NA - CVE-2025-49218 - A post-auth SQL injection vulnerability in the...
A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installations. This is similar to, but not...
NA - CVE-2025-49384 - Trend Micro Security 17.8 (Consumer) is...
Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that could allow a local attacker to unintentionally delete privileged Trend Micro...
NA - CVE-2025-49385 - Trend Micro Security 17.8 (Consumer) is...
Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that could allow a local attacker to unintentionally delete privileged Trend Micro...
NA - CVE-2025-49824 - conda-smithy is a tool for combining a conda...
conda-smithy is a tool for combining a conda recipe with configurations to build using freely hosted CI services into a single repository. Prior to version 3.47.1, the travis_encrypt_binstar_token...
NA - CVE-2025-49843 - conda-smithy is a tool for combining a conda...
conda-smithy is a tool for combining a conda recipe with configurations to build using freely hosted CI services into a single repository. Prior to version 3.47.1, the travis_headers function in...
NA - CVE-2025-49842 - conda-forge-webservices is the web app deployed...
conda-forge-webservices is the web app deployed to run conda-forge admin commands and linting. Prior to version 2025.3.24, the conda_forge_webservice Docker container executes commands without...
NA - CVE-2025-4404 - A privilege escalation from host to domain...
A privilege escalation from host to domain vulnerability was found in the FreeIPA project. The FreeIPA package fails to validate the uniqueness of the `krbCanonicalName` for the admin account by...
NA - CVE-2025-6069 - The html.parser.HTMLParser class had worse-case...
The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain crafted malformed inputs potentially leading to amplified denial-of-service.