NA - CVE-2025-1433 - A maliciously crafted MODEL file, when parsed...
A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read...
NA - CVE-2025-1649 - A maliciously crafted CATPRODUCT file, when...
A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash,...
NA - CVE-2025-1650 - A maliciously crafted CATPRODUCT file, when...
A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash,...
NA - CVE-2025-1651 - A maliciously crafted MODEL file, when parsed...
A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read...
NA - CVE-2025-1652 - A maliciously crafted MODEL file, when parsed...
A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read...
NA - CVE-2025-1767 - This CVE only affects Kubernetes clusters that...
This CVE only affects Kubernetes clusters that utilize the in-tree gitRepo volume to clone git repositories from other pods within the same node. Since the in-tree gitRepo volume feature has been...
NA - CVE-2025-24974 - DataEase is an open source business...
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, authenticated users can read and deserialize arbitrary files through the background JDBC...
NA - CVE-2025-27103 - DataEase is an open source business...
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, a bypass for the patch for CVE-2024-55953 allows authenticated users to read and deserialize...
NA - CVE-2025-27107 - Integrated Scripting is a tool for creating...
Integrated Scripting is a tool for creating scripts for handling complex operations in Integrated Dynamics. Minecraft users who use Integrated Scripting prior to versions 1.21.1-1.0.17,...
NA - CVE-2025-27138 - DataEase is an open source business...
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, there is a flaw in the authentication in the io.dataease.auth.filter.TokenFilter class, which...