CVE tracker
280 subscribers
3.79K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-8677 - Resource exhaustion via malformed DNSKEY handling

CVE ID : CVE-2025-8677
Published : Oct. 22, 2025, 4:15 p.m. | 50 minutes ago
Description : Querying for records within a specially crafted zone containing certain malformed DNSKEY records can lead to CPU exhaustion. This issue affects BIND 9 versions 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22175 - Jira Align Authorization Bypass

CVE ID : CVE-2025-22175
Published : Oct. 22, 2025, 4:30 p.m. | 36 minutes ago
Description : Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to modify the steps of another user's private checklist.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22177 - Jira Align Authorization Bypass

CVE ID : CVE-2025-22177
Published : Oct. 22, 2025, 4:30 p.m. | 36 minutes ago
Description : Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view other team overviews.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22168 - Atlassian Jira Align Authorization Bypass

CVE ID : CVE-2025-22168
Published : Oct. 22, 2025, 4:30 p.m. | 36 minutes ago
Description : Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to read the steps of another user's private checklist.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22171 - Jira Align Authorization Bypass

CVE ID : CVE-2025-22171
Published : Oct. 22, 2025, 4:30 p.m. | 36 minutes ago
Description : Jira Align is vulnerable to an authorization issue. A low-privilege user is able to alter the private checklists of other users.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22176 - Jira Align Authorization Bypass

CVE ID : CVE-2025-22176
Published : Oct. 22, 2025, 4:30 p.m. | 36 minutes ago
Description : Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view audit log items.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22172 - "Atlassian Jira Align Authorization Bypass"

CVE ID : CVE-2025-22172
Published : Oct. 22, 2025, 4:30 p.m. | 36 minutes ago
Description : Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to read external reports without the required permission.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22174 - Jira Align Authorization Bypass

CVE ID : CVE-2025-22174
Published : Oct. 22, 2025, 4:30 p.m. | 36 minutes ago
Description : Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view portfolio rooms without the required permission.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22170 - Jira Align Privilege Escalation Authorization Bypass

CVE ID : CVE-2025-22170
Published : Oct. 22, 2025, 4:30 p.m. | 36 minutes ago
Description : Jira Align is vulnerable to an authorization issue. A low-privilege user without sufficient privileges to perform an action could if they included a particular state-related parameter of a user with sufficient privileges to perform the action.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22173 - Jira Align Authorization Bypass

CVE ID : CVE-2025-22173
Published : Oct. 22, 2025, 4:30 p.m. | 36 minutes ago
Description : Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view certain sprint data without the required permission.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22169 - Jira Align Authorization Bypass

CVE ID : CVE-2025-22169
Published : Oct. 22, 2025, 4:30 p.m. | 36 minutes ago
Description : Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to subscribe to an item/object without having the expected permission level.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22178 - Jira Align Information Disclosure Authorization Bypass

CVE ID : CVE-2025-22178
Published : Oct. 22, 2025, 4:30 p.m. | 36 minutes ago
Description : Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view items on the "Why" page.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-24934 - SO_REUSEPORT_LB breaks connect(2) for UDP sockets

CVE ID : CVE-2025-24934
Published : Oct. 22, 2025, 6:15 p.m. | 2 hours, 52 minutes ago
Description : Software which sets SO_REUSEPORT_LB on a socket and then connects it to a host will not directly observe any problems. However, due to its membership in a load-balancing group, that socket will receive packets originating from any host. This breaks the contract of the connect(2) and implied connect via sendto(2), and may leave the application vulnerable to spoofing attacks. The kernel failed to check the connection state of sockets when adding them to load-balancing groups. Furthermore, when looking up the destination socket for an incoming packet, the kernel will match a socket belonging to a load-balancing group even if it is connected, in violation of the contract that connected sockets are only supposed to receive packets originating from the connected host.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-60336 - TOTOLINK N600R NULL Pointer Dereference DoS Vulnerability

CVE ID : CVE-2025-60336
Published : Oct. 22, 2025, 6:15 p.m. | 2 hours, 52 minutes ago
Description : A NULL pointer dereference in the sub_41773C function of TOTOLINK N600R v4.3.0cu.7866_B20220506 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-60337 - Tenda AC6 Buffer Overflow DoS

CVE ID : CVE-2025-60337
Published : Oct. 22, 2025, 6:15 p.m. | 2 hours, 52 minutes ago
Description : Tenda AC6 V2.0 15.03.06.50 was discovered to contain a buffer overflow in the speed_dir parameter in the SetSpeedWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-60339 - Tenda AC6 Buffer Overflow Vulnerability

CVE ID : CVE-2025-60339
Published : Oct. 22, 2025, 6:15 p.m. | 2 hours, 52 minutes ago
Description : Multiple buffer overflow vulnerabilities in the openSchedWifi function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial of Service (DoS) via injecting a crafted payload into the schedStartTime and schedEndTime parameters.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-60340 - Tenda AC6 Buffer Overflows

CVE ID : CVE-2025-60340
Published : Oct. 22, 2025, 6:15 p.m. | 2 hours, 52 minutes ago
Description : Multiple buffer overflows in the SetClientState function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial of Service (DoS) via injecting a crafted payload into the limitSpeed, deviceId, and limitSpeedUp parameters.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-60341 - Tenda AC6 Stack Overflow Denial of Service

CVE ID : CVE-2025-60341
Published : Oct. 22, 2025, 6:15 p.m. | 2 hours, 52 minutes ago
Description : Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the ssid parameter in the fast_setting_wifi_set function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-60342 - Tenda AC6 Stack Overflow Vulnerability

CVE ID : CVE-2025-60342
Published : Oct. 22, 2025, 6:15 p.m. | 2 hours, 52 minutes ago
Description : Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the page parameter in the addressNat function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-60343 - Tenda AC6 Buffer Overflow Denial of Service

CVE ID : CVE-2025-60343
Published : Oct. 22, 2025, 6:15 p.m. | 2 hours, 52 minutes ago
Description : Multiple buffer overflows in the AdvSetMacMtuWan function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial of Service (DoS) via injecting a crafted payload into the wanMTU, wanSpeed, cloneType, mac, serviceName, serverName, wanMTU2, wanSpeed2, cloneType2, mac2, serviceName2, and serverName2 parameters.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-58712 - Amq: privilege escalation via excessive /etc/passwd permissions

CVE ID : CVE-2025-58712
Published : Oct. 22, 2025, 7:15 p.m. | 1 hour, 52 minutes ago
Description : A container privilege escalation flaw was found in certain AMQ Broker images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root user, can leverage their membership in the root group to modify the /etc/passwd file. This could allow the attacker to add a new user with any arbitrary UID, including UID 0, leading to full root privileges within the container.
Severity: 5.2 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...