Year Archive: 2025

EUVD Vulnerabilities (2025)

Browse security threats, CVE catalog items, and software security flaws mapped under the EUVD sequence for the year 2025.

CRITICAL (10) CVSS 3.1 Source: ibm

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and u...

Aliases:
CVE-2025-15399 GHSA-2vwg-4434-qc95
Published: 2026-09-18 View Complete Profile →
CRITICAL (10) CVSS 3.1 Source: redhat

A flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration packets are passed to a shell without proper validation or escaping. Unsanitized NetBIOS name data from ...

Aliases:
CVE-2025-10230 GHSA-88qg-f543-x242
Published: 2025-11-07 View Complete Profile →

EUVD-2025-34068

Actively Exploited
HIGH (7.8) CVSS 3.1 Source: Linux

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data wi...

Aliases:
GHSA-wr5g-mfhw-rpfj CVE-2025-39964
Published: 2025-10-13 View Complete Profile →

EUVD-2025-31542

Actively Exploited
CRITICAL (9.8) CVSS 3.1 Source: Linux

In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either - only contiguous DATA records (a...

Aliases:
GHSA-v2pf-75pf-9c5h CVE-2025-39682
Published: 2025-09-05 View Complete Profile →
MEDIUM (4.8) CVSS 4.0 Source: CERT-PL

The configuration of Mosh-Pro on macOS, specifically the "RunAsNode" fuse enabled, allows a local attacker with unprivileged access to execute arbitrary code that inherits Mosh-Pro TCC (Transparency,...

Aliases:
GHSA-p5h8-h669-x47q CVE-2025-53811
Published: 2025-08-26 View Complete Profile →
CRITICAL (9.1) CVSS 3.1 Source: redhat

A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the <sch:name path="..."/> schema elements. T...

Aliases:
GHSA-qg4c-8pj4-qgw2 CVE-2025-49794
Published: 2025-06-16 View Complete Profile →
CRITICAL (9.1) CVSS 3.1 Source: redhat

A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input fi...

Aliases:
CVE-2025-49796 GHSA-83xx-9f6p-vwfj
Published: 2025-06-16 View Complete Profile →