CVE-2018-9384 – VMware Hypervisor KASLR Bypass Information Disclosure Vulnerability
CVE ID : CVE-2018-9384 Published : Jan. 17, 2025, 11:15 p.m. | 31 minutes ago Description : In multiple locations, there is a possible way to bypass KASLR due to an unusual root cause. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Severity: 0.0 | […]
CVE-2018-9379 – Apache MiniThumb Local Information Disclosure Vulnerability
The following table lists the changes that have been made to the CVE-2018-9379 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 17, 2025 Action […]
CVE-2018-9375 – Apache OpenNLP Privilege Escalation Vulnerability
The following table lists the changes that have been made to the CVE-2018-9375 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 17, 2025 Action […]
CVE-2018-9382 – Android WifiService Unauthorized Hotspot Activation
The following table lists the changes that have been made to the CVE-2018-9382 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 17, 2025 Action […]
CVE-2017-13322 – Cisco Phones Denial of Service Vulnerability
The following table lists the changes that have been made to the CVE-2017-13322 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 17, 2025 Action […]
CVE-2025-23207 – KaTeX HTML Injection Vulnerability
The following table lists the changes that have been made to the CVE-2025-23207 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 17, 2025 Action […]
CVE-2025-0541 – Codezips Gym Management System SQL Injection Vulnerability
The following table lists the changes that have been made to the CVE-2025-0541 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 17, 2025 Action […]
CVE-2025-23206 – AWS CDK IAM OIDC Unverified Connections Weakness
The AWS Cloud Development Kit (AWS CDK) is an open-source software development framework to define cloud infrastructure in code and provision it through AWS CloudFormation. Users who use IAM OIDC custom resource provider package will download CA Thumbprints as part of the custom resource workflow. However, the current `tls.connect` method will always set `rejectUnauthorized: false` […]
CVE-2025-23205 – JupyterHub nbgrader Frame Ancestor Hack
nbgrader is a system for assigning and grading notebooks. Enabling frame-ancestors: ‘self’ grants any JupyterHub user the ability to extract formgrader content by sending malicious links to users with access to formgrader, at least when using the default JupyterHub configuration of `enable_subdomains = False`. #1915 disables a protection which would allow user Alice to craft […]
CVE-2025-23202 – ROBLOX Bible Module API Injection Vulnerability
The following table lists the changes that have been made to the CVE-2025-23202 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 17, 2025 Action […]