Post

2025-10-29 Daily Vulns

NEW:

CVEvendor-productdescriptionmetricReferenceurltitleGithubURL 
CVE-2024-57412n/a - n/aAn issue in SunOS Omnios v5.11 allows attackers to cause a Denial of Service (DoS) via repeatedly sending crafted TCP packets.CNA n/a CVSS3.1: 7.5 - HIGH0Exploitation: pocAutomatable: noTechnical Impact: partialundefinedgithub
CVE-2025-12198n/a - dnsmasqA vulnerability has been found in dnsmasq up to 2.73rc6. Affected is the function parse_hex of the file src/util.c of the component Config File Handler. The manipulation of the argument i leads to heap-based buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.Eine Schwachstelle wurde in dnsmasq up to 2.73rc6 gefunden. Es betrifft die Funktion parse_hex der Datei src/util.c der Komponente Config File Handler. Dank der Manipulation des Arguments i mit unbekannten Daten kann eine heap-based buffer overflow-Schwachstelle ausgenutzt werden. Die Umsetzung des Angriffs hat dabei lokal zu erfolgen. Der Exploit ist öffentlich verfügbar und könnte genutzt werden.CVSS4.0: 8.5 - HIGH CVSS3.1: 7.8 - HIGH0 1 2 3Exploitation: pocAutomatable: noTechnical Impact: totaldnsmasq Config File util.c parse_hex heap-based overflowgithub
CVE-2025-10150Softing Industrial Automation GmbH - smartLink HW-PNSofting Industrial Automation GmbH - smartLink HW-DPWebserver crash caused by scanning on TCP port 80 in Softing Industrial Automation GmbH gateways and switch.This issue affects smartLink HW-PN: from 1.02 through 1.03 smartLink HW-DP: 1.31CVSS4.0: 8.7 - HIGH0 1Exploitation: noneAutomatable: yesTechnical Impact: partialWebserver crash caused by scanning on TCP port 80github
This post is licensed under CC BY 4.0 by the author.