Aggregator
CVE-2025-44172 | Tenda AC6 15.03.05.16 setSmartPowerManagement Time stack-based overflow (EUVD-2025-16664)
CVE-2025-37096 | HPE StoreOnce Software up to 4.3.10 command injection
CVE-2024-54028 | catdoc 0.95 OLE Document DIFAT Parser integer underflow (TALOS-2024-2132 / EUVD-2024-54622)
CVE-2024-52035 | catdoc 0.95 OLE Document File Allocation Table Parser integer overflow (TALOS-2024-2131)
CVE-2024-48877 | xls2csv 0.95 Shared String Table Record Parser integer overflow to buffer overflow (TALOS-2024-2128 / EUVD-2024-54625)
CVE-2025-20001 | High-Logic FontCreator 15.0.0.3015 Font File out-of-bounds (TALOS-2025-2157 / EUVD-2025-16663)
CVE-2024-28995 | SolarWinds Serv-U up to 15.4.2 HF 1 path traversal (EDB-52311)
2nd June – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 2nd June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES IT management software company ConnectWise confirmed that a sophisticated nation-state cyberattack had compromised its environment, affecting a limited number of customers using its ScreenConnect remote access tool. The company launched a forensic […]
The post 2nd June – Threat Intelligence Report appeared first on Check Point Research.
MediaTek Vulnerabilities Let Attackers Escalate Privileges Without User Interaction
Multiple critical security vulnerabilities affecting MediaTek smartphones, tablets, and IoT chipsets could allow attackers to escalate privileges and compromise device security without requiring any user interaction. The Taiwan-based chipset manufacturer published its June 2025 Product Security Bulletin, revealing seven Common Vulnerabilities and Exposures (CVEs) with severity ratings from high to medium severity, according to CVSS […]
The post MediaTek Vulnerabilities Let Attackers Escalate Privileges Without User Interaction appeared first on Cyber Security News.