VulDB Updates Updates
- CVE-2024-5953 | 389-ds-base Hash userPassword denial of service (EUVD-2024-47135 / Nessus ID 207920)by vuldb.com on July 5, 2025 at 7:35 am
A vulnerability classified as problematic was found in 389-ds-base. This vulnerability affects unknown code of the component Hash Handler. The manipulation of the argument userPassword leads to denial of service. This vulnerability was named CVE-2024-5953. The attack can be initiated remotely. There is no exploit available.
- CVE-2024-5148 | GNOME gnome-remote-desktop Session Agent information disclosure (EUVD-2024-47138)by vuldb.com on July 5, 2025 at 7:35 am
A vulnerability classified as problematic has been found in GNOME gnome-remote-desktop. Affected is an unknown function of the component Session Agent Handler. The manipulation leads to information disclosure. This vulnerability is traded as CVE-2024-5148. An attack has to be approached locally. There is no exploit available.
- CVE-2024-9979 | PyO3 up to 0.22.3 Reference use after free (EUVD-2024-2969)by vuldb.com on July 5, 2025 at 7:35 am
A vulnerability has been found in PyO3 up to 0.22.3 and classified as problematic. This vulnerability affects unknown code of the component Reference Handler. The manipulation leads to use after free. This vulnerability was named CVE-2024-9979. The attack needs to be initiated within the local network. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2025-0678 | GNU grub2 squash4 out-of-bounds write (EUVD-2025-5569 / Nessus ID 216508)by vuldb.com on July 5, 2025 at 7:35 am
A vulnerability classified as critical was found in GNU grub2. Affected by this vulnerability is an unknown functionality of the component squash4. The manipulation leads to out-of-bounds write. This vulnerability is known as CVE-2025-0678. Attacking locally is a requirement. There is no exploit available.
- CVE-2025-0684 | GNU grub2 reiserfs out-of-bounds write (EUVD-2025-5572 / Nessus ID 216508)by vuldb.com on July 5, 2025 at 7:35 am
A vulnerability, which was classified as critical, has been found in GNU grub2. Affected by this issue is some unknown functionality of the component reiserfs. The manipulation leads to out-of-bounds write. This vulnerability is handled as CVE-2025-0684. It is possible to launch the attack on the local host. There is no exploit available.
- CVE-2025-0685 | GNU grub2 jfs Filesystem out-of-bounds write (EUVD-2025-5577 / Nessus ID 216508)by vuldb.com on July 5, 2025 at 7:34 am
A vulnerability, which was classified as critical, was found in GNU grub2. This affects an unknown part of the component jfs Filesystem Handler. The manipulation leads to out-of-bounds write. This vulnerability is uniquely identified as CVE-2025-0685. The attack needs to be approached locally. There is no exploit available.
- CVE-2025-1057 | Keylime 7.12.0 Database Entry denial of service (EUVD-2025-4900)by vuldb.com on July 5, 2025 at 7:34 am
A vulnerability, which was classified as problematic, was found in Keylime 7.12.0. This affects an unknown part of the component Database Entry Handler. The manipulation leads to denial of service. This vulnerability is uniquely identified as CVE-2025-1057. Access to the local network is required for this attack to succeed. There is no exploit available.
- CVE-2025-0686 | GNU grub2 romfs out-of-bounds write (EUVD-2025-5576 / Nessus ID 216508)by vuldb.com on July 5, 2025 at 7:34 am
A vulnerability has been found in GNU grub2 and classified as critical. This vulnerability affects unknown code of the component romfs. The manipulation leads to out-of-bounds write. This vulnerability was named CVE-2025-0686. An attack has to be approached locally. There is no exploit available.
- CVE-2025-0689 | GNU grub2 udf grub_udf_read_block heap-based overflow (EUVD-2025-5596 / Nessus ID 216508)by vuldb.com on July 5, 2025 at 7:34 am
A vulnerability was found in GNU grub2 and classified as critical. This issue affects the function grub_udf_read_block of the component udf. The manipulation leads to heap-based buffer overflow. The identification of this vulnerability is CVE-2025-0689. Local access is required to approach this attack. There is no exploit available.
- CVE-2025-1125 | GNU grub2 hfs out-of-bounds write (EUVD-2025-5597 / Nessus ID 216508)by vuldb.com on July 5, 2025 at 7:34 am
A vulnerability was found in GNU grub2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component hfs. The manipulation leads to out-of-bounds write. This vulnerability is known as CVE-2025-1125. It is possible to launch the attack on the local host. There is no exploit available.
- CVE-2006-1504 | Arab Portal download.php Title cross site scripting (EDB-27501 / XFDB-25515)by vuldb.com on July 5, 2025 at 7:11 am
A vulnerability has been found in Arab Portal and classified as problematic. This vulnerability affects unknown code of the file download.php. The manipulation of the argument Title leads to basic cross site scripting. This vulnerability was named CVE-2006-1504. The attack can be initiated remotely. Furthermore, there is an exploit available.
- CVE-2025-53485 | SecurePoll Extension up to 1.39.12/1.42.6/1.43.1 on Mediawiki SetTranslationHandler.php authorization (EUVD-2025-20087)by vuldb.com on July 5, 2025 at 6:01 am
A vulnerability classified as critical was found in SecurePoll Extension up to 1.39.12/1.42.6/1.43.1 on Mediawiki. This vulnerability affects unknown code of the file SetTranslationHandler.php. The manipulation leads to missing authorization. This vulnerability was named CVE-2025-53485. The attack can be initiated remotely. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2025-53484 | SecurePoll Extension up to 1.39.12/1.42.6/1.43.1 on Mediawiki VotePage.php ResultPage::getPagesTab cross site scripting (EUVD-2025-20088)by vuldb.com on July 5, 2025 at 6:01 am
A vulnerability has been found in SecurePoll Extension up to 1.39.12/1.42.6/1.43.1 on Mediawiki and classified as problematic. Affected by this vulnerability is the function ResultPage::getPagesTab of the file VotePage.php. The manipulation leads to cross site scripting. This vulnerability is known as CVE-2025-53484. The attack can be launched remotely. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2025-53483 | SecurePoll Extension up to 1.39.12/1.42.6/1.43.1 on Mediawiki ArchivePage.php executeClear cross-site request forgery (EUVD-2025-20085)by vuldb.com on July 5, 2025 at 6:01 am
A vulnerability was found in SecurePoll Extension up to 1.39.12/1.42.6/1.43.1 on Mediawiki and classified as problematic. Affected by this issue is the function executeClear of the file ArchivePage.php. The manipulation leads to cross-site request forgery. This vulnerability is handled as CVE-2025-53483. The attack may be launched remotely. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2025-53365 | modelcontextprotocol python-sdk up to 1.9.x uncaught exception (GHSA-j975-95f5-7wqh / EUVD-2025-20094)by vuldb.com on July 5, 2025 at 6:01 am
A vulnerability classified as problematic has been found in modelcontextprotocol python-sdk up to 1.9.x. Affected is an unknown function. The manipulation leads to uncaught exception. This vulnerability is traded as CVE-2025-53365. It is possible to launch the attack remotely. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2025-53602 | Zipkin up to 3.5.1 Spring Boot Actuator /heapdump insecure default initialization of resource (EUVD-2025-20090)by vuldb.com on July 5, 2025 at 6:01 am
A vulnerability, which was classified as problematic, was found in Zipkin up to 3.5.1. This affects an unknown part of the file /heapdump of the component Spring Boot Actuator. The manipulation leads to insecure default initialization of resource. This vulnerability is uniquely identified as CVE-2025-53602. It is possible to initiate the attack remotely. There is no exploit available. It is recommended to apply a patch to fix this issue.
- CVE-2025-53603 | Alinto SOPE SOGo up to 5.12.2 Query String NGHashMap.m null pointer dereference (EUVD-2025-20097)by vuldb.com on July 5, 2025 at 6:01 am
A vulnerability, which was classified as problematic, has been found in Alinto SOPE SOGo up to 5.12.2. Affected by this issue is some unknown functionality of the file sope-core/NGExtensions/NGHashMap.m of the component Query String Handler. The manipulation leads to null pointer dereference. This vulnerability is handled as CVE-2025-53603. The attack may be launched remotely. There is no exploit available. It is recommended to apply a patch to fix this issue.
- CVE-2008-5283 | GHH Google Hack Honeypot File Upload Manager 1.3 index.php access control (EDB-31239 / BID-27877)by vuldb.com on July 5, 2025 at 5:54 am
A vulnerability, which was classified as critical, was found in GHH Google Hack Honeypot File Upload Manager 1.3. This affects an unknown part of the file index.php of the component File Upload. The manipulation leads to improper access controls. This vulnerability is uniquely identified as CVE-2008-5283. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
- CVE-2025-53366 | modelcontextprotocol python-sdk up to 1.9.3 uncaught exception (GHSA-3qhf-m339-9g5v / EUVD-2025-20093)by vuldb.com on July 5, 2025 at 5:46 am
A vulnerability, which was classified as problematic, has been found in modelcontextprotocol python-sdk up to 1.9.3. This issue affects some unknown processing. The manipulation leads to uncaught exception. The identification of this vulnerability is CVE-2025-53366. The attack may be initiated remotely. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2025-48952 | jokob-sk NetAlertX up to 25.6.6 front/index.php comparison (GHSA-4p4p-vq2v-9489 / EUVD-2025-20092)by vuldb.com on July 5, 2025 at 5:46 am
A vulnerability, which was classified as critical, was found in jokob-sk NetAlertX up to 25.6.6. Affected is an unknown function of the file front/index.php. The manipulation leads to incorrect comparison. This vulnerability is traded as CVE-2025-48952. It is possible to launch the attack remotely. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2025-43711 | Tunnelblick up to 6.x Uninstall Tunnelblick.app cleanup (EUVD-2025-20098)by vuldb.com on July 5, 2025 at 5:46 am
A vulnerability was found in Tunnelblick up to 6.x. It has been declared as critical. This vulnerability affects unknown code of the file Tunnelblick.app of the component Uninstall. The manipulation leads to incomplete cleanup. This vulnerability was named CVE-2025-43711. The attack needs to be approached locally. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2025-47227 | Netmake ScriptCase up to 9.12.006 (23) Production Environment Extension login.php.is incorrect provision of specified functionality (EUVD-2025-20102)by vuldb.com on July 5, 2025 at 5:46 am
A vulnerability was found in Netmake ScriptCase up to 9.12.006 (23). It has been rated as problematic. This issue affects some unknown processing of the file login.php.is of the component Production Environment Extension. The manipulation leads to incorrect provision of specified functionality. The identification of this vulnerability is CVE-2025-47227. The attack may be initiated remotely. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2025-26850 | Quest KACE Systems Management Appliance up to 14.0.96/14.1.18 Agent authorization (EUVD-2025-20096)by vuldb.com on July 5, 2025 at 5:46 am
A vulnerability has been found in Quest KACE Systems Management Appliance up to 14.0.96/14.1.18 and classified as critical. This vulnerability affects unknown code of the component Agent. The manipulation leads to incorrect authorization. This vulnerability was named CVE-2025-26850. An attack has to be approached locally. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2025-53605 | stepancheg protobuf up to 3.7.1 coded_input_stream recursion (Issue 749 / EUVD-2025-20099)by vuldb.com on July 5, 2025 at 5:46 am
A vulnerability was found in stepancheg protobuf up to 3.7.1 and classified as problematic. This issue affects the function protobuf::coded_input_stream. The manipulation leads to uncontrolled recursion. The identification of this vulnerability is CVE-2025-53605. The attack may be initiated remotely. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2025-53604 | pimeys web-push Crate up to 0.10.2 on Rust length parameter (RUSTSEC-2025-0015 / EUVD-2025-20100)by vuldb.com on July 5, 2025 at 5:46 am
A vulnerability was found in pimeys web-push Crate up to 0.10.2 on Rust. It has been classified as problematic. Affected is an unknown function. The manipulation leads to improper handling of length parameter inconsistency. This vulnerability is traded as CVE-2025-53604. It is possible to launch the attack remotely. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2023-50786 | Dradis up to 4.16.0 Image Parser authentication replay (EUVD-2023-55519)by vuldb.com on July 5, 2025 at 5:46 am
A vulnerability was found in Dradis up to 4.16.0. It has been classified as critical. This affects an unknown part of the component Image Parser. The manipulation leads to authentication bypass by capture-replay. This vulnerability is uniquely identified as CVE-2023-50786. The attack needs to be approached within the local network. There is no exploit available.
- CVE-2025-47228 | Netmake ScriptCase up to 9.12.006 (23) Production Environment Extension os command injection (EUVD-2025-20101)by vuldb.com on July 5, 2025 at 5:46 am
A vulnerability classified as critical was found in Netmake ScriptCase up to 9.12.006 (23). Affected by this vulnerability is an unknown functionality of the component Production Environment Extension. The manipulation leads to os command injection. This vulnerability is known as CVE-2025-47228. The attack can be launched remotely. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2017-2364 | Apple Safari up to 10.0.2 WebKit Frame::setDocument information disclosure (HT207484 / EDB-41799)by vuldb.com on July 5, 2025 at 5:31 am
A vulnerability classified as problematic was found in Apple Safari up to 10.0.2. This vulnerability affects the function Frame::setDocument of the component WebKit. The manipulation leads to information disclosure. This vulnerability was named CVE-2017-2364. The attack can be initiated remotely. Furthermore, there is an exploit available. It is recommended to upgrade the affected component.
- CVE-2002-1359 | PuTTY 0.48/0.49/0.53 Large Value input validation (EDB-16463 / Nessus ID 48968)by vuldb.com on July 5, 2025 at 5:24 am
A vulnerability, which was classified as critical, was found in PuTTY 0.48/0.49/0.53. This affects an unknown part of the component Large Value Handler. The manipulation leads to improper input validation. This vulnerability is uniquely identified as CVE-2002-1359. It is possible to initiate the attack remotely. Furthermore, there is an exploit available. It is recommended to apply a patch to fix this issue.
- CVE-2004-1707 | Oracle Application Server Portal 9.0.2.0.1 dbsnmp/nmo privileges management (EDB-24335 / Nessus ID 57619)by vuldb.com on July 5, 2025 at 5:15 am
A vulnerability, which was classified as problematic, was found in Oracle Application Server Portal 9.0.2.0.1. Affected is an unknown function of the component dbsnmp/nmo. The manipulation leads to improper privilege management. This vulnerability is traded as CVE-2004-1707. The attack needs to be approached locally. Furthermore, there is an exploit available.