Aggregator
CVE-2025-9394 | PoDoFo 1.1.0-dev PDF Dictionary Parser PdfTokenizer.cpp DetermineDataType use after free (275/276)
3 days 8 hours ago
A vulnerability labeled as critical has been found in PoDoFo 1.1.0-dev. This issue affects the function PdfTokenizer::DetermineDataType of the file src/podofo/main/PdfTokenizer.cpp of the component PDF Dictionary Parser. Executing manipulation can lead to use after free.
This vulnerability is handled as CVE-2025-9394. It is possible to launch the attack on the local host. Additionally, an exploit exists.
A patch should be applied to remediate this issue.
vuldb.com
Submit #632365: podofo podofoencrypt PoDoFo version 1.1.0-dev (commit 053cf47) compiled on Jul 30 2025 and the newest master version. Heap Use-After-Free [Duplicate]
3 days 9 hours ago
Submit #632365 / VDB-321227
xdcao
Submit #632364: podofo podofoencrypt PoDoFo version 1.1.0-dev (commit 053cf47) compiled on Jul 30 2025 and the newest master version. Heap Use-After-Free [Accepted]
3 days 9 hours ago
Submit #632364 / VDB-321227
xdcao
CVE-2025-9393 | Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 /goform/addStaProfile stack-based overflow (EUVD-2025-25650)
3 days 9 hours ago
A vulnerability identified as critical has been detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This vulnerability affects the function addStaProfile of the file /goform/addStaProfile. Performing manipulation of the argument profile_name/Ssid/wep_key_1/wep_key_2/wep_key_3/wep_key_4/wep_key_length/wep_default_key/cipher/passphrase results in stack-based buffer overflow.
This vulnerability is known as CVE-2025-9393. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2025-9392 | Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 /goform/qosClassifier stack-based overflow
3 days 9 hours ago
A vulnerability categorized as critical has been discovered in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This affects the function qosClassifier of the file /goform/qosClassifier. Such manipulation of the argument dir/sFromPort/sToPort/dFromPort/dToPort/protocol/layer7/dscp/remark_dscp leads to stack-based buffer overflow.
This vulnerability is traded as CVE-2025-9392. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
Submit #631538: Linksys RE6500、RE6250、RE6300、RE6350、RE7000、RE9000 RE6500(1.0.013.001) RE6250(1.0.04.001) RE6300(1.2.07.001) RE6350(1.0.04.001) RE7000(1.1.05.003) RE9000(1.0.04.002) Stack-based Buffer Overflow [Accepted]
3 days 9 hours ago
Submit #631538 / VDB-321226
pjq123
Submit #631537: Linksys RE6500、RE6250、RE6300、RE6350、RE7000、RE9000 RE6500(1.0.013.001) RE6250(1.0.04.001) RE6300(1.2.07.001) RE6350(1.0.04.001) RE7000(1.1.05.003) RE9000(1.0.04.002) Stack-based Buffer Overflow [Accepted]
3 days 9 hours ago
Submit #631537 / VDB-321225
pjq123
CVE-2025-9391 | Bjskzy Zhiyou ERP up to 11.0 com.artery.workflow.ServiceImpl getFieldValue sql sql injection (EUVD-2025-25649)
3 days 9 hours ago
A vulnerability was found in Bjskzy Zhiyou ERP up to 11.0. It has been rated as critical. Affected by this issue is the function getFieldValue of the component com.artery.workflow.ServiceImpl. This manipulation of the argument sql causes sql injection.
This vulnerability appears as CVE-2025-9391. The attack may be initiated remotely. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2025-9390 | vim up to 9.1.1615 xxd src/xxd/xxd.c main buffer overflow (Issue 17944)
3 days 9 hours ago
A vulnerability was found in vim up to 9.1.1615. It has been declared as critical. Affected by this vulnerability is the function main of the file src/xxd/xxd.c of the component xxd. The manipulation results in buffer overflow.
This vulnerability is reported as CVE-2025-9390. The attack requires a local approach. Moreover, an exploit is present.
It is recommended to upgrade the affected component.
vuldb.com
Submit #631536: Beijing ShiKong-ZhiYou Technology Co., Ltd. ShiKong-ZhiYou ERP 11.0 SQL Injection [Accepted]
3 days 9 hours ago
Submit #631536 / VDB-321224
nu11
Submit #630903: vim xxd vim-9.1.0000 and related xxd versions (latest master branch) Buffer Overflow [Accepted]
3 days 9 hours ago
Submit #630903 / VDB-321223
nipc-cxd
为前雇主 IT 系统设立关闭开关的开发者被判四年
3 days 9 hours ago
被裁前在前雇主 IT 系统植入恶意程序和设立关闭开关的开发者 Davis Lu 被判四年监禁以及三年的监督释放。美国司法部称,2018 年 Davis Lu 任职的 Eaton Corporation 进行了重组,他遭到了降级。他随后在公司 Windows 生产环境中植入恶意代码进行报复。该恶意程序包含了一个无限的 Java 线程循环,旨在拖垮服务器,导致生产系统崩溃。Lu 还创建了一个过于明显的关闭开关:IsDLEnabledinAD ("Is Davis Lu enabled in Active Directory") ,当 Active Directory 中他的账户被禁用,关闭开关将会激活禁用所有用户的账户。2019 年 9 月 9 日,Lu 的雇佣关系终止,账户被禁用后关闭开关激活,数千名用户被锁定在系统外。此事导致雇主损失了数十万美元。在 Lu 被要求上缴公司发的笔记本电脑前,他删除了其中的加密数据。调查人员后来从设备上发现了他的搜索查询记录,包括搜寻如何提权,隐藏进程以及快速删除文件。
CVE-2025-9389 | vim 9.1.0000 memmove-vec-unaligned-erms.S __memmove_avx_unaligned_erms memory corruption (Issue 17940)
3 days 9 hours ago
A vulnerability was found in vim 9.1.0000. It has been classified as problematic. Affected is the function __memmove_avx_unaligned_erms of the file memmove-vec-unaligned-erms.S. The manipulation leads to memory corruption.
This vulnerability is documented as CVE-2025-9389. The attack needs to be performed locally. Additionally, an exploit exists.
Some users are not able to reproduce this. One of the users mentions that this appears not to be working, "when coloring is turned on".
vuldb.com
Submit #630898: vim xxd vim-9.1.0000 and related xxd versions (latest master branch) Memory Corruption [Accepted]
3 days 9 hours ago
Submit #630898 / VDB-321222
CVE-2025-9388 | Scada-LTS up to 2.7.8.1 watch_list.shtm Name cross site scripting (EUVD-2025-25648)
3 days 9 hours ago
A vulnerability was found in Scada-LTS up to 2.7.8.1 and classified as problematic. This impacts an unknown function of the file watch_list.shtm. Executing manipulation of the argument Name can lead to cross site scripting.
This vulnerability is registered as CVE-2025-9388. It is possible to launch the attack remotely. Furthermore, an exploit is available.
vuldb.com
FTC warns tech giants not to bow to foreign pressure on encryption
3 days 9 hours ago
The Federal Trade Commission (FTC) is warning major U.S. tech companies against yielding to foreign government demands that weaken data security, compromise encryption, or impose censorship on their platforms. [...]
Bill Toulas
CVE-2025-9387 | DCN DCME-720 9.1.5.11 Web Management Backend ip_block.php ip os command injection
3 days 9 hours ago
A vulnerability has been found in DCN DCME-720 9.1.5.11 and classified as critical. This affects an unknown function of the file /usr/local/www/function/audit/newstatistics/ip_block.php of the component Web Management Backend. Performing manipulation of the argument ip results in os command injection.
This vulnerability is cataloged as CVE-2025-9387. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
Other products might be affected as well. The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
Submit #630800: Scada-LTS 2.7.8.1 Cross Site Scripting (XSS) Stored [Accepted]
3 days 9 hours ago
Submit #630800 / VDB-321221
marceloQz
Submit #630727: DCN DCME-720 9.1.5.11 Command Injection [Accepted]
3 days 9 hours ago
Submit #630727 / VDB-321220
QMSSDXN