A vulnerability was found in risc0 risc0-ethereum up to 2.1.0. It has been classified as problematic. This affects the function Steel.validateCommitment. The manipulation leads to improper handling of invalid use of special elements.
This vulnerability is uniquely identified as CVE-2025-52884. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A CVSS score 5.0 AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L severity vulnerability discovered by 'Anonymous' was reported to the affected vendor on: 2025-06-25, 78 days ago. The vendor is given until 2025-10-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
A vulnerability was found in hikariatama Hikka up to 1.7.0-wip and classified as critical. Affected by this issue is some unknown functionality of the component Web Interface. The manipulation leads to improper authentication.
This vulnerability is handled as CVE-2025-52572. The attack may be launched remotely. There is no exploit available.
A vulnerability has been found in espressif esp-idf 5.1.6/5.2.5/5.3.3/5.4.1 and classified as very critical. Affected by this vulnerability is the function esp_now_register_recv_cb of the component ESP-NOW Protocol. The manipulation of the argument data_len leads to integer underflow.
This vulnerability is known as CVE-2025-52471. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, was found in Moodle up to 3.11.18. Affected is an unknown function. The manipulation of the argument sesskey leads to session fixiation. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is traded as CVE-2025-53021. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, has been found in IBM i 7.2/7.3/7.4/7.5. This issue affects some unknown processing. The manipulation leads to uncontrolled search path.
The identification of this vulnerability is CVE-2025-36004. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical was found in IBM InfoSphere Information Server 11.7. This vulnerability affects unknown code. The manipulation leads to sql injection.
This vulnerability was named CVE-2025-0966. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical has been found in NVIDIA Megatron LM. This affects an unknown part. The manipulation leads to code injection.
This vulnerability is uniquely identified as CVE-2025-23265. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability was found in NVIDIA Megatron LM. It has been rated as critical. Affected by this issue is some unknown functionality of the component Python. The manipulation leads to code injection.
This vulnerability is handled as CVE-2025-23264. The attack may be launched remotely. There is no exploit available.
A vulnerability was found in OS4Ed Open Source Information System Community 8.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /TransferredOutModal.php of the component POST Request Handler. The manipulation of the argument student_id/TRANSFER{SCHOOL} leads to sql injection.
This vulnerability is known as CVE-2021-41691. The attack can be launched remotely. There is no exploit available.
A vulnerability was found in Google Chrome on Windows. It has been classified as critical. Affected is an unknown function of the component DevTools. The manipulation leads to improper restriction of rendered ui layers.
This vulnerability is traded as CVE-2025-6557. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Google Chrome and classified as critical. This issue affects some unknown processing of the component Animation. The manipulation leads to use after free.
The identification of this vulnerability is CVE-2025-6555. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in Google Chrome and classified as critical. This vulnerability affects unknown code of the component Loader. The manipulation leads to improper access controls.
This vulnerability was named CVE-2025-6556. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical was found in Microsoft Outlook 2000/2002/2003. Affected by this vulnerability is an unknown functionality of the component TNEF MIME Attachment Handler. The manipulation leads to integer coercion error.
This vulnerability is known as CVE-2006-0002. The attack can be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability, which was classified as critical, has been found in Microsoft Exchange 5/5.5/2000. Affected by this issue is some unknown functionality of the component Email. The manipulation as part of NEF MIME Attachment leads to memory corruption.
This vulnerability is handled as CVE-2006-0002. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability was found in Microsoft Windows 2000/Server 2003/XP. It has been classified as critical. This affects an unknown part of the component Media Player. The manipulation as part of EMBED Tag leads to memory corruption.
This vulnerability is uniquely identified as CVE-2006-0005. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability classified as critical has been found in Microsoft PowerPoint 2000. Affected is an unknown function of the component HTML Rendering. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2006-0004. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability was found in Microsoft Data Access Components 2.7. It has been declared as critical. This vulnerability affects unknown code of the component Data Access Components. The manipulation leads to memory corruption.
This vulnerability was named CVE-2006-0003. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.