CVE tracker
312 subscribers
4.41K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-53765 - Azure Stack Information Disclosure Vulnerability

CVE ID : CVE-2025-53765
Published : Aug. 12, 2025, 6:15 p.m. | 23 minutes ago
Description : Exposure of private personal information to an unauthorized actor in Azure Stack allows an authorized attacker to disclose information locally.
Severity: 4.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-53766 - Windows GDI+ Heap-based Buffer Overflow

CVE ID : CVE-2025-53766
Published : Aug. 12, 2025, 6:15 p.m. | 23 minutes ago
Description : Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-53769 - Windows Security App Path Traversal Vulnerability

CVE ID : CVE-2025-53769
Published : Aug. 12, 2025, 6:15 p.m. | 23 minutes ago
Description : External control of file name or path in Windows Security App allows an authorized attacker to perform spoofing locally.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-53772 - Web Deploy Untrusted Data Deserialization Code Execution Vulnerability

CVE ID : CVE-2025-53772
Published : Aug. 12, 2025, 6:15 p.m. | 23 minutes ago
Description : Deserialization of untrusted data in Web Deploy allows an authorized attacker to execute code over a network.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-53773 - GitHub Copilot Command Injection Vulnerability

CVE ID : CVE-2025-53773
Published : Aug. 12, 2025, 6:15 p.m. | 23 minutes ago
Description : Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code locally.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-53778 - Microsoft Windows NTLM Privilege Escalation

CVE ID : CVE-2025-53778
Published : Aug. 12, 2025, 6:15 p.m. | 23 minutes ago
Description : Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-53779 - Microsoft Windows Kerberos Path Traversal Privilege Escalation

CVE ID : CVE-2025-53779
Published : Aug. 12, 2025, 6:15 p.m. | 23 minutes ago
Description : Relative path traversal in Windows Kerberos allows an authorized attacker to elevate privileges over a network.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-53781 - Azure Virtual Machines Information Exposure Vulnerability

CVE ID : CVE-2025-53781
Published : Aug. 12, 2025, 6:15 p.m. | 23 minutes ago
Description : Exposure of sensitive information to an unauthorized actor in Azure Virtual Machines allows an authorized attacker to disclose information over a network.
Severity: 7.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-53783 - Microsoft Teams Heap Buffer Overflow Remote Code Execution Vulnerability

CVE ID : CVE-2025-53783
Published : Aug. 12, 2025, 6:15 p.m. | 23 minutes ago
Description : Heap-based buffer overflow in Microsoft Teams allows an unauthorized attacker to execute code over a network.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-53784 - Microsoft Office Word Use After Free Remote Code Execution Vulnerability

CVE ID : CVE-2025-53784
Published : Aug. 12, 2025, 6:15 p.m. | 23 minutes ago
Description : Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-53788 - Windows Subsystem for Linux TOCTOU Privilege Escalation

CVE ID : CVE-2025-53788
Published : Aug. 12, 2025, 6:15 p.m. | 23 minutes ago
Description : Time-of-check time-of-use (toctou) race condition in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.
Severity: 7.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-53789 - Windows StateRepository API Local Privilege Escalation

CVE ID : CVE-2025-53789
Published : Aug. 12, 2025, 6:15 p.m. | 23 minutes ago
Description : Missing authentication for critical function in Windows StateRepository API allows an authorized attacker to elevate privileges locally.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-53793 - Azure Stack Authentication Bypass

CVE ID : CVE-2025-53793
Published : Aug. 12, 2025, 6:15 p.m. | 23 minutes ago
Description : Improper authentication in Azure Stack allows an unauthorized attacker to disclose information over a network.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-54207 - Adobe InDesign Uninitialized Pointer Code Execution Vulnerability

CVE ID : CVE-2025-54207
Published : Aug. 12, 2025, 9:15 p.m. | 1 hour, 1 minute ago
Description : InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-54208 - Adobe InDesign Out-of-Bounds Write Arbitrary Code Execution Vulnerability

CVE ID : CVE-2025-54208
Published : Aug. 12, 2025, 9:15 p.m. | 1 hour, 1 minute ago
Description : InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-54209 - Adobe InDesign Heap-based Buffer Overflow Vulnerability

CVE ID : CVE-2025-54209
Published : Aug. 12, 2025, 9:15 p.m. | 1 hour, 1 minute ago
Description : InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-54210 - Adobe InDesign Arbitrary Code Execution Vulnerability

CVE ID : CVE-2025-54210
Published : Aug. 12, 2025, 9:15 p.m. | 1 hour, 1 minute ago
Description : InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-54211 - Adobe InDesign Heap-based Buffer Overflow Vulnerability

CVE ID : CVE-2025-54211
Published : Aug. 12, 2025, 9:15 p.m. | 1 hour, 1 minute ago
Description : InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-54212 - Adobe InDesign Heap-based Buffer Overflow Vulnerability

CVE ID : CVE-2025-54212
Published : Aug. 12, 2025, 9:15 p.m. | 1 hour, 1 minute ago
Description : InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-54213 - Adobe InDesign Out-of-Bounds Write Arbitrary Code Execution Vulnerability

CVE ID : CVE-2025-54213
Published : Aug. 12, 2025, 9:15 p.m. | 1 hour, 1 minute ago
Description : InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-54214 - Adobe InDesign Out-of-Bounds Read Vulnerability

CVE ID : CVE-2025-54214
Published : Aug. 12, 2025, 9:15 p.m. | 1 hour, 1 minute ago
Description : InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...