NA - CVE-2025-49216 - An authentication bypass vulnerability in the...
An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to access key methods as an admin user and modify product configurations on...
NA - CVE-2025-49217 - An insecure deserialization operation in the...
An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this...
NA - CVE-2025-49218 - A post-auth SQL injection vulnerability in the...
A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installations. This is similar to, but not...
NA - CVE-2025-49384 - Trend Micro Security 17.8 (Consumer) is...
Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that could allow a local attacker to unintentionally delete privileged Trend Micro...
NA - CVE-2025-49385 - Trend Micro Security 17.8 (Consumer) is...
Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that could allow a local attacker to unintentionally delete privileged Trend Micro...
NA - CVE-2025-49824 - conda-smithy is a tool for combining a conda...
conda-smithy is a tool for combining a conda recipe with configurations to build using freely hosted CI services into a single repository. Prior to version 3.47.1, the travis_encrypt_binstar_token...
NA - CVE-2025-49843 - conda-smithy is a tool for combining a conda...
conda-smithy is a tool for combining a conda recipe with configurations to build using freely hosted CI services into a single repository. Prior to version 3.47.1, the travis_headers function in...
NA - CVE-2025-49842 - conda-forge-webservices is the web app deployed...
conda-forge-webservices is the web app deployed to run conda-forge admin commands and linting. Prior to version 2025.3.24, the conda_forge_webservice Docker container executes commands without...
NA - CVE-2025-4404 - A privilege escalation from host to domain...
A privilege escalation from host to domain vulnerability was found in the FreeIPA project. The FreeIPA package fails to validate the uniqueness of the `krbCanonicalName` for the admin account by...