SonicWall probes possible new zero-day after spike in Akira ransomware attacks on Gen 7 firewalls with SSLVPN enabled. SonicWall is investigating a potential new zero-day after a surge in Akira ransomware attacks targeting Gen 7 firewalls with SSLVPN enabled. The company is working to determine if the incidents stem from an existing flaw or a […]
A vulnerability, which was classified as problematic, was found in libav up to 12.3. This affects the function ff_seek_frame_binary of the file /libavformat/utils.c of the component MPEG File Parser. The manipulation leads to null pointer dereference. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is uniquely identified as CVE-2025-8586. It is possible to launch the attack on the local host. Furthermore, there is an exploit available.
The bug was initially reported by the researcher to the wrong project.
A vulnerability, which was classified as critical, has been found in libav up to 12.3. Affected by this issue is the function main of the file /avtools/avconv.c of the component DSS File Demuxer. The manipulation leads to double free. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is handled as CVE-2025-8585. Attacking locally is a requirement. Furthermore, there is an exploit available.
The bug was initially reported by the researcher to the wrong project.
A vulnerability classified as problematic was found in libav up to 12.3. Affected by this vulnerability is the function av_buffer_unref of the file libavutil/buffer.c of the component AVI File Parser. The manipulation leads to null pointer dereference. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is known as CVE-2025-8584. Local access is required to approach this attack. Furthermore, there is an exploit available.
The bug was initially reported by the researcher to the wrong project.
Threat actors are embracing ClickFix, ransomware gangs are turning on each other – toppling even the leaders – and law enforcement is disrupting one infostealer after another
A vulnerability classified as critical has been found in Draeger ICMHelper up to 1.4.0.1. Affected is an unknown function. The manipulation leads to missing authorization.
This vulnerability is traded as CVE-2025-41698. An attack has to be approached locally. There is no exploit available.
A vulnerability was found in Draeger ICMHelper up to 1.4.0.1. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to use of hard-coded cryptographic key
.
The identification of this vulnerability is CVE-2025-2810. The attack needs to be approached locally. There is no exploit available.