE-2025-1147
A vulnerability has been found in GNU Binutils 2.43 and classified as problematic. Affected by this vulnerability is the function __sanitizer::internal_strlen of the file binutils/nm.c of the component nm. The manipulation of the argument const leads to b... Read more
Affected Products : binutils- Published: Feb. 10, 2025
- Modified: Apr. 04, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2024-11621
Missing certificate validation in Devolutions Remote Desktop Manager on macOS, iOS, Android, Linux allows an attacker to intercept and modify encrypted communications via a man-in-the-middle attack. Versions affected are : Remote Desktop Manager macOS 20... Read more
- Published: Feb. 10, 2025
- Modified: Mar. 28, 2025
- Vuln Type: Cryptography
-
6.1
MEDIUMCVE-2025-1175
Reflected Cross-Site Scripting (XSS) vulnerability in Kelio Visio 1, Kelio Visio X7 and Kelio Visio X4, in versions between 3.2C and 5.1K. This vulnerability could allow an attacker to execute a JavaScript payload by making a POST request and injecting ma... Read more
Affected Products :- Published: Feb. 10, 2025
- Modified: Feb. 10, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2024-8685
Path-Traversal vulnerability in Revolution Pi version 2022-07-28-revpi-buster from KUNBUS GmbH. This vulnerability could allow an authenticated attacker to list device directories via the ‘/pictory/php/getFileList.php’ endpoint in the ‘dir’ parameter.... Read more
Affected Products :- Published: Feb. 10, 2025
- Modified: Feb. 10, 2025
- Vuln Type: Path Traversal
-
8.3
HIGHCVE-2024-8684
OS Command Injection vulnerability in Revolution Pi version 2022-07-28-revpi-buster from KUNBUS GmbH. This vulnerability could allow an authenticated attacker to execute OS commands on the device via the ‘php/dal.php’ endpoint, in the ‘arrSaveConfig’ para... Read more
Affected Products :- Published: Feb. 10, 2025
- Modified: Feb. 10, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2025-25247
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix Webconsole. This issue affects Apache Felix Webconsole 4.x up to 4.9.8 and 5.x up to 5.0.8. Users are recommended to upgrade to version 4.... Read more
Affected Products : felix_webconsole- Published: Feb. 10, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Cross-Site Scripting
-
7.0
HIGHCVE-2025-1099
This vulnerability exists in Tapo C500 Wi-Fi camera due to hard-coded RSA private key embedded within the device firmware. An attacker with physical access could exploit this vulnerability to obtain cryptographic private keys which can then be used to per... Read more
Affected Products :- Published: Feb. 10, 2025
- Modified: Feb. 14, 2025
- Vuln Type: Cryptography