Total
3244 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-48595 | 1 Google | 1 Android | 2026-06-17 | N/A | 8.4 HIGH |
| In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
| CVE-2025-48515 | 2026-06-17 | N/A | N/A | ||
| Insufficient parameter sanitization in AMD Secure Processor (ASP) Boot Loader could allow an attacker with access to SPIROM upgrade to overwrite the memory, potentially resulting in arbitrary code execution. | |||||
| CVE-2025-48175 | 1 Aomedia | 1 Libavif | 2026-06-17 | N/A | 4.5 MEDIUM |
| In libavif before 1.3.0, avifImageRGBToYUV in reformat.c has integer overflows in multiplications involving rgbRowBytes, yRowBytes, uRowBytes, and vRowBytes. | |||||
| CVE-2025-48174 | 1 Aomedia | 1 Libavif | 2026-06-17 | N/A | 4.5 MEDIUM |
| In libavif before 1.3.0, makeRoom in stream.c has an integer overflow and resultant buffer overflow in stream->offset+size. | |||||
| CVE-2025-48172 | 2026-06-17 | N/A | 5.6 MEDIUM | ||
| CHMLib through 2bef8d0, as used in SumatraPDF and other products, has a chm_lib.c _chm_decompress_block integer overflow. There is a resultant heap-based buffer overflow in _chm_fetch_bytes. | |||||
| CVE-2025-48002 | 1 Microsoft | 2 Windows 11 24h2, Windows Server 2025 | 2026-06-17 | N/A | 5.7 MEDIUM |
| Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to disclose information over an adjacent network. | |||||
| CVE-2025-47998 | 1 Microsoft | 7 Windows Server 2008, Windows Server 2012, Windows Server 2016 and 4 more | 2026-06-17 | N/A | 8.8 HIGH |
| Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2025-47987 | 1 Microsoft | 15 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 12 more | 2026-06-17 | N/A | 7.8 HIGH |
| Heap-based buffer overflow in Windows Cred SSProvider Protocol allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2025-47392 | 1 Qualcomm | 308 5g Fixed Wireless Access Platform, 5g Fixed Wireless Access Platform Firmware, Ar8035 and 305 more | 2026-06-17 | N/A | 8.8 HIGH |
| Memory corruption when decoding corrupted satellite data files with invalid signature offsets. | |||||
| CVE-2025-47365 | 1 Qualcomm | 70 Qam8255p, Qam8255p Firmware, Qam8295p and 67 more | 2026-06-17 | N/A | 7.8 HIGH |
| Memory corruption while processing large input data from a remote source via a communication interface. | |||||
| CVE-2025-47364 | 1 Qualcomm | 70 Qam8255p, Qam8255p Firmware, Qam8295p and 67 more | 2026-06-17 | N/A | 6.8 MEDIUM |
| Memory corruption while calculating offset from partition start point. | |||||
| CVE-2025-47363 | 1 Qualcomm | 70 Qam8255p, Qam8255p Firmware, Qam8295p and 67 more | 2026-06-17 | N/A | 6.8 MEDIUM |
| Memory corruption when calculating oversized partition sizes without proper checks. | |||||
| CVE-2025-47351 | 1 Qualcomm | 56 Fastconnect 6200, Fastconnect 6200 Firmware, Fastconnect 6700 and 53 more | 2026-06-17 | N/A | 7.8 HIGH |
| Memory corruption while processing user buffers. | |||||
| CVE-2025-47323 | 1 Qualcomm | 356 Ar8035, Ar8035 Firmware, Csra6620 and 353 more | 2026-06-17 | N/A | 7.8 HIGH |
| Memory corruption while routing GPR packets between user and root when handling large data packet. | |||||
| CVE-2025-47294 | 1 Fortinet | 1 Fortios | 2026-06-17 | N/A | 5.3 MEDIUM |
| A integer overflow or wraparound in Fortinet FortiOS versions 7.2.0 through 7.2.7, versions 7.0.0 through 7.0.14 may allow a remote unauthenticated attacker to crash the csfd daemon via a specially crafted request. | |||||
| CVE-2025-47268 | 1 Iputils | 1 Iputils | 2026-06-17 | N/A | 6.5 MEDIUM |
| ping in iputils before 20250602 allows a denial of service (application error or incorrect data collection) via a crafted ICMP Echo Reply packet, because of a signed 64-bit integer overflow in timestamp multiplication. | |||||
| CVE-2025-46819 | 1 Redis | 1 Redis | 2026-06-17 | N/A | 6.3 MEDIUM |
| Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted LUA script to read out-of-bound data or crash the server and subsequent denial of service. The problem exists in all versions of Redis with Lua scripting. This issue is fixed in version 8.2.2. To workaround this issue without patching the redis-server executable is to prevent users from executing Lua scripts. This can be done using ACL to block a script by restricting both the EVAL and FUNCTION command families. | |||||
| CVE-2025-46817 | 1 Redis | 1 Redis | 2026-06-17 | N/A | 7.0 HIGH |
| Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to cause an integer overflow and potentially lead to remote code execution The problem exists in all versions of Redis with Lua scripting. This issue is fixed in version 8.2.2. | |||||
| CVE-2025-46597 | 1 Bitcoin | 1 Bitcoin Core | 2026-06-17 | N/A | 7.5 HIGH |
| Bitcoin Core 0.13.0 through 29.x has an integer overflow. | |||||
| CVE-2025-46333 | 2026-06-17 | N/A | N/A | ||
| z2d is a pure Zig 2D graphics library. Versions of z2d after `0.5.1` and up to and including `0.6.0`, when writing from one surface to another using `z2d.compositor.StrideCompositor.run`, and higher-level operations when the anti-aliasing mode is set to `.default` (such as `Context.fill`, `Context.stroke`, `painter.fill`, and `painter.stroke`), the source surface can be completely out-of-bounds on the x-axis, but not on the y-axis, by way of a negative offset. This results in an overflow of the value controlling the length of the stride. In non-safe optimization modes (consumers compiling with `ReleaseFast` or `ReleaseSmall`), this could potentially lead to invalid memory accesses or corruption. This issue is patched in version `0.6.1`. Users on an untagged version after `v0.5.1` and before `v0.6.1` are advised to update to address the vulnerability. Those still on Zig `0.13.0` are recommended to downgrade to `v0.5.1`. | |||||
