1641
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The vulnerability was found in OpenShift Service Mesh 2.6.3 and 2.5.6. This issue occurs due to improper sanitization of HTTP headers by Envoy, particularly the x-forwarded-for header. This lack of s…
|
CWE-117
Improper Output Neutralization for Logs
|
CVE-2025-0754
|
2025-01-28 19:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1642
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A flaw was found in OpenShift Service Mesh 2.6.3 and 2.5.6. Rate-limiter avoidance, access-control bypass, CPU and memory exhaustion, and replay attacks may be possible due to improper HTTP header sa…
|
CWE-444
HTTP Request Smuggling
|
CVE-2025-0752
|
2025-01-28 19:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1643
|
6.6 |
MEDIUM
Local
|
-
|
-
|
A vulnerability was found in CRI-O. A path traversal issue in the log management functions (UnMountPodLogs and LinkContainerLogs) may allow an attacker with permissions to create and delete Pods to u…
|
CWE-22
Path Traversal
|
CVE-2025-0750
|
2025-01-28 19:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1644
|
5.5 |
MEDIUM
Local
|
-
|
-
|
A flaw was found in Infinispan, when using JGroups with JDBC_PING. This issue occurs when an application inadvertently exposes sensitive information, such as configuration details or credentials, thr…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2025-0736
|
2025-01-28 18:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1645
|
- |
|
-
|
-
|
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.0 prior to 17.5.5, from 17.6 prior to 17.6.3, and from 17.7 prior to 17.7.1. Under certain conditions, processing …
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2025-0290
|
2025-01-28 18:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1646
|
- |
|
-
|
-
|
Cross-site scripting vulnerability exists in Simple Image Sizes 3.2.3 and earlier. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is loggin…
|
CWE-79
Cross-site Scripting
|
CVE-2025-24810
|
2025-01-28 14:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1647
|
- |
|
-
|
-
|
NVIDIA vGPU software contains a vulnerability in the host driver, where it can allow a guest to cause an interrupt storm on the host, which may lead to denial of service.
|
CWE-459
Incomplete Cleanup
|
CVE-2024-53881
|
2025-01-28 13:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1648
|
- |
|
-
|
-
|
NVIDIA Unified Memory driver for Linux contains a vulnerability where an attacker could leak uninitialized memory. A successful exploit of this vulnerability might lead to information disclosure.
|
CWE-459
Incomplete Cleanup
|
CVE-2024-53869
|
2025-01-28 13:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1649
|
- |
|
-
|
-
|
NVIDIA GPU display driver for Windows and Linux contains a vulnerability where data is written past the end or before the beginning of a buffer. A successful exploit of this vulnerability might lead …
|
CWE-787
Out-of-bounds Write
|
CVE-2024-0150
|
2025-01-28 13:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1650
|
- |
|
-
|
-
|
NVIDIA GPU Display Driver for Linux contains a vulnerability which could allow an attacker unauthorized access to files. A successful exploit of this vulnerability might lead to limited information d…
|
CWE-125
Out-of-bounds Read
|
CVE-2024-0149
|
2025-01-28 13:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|