🚨 CVE-2025-31963
Improper authentication and missing CSRF protection in the local setup interface component in HCL BigFix IVR version 4.2 allows a local attacker to perform unauthorized configuration changes via unauthenticated administrative configuration requests.
🎖@cveNotify
Improper authentication and missing CSRF protection in the local setup interface component in HCL BigFix IVR version 4.2 allows a local attacker to perform unauthorized configuration changes via unauthenticated administrative configuration requests.
🎖@cveNotify
Hcl-Software
Security Bulletin: HCL BigFix IVR is impacted by multiple security vulnerabilities - Customer Support
HCL BigFix IVR is impacted by multiple security vulnerabilities due to insufficient session expiration,
🚨 CVE-2025-31964
Improper service binding configuration in internal service components in HCL BigFix IVR version 4.2 allows a privileged attacker to impact service availability via exposure of administrative services bound to external network interfaces instead of the local authentication interface.
🎖@cveNotify
Improper service binding configuration in internal service components in HCL BigFix IVR version 4.2 allows a privileged attacker to impact service availability via exposure of administrative services bound to external network interfaces instead of the local authentication interface.
🎖@cveNotify
Hcl-Software
Security Bulletin: HCL BigFix IVR is impacted by multiple security vulnerabilities - Customer Support
HCL BigFix IVR is impacted by multiple security vulnerabilities due to insufficient session expiration,
🚨 CVE-2025-32300
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Digital zoom studio DZS Video Gallery allows Reflected XSS.This issue affects DZS Video Gallery: from n/a through 12.25.
🎖@cveNotify
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Digital zoom studio DZS Video Gallery allows Reflected XSS.This issue affects DZS Video Gallery: from n/a through 12.25.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress DZS Video Gallery Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
🚨 CVE-2025-47330
Transient DOS while parsing video packets received from the video firmware.
🎖@cveNotify
Transient DOS while parsing video packets received from the video firmware.
🎖@cveNotify
🚨 CVE-2025-47333
Memory corruption while handling buffer mapping operations in the cryptographic driver.
🎖@cveNotify
Memory corruption while handling buffer mapping operations in the cryptographic driver.
🎖@cveNotify
🚨 CVE-2025-47334
Memory corruption while processing shared command buffer packet between camera userspace and kernel.
🎖@cveNotify
Memory corruption while processing shared command buffer packet between camera userspace and kernel.
🎖@cveNotify
🚨 CVE-2025-47335
Memory corruption while parsing clock configuration data for a specific hardware type.
🎖@cveNotify
Memory corruption while parsing clock configuration data for a specific hardware type.
🎖@cveNotify
🚨 CVE-2025-47337
Memory corruption while accessing a synchronization object during concurrent operations.
🎖@cveNotify
Memory corruption while accessing a synchronization object during concurrent operations.
🎖@cveNotify
🚨 CVE-2025-47343
Memory corruption while processing a video session to set video parameters.
🎖@cveNotify
Memory corruption while processing a video session to set video parameters.
🎖@cveNotify
🚨 CVE-2025-47346
Memory corruption while processing a secure logging command in the trusted application.
🎖@cveNotify
Memory corruption while processing a secure logging command in the trusted application.
🎖@cveNotify
🚨 CVE-2025-47356
Memory Corruption when multiple threads concurrently access and modify shared resources.
🎖@cveNotify
Memory Corruption when multiple threads concurrently access and modify shared resources.
🎖@cveNotify
🚨 CVE-2025-47369
Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID.
🎖@cveNotify
Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID.
🎖@cveNotify
🚨 CVE-2025-47388
Memory corruption while passing pages to DSP with an unaligned starting address.
🎖@cveNotify
Memory corruption while passing pages to DSP with an unaligned starting address.
🎖@cveNotify
🚨 CVE-2025-47394
Memory corruption when copying overlapping buffers during memory operations due to incorrect offset calculations.
🎖@cveNotify
Memory corruption when copying overlapping buffers during memory operations due to incorrect offset calculations.
🎖@cveNotify