TheCyberThrone Security Weekly Review – February 08, 2025

TheCyberThrone Security Weekly Review – February 08, 2025 Welcome to TheCyberThrone  cybersecurity week in review will be posted covering the important security happenings. This review is for the week ending Saturday, February 08, 2025.CVE-2025-21293 PoC Exp … Read more Published Date: Feb 09, 2025 (2 hours, 37 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-23419 CVE-2025-24503 CVE-2025-21293 CVE-2024-51741 […]

CVE-2025-21685 – Lenovo Yoga Tab 2 Pro 1380 Fastcharger Serdev NULL Pointer Dereference Vulnerability

The following table lists the changes that have been made to the CVE-2025-21685 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Feb. 09, 2025 Action […]

CVE-2025-21684 – Xilinx GPIO Lock Violation Vulnerability

In the Linux kernel, the following vulnerability has been resolved: gpio: xilinx: Convert gpio_lock to raw spinlock irq_chip functions may be called in raw spinlock context. Therefore, we must also use a raw spinlock for our own internal locking. This fixes the following lockdep splat: [ 5.349336] ============================= [ 5.353349] [ BUG: Invalid wait context […]

CVE-2024-57949 – Linux kernel GIC-v3-its Infinite Recursion Vulnerability

The following table lists the changes that have been made to the CVE-2024-57949 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Feb. 09, 2025 Action […]

Week in review: Exploited 7-Zip 0-day flaw, crypto-stealing malware found on App Store, Google Play

Week in review: Exploited 7-Zip 0-day flaw, crypto-stealing malware found on App Store, Google Play Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Russian cybercrooks exploiting 7-Zip zero-day vulnerability (CVE-2025-0411) CVE-2025-0411, a Mark-of-t … Read more Published Date: Feb 09, 2025 (1 hour, 59 minutes ago) Vulnerabilities has been mentioned […]

CVE-2024-13440 – WordPress Super Store Finder Unauthenticated SQL Injection

CVE ID : CVE-2024-13440 Published : Feb. 9, 2025, 5:15 a.m. | 1 hour, 29 minutes ago Description : The Super Store Finder plugin for WordPress is vulnerable to SQL Injection via the ‘ssf_wp_user_name’ parameter in all versions up to, and including, 7.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation […]

Fixing stdlib 1.18.2 Vulnerabilities in Docker Images: A PostgreSQL Implementation Guide

Fixing stdlib 1.18.2 Vulnerabilities in Docker Images: A PostgreSQL Implementation Guide IntroductionInformation from Docker Hub on PostgreSQL Docker Official Image as you can see on the image below [1].[1] Informations based on docker official imageAs you know that Docker official images … Read more Published Date: Feb 09, 2025 (1 hour, 51 minutes ago) Vulnerabilities has been […]