Security Vulnerabilities
- CVEs Published In 2025
Memory corruption while processing MFC channel configuration during music playback.
Memory corruption while copying packets received from unix clients.
Memory corruption while handling IOCTL calls to set mode.
Memory corruption while routing GPR packets between user and root when handling large data packet.
Information disclosure while processing system calls with invalid parameters.
Memory corruption during video playback when video session open fails with time out error.
Information disclosure while exposing internal TA-to-TA communication APIs to HLOS
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML style sanitizer.
A security vulnerability has been detected in y_project RuoYi up to 4.8.1. The affected element is an unknown function of the file /monitor/cache/getnames. Such manipulation of the argument fragment leads to code injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.