CVE tracker
389 subscribers
5.52K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-28413 - RUoYi Privilege Escalation Vulnerability

CVE ID : CVE-2025-28413
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the SysDictTypeController component
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3373 - PCMan FTP Server Buffer Overflow Vulnerability

CVE ID : CVE-2025-3373
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this vulnerability is an unknown functionality of the component SITE CHMOD Command Handler. The manipulation leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3374 - PCMan FTP Server Buffer Overflow Vulnerability

CVE ID : CVE-2025-3374
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : A vulnerability was found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this issue is some unknown functionality of the component CCC Command Handler. The manipulation leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3424 - IntelliSpace Portal .NET Remoting Unauthenticated File Disclosure

CVE ID : CVE-2025-3424
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : The IntelliSpace portal application utilizes .NET Remoting for its functionality. The vulnerability arises from the exploitation of port 755 through the "Object Marshalling" technique, which allows an attacker to read internal files without any authentication. This is possible by crafting specific .NET Remoting URLs derived from information enumerated in the client-side configuration files. This issue affects IntelliSpace Portal: 12 and prior.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3425 - "IntelliSpace Portal .NET Remoting Deserialization Remote Code Execution"

CVE ID : CVE-2025-3425
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : The IntelliSpace portal application utilizes .NET Remoting for its functionality. The vulnerability arises from the exploitation of port 755 through the deserialization vulnerability. After analyzing the configuration files, we observed that the server had set the TypeFilterLevel to Full which is dangerous as it can potentially lead to remote code execution using deserialization. This issue affects IntelliSpace Portal: 12 and prior.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3375 - PCMan FTP Server Buffer Overflow Vulnerability

CVE ID : CVE-2025-3375
Published : April 7, 2025, 5:15 p.m. | 4 hours, 5 minutes ago
Description : A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as critical. This affects an unknown part of the component CDUP Command Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3376 - PCMan FTP Server CONF Command Handler Buffer Overflow Vulnerability

CVE ID : CVE-2025-3376
Published : April 7, 2025, 5:15 p.m. | 4 hours, 5 minutes ago
Description : A vulnerability was found in PCMan FTP Server 2.0.7. It has been declared as critical. This vulnerability affects unknown code of the component CONF Command Handler. The manipulation leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3426 - "IntelliSpace Portal Unprotected Binary Reversibility and Hardcoded Credentials"

CVE ID : CVE-2025-3426
Published : April 7, 2025, 5:15 p.m. | 4 hours, 5 minutes ago
Description : We observed that Intellispace Portal binaries doesn’t have any protection mechanisms to prevent reverse engineering. Specifically, the app’s code is not obfuscated, and no measures are in place to protect against decompilation, disassembly, or debugging. As a result, attackers can reverse-engineer the application to gain insights into its internal workings, which can potentially lead to the discovery of sensitive information, business logic flaws, and other vulnerabilities. Utilizing this flaw, the attacker was able to identify the Hardcoded credentials from PortalUsersDatabase.dll, which contains .NET remoting definition. Inside the namespace PortalUsersDatabase, the class Users contains the functions CreateAdmin and CreateService that are used to initialize accounts in the Portal service. Both CreateAdmin and CreateService functions contain a hardcoded encrypted password along with its respective salt that are set with the function SetInitialPasswordAndSalt. This issue affects IntelliSpace Portal: 12 and prior; Advanced Visualization Workspace: 15.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-38797 - EDK2 HashPeImageByType Out-of-Bounds Read Vulnerability

CVE ID : CVE-2024-38797
Published : April 7, 2025, 6:15 p.m. | 3 hours, 5 minutes ago
Description : EDK2 contains a vulnerability in the HashPeImageByType(). A user may cause a read out of bounds when a corrupted data pointer and length are sent via an adjecent network. A successful exploit of this vulnerability may lead to a loss of Integrity and/or Availability.
Severity: 4.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3377 - PCMan FTP Server Buffer Overflow Vulnerability

CVE ID : CVE-2025-3377
Published : April 7, 2025, 6:15 p.m. | 3 hours, 5 minutes ago
Description : A vulnerability was found in PCMan FTP Server 2.0.7. It has been rated as critical. This issue affects some unknown processing of the component ENC Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3378 - PCMan FTP Server EPRT Command Handler Buffer Overflow

CVE ID : CVE-2025-3378
Published : April 7, 2025, 6:15 p.m. | 3 hours, 5 minutes ago
Description : A vulnerability classified as critical has been found in PCMan FTP Server 2.0.7. Affected is an unknown function of the component EPRT Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3379 - PCMan FTP Server EPSV Command Handler Buffer Overflow

CVE ID : CVE-2025-3379
Published : April 7, 2025, 7:15 p.m. | 2 hours, 5 minutes ago
Description : A vulnerability classified as critical was found in PCMan FTP Server 2.0.7. Affected by this vulnerability is an unknown functionality of the component EPSV Command Handler. The manipulation leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3380 - PCMan FTP Server Buffer Overflow Vulnerability

CVE ID : CVE-2025-3380
Published : April 7, 2025, 7:15 p.m. | 2 hours, 5 minutes ago
Description : A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. Affected by this issue is some unknown functionality of the component FEAT Command Handler. The manipulation leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-46494 - Typecho XSS

CVE ID : CVE-2024-46494
Published : April 7, 2025, 8:15 p.m. | 1 hour, 5 minutes ago
Description : A cross-site scripting (XSS) vulnerability in Typecho v1.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into Name parameter under a comment for an Article.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-29087 - Sqlite Integer Overflow Through Concat Function

CVE ID : CVE-2025-29087
Published : April 7, 2025, 8:15 p.m. | 1 hour, 5 minutes ago
Description : Sqlite 3.49.0 is susceptible to integer overflow through the concat function.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-29478 - Apache Fluent-bit Denial of Service

CVE ID : CVE-2025-29478
Published : April 7, 2025, 8:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the cfl_list_size in cfl_list.h:165.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-29479 - Redis Buffer Overflow Denial of Service

CVE ID : CVE-2025-29479
Published : April 7, 2025, 8:15 p.m. | 1 hour, 5 minutes ago
Description : Buffer Overflow in hiredis 1.2.0 allows a local attacker to cause a denial of service via the sdscatlen function.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-29480 - GDAL Buffer Overflow Denial of Service

CVE ID : CVE-2025-29480
Published : April 7, 2025, 8:15 p.m. | 1 hour, 5 minutes ago
Description : Buffer Overflow vulnerability in gdal 3.10.2 allows a local attacker to cause a denial of service via the OGRSpatialReference::Release function.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-29481 - Libbpf Buffer Overflow RCE

CVE ID : CVE-2025-29481
Published : April 7, 2025, 8:15 p.m. | 1 hour, 5 minutes ago
Description : Buffer Overflow vulnerability in libbpf 1.5.0 allows a local attacker to execute arbitrary code via the bpf_object__init_prog` function of libbpf.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-29482 - Libheif Buffer Overflow Arbitrary Code Execution

CVE ID : CVE-2025-29482
Published : April 7, 2025, 8:15 p.m. | 1 hour, 5 minutes ago
Description : Buffer Overflow vulnerability in libheif 1.19.7 allows a local attacker to execute arbitrary code via the SAO (Sample Adaptive Offset) processing of libde265.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-29594 - Apache CS2-WeaponPaints Website Unvalidated Input XSS

CVE ID : CVE-2025-29594
Published : April 7, 2025, 8:15 p.m. | 1 hour, 5 minutes ago
Description : A vulnerability exists in the errorpage.php file of the CS2-WeaponPaints-Website v2.1.7 where user-controlled input is not adequately validated before being processed. Specifically, the $_GET['errorcode'] parameter can be manipulated to access unauthorized error codes, leading to Cross-Site Scripting (XSS) attacks and information disclosure.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...