Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-62558

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft SharePoint Server 2019, Microsoft Office LTSC for Mac 2024, Microsoft Office LTSC for Mac 2021, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2024, Microsoft Office LTSC 2021, Microsoft Office 2019, Microsoft SharePoint Enterprise Server 2016, Microsoft Word 2016
Provider severity
HIGH
Conflicts
1

CVE-2025-62557

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC for Mac 2024, Microsoft Office LTSC 2024, Microsoft Office 2016, Microsoft Office for Android, Microsoft Office LTSC for Mac 2021, Microsoft Office 2019, Microsoft Office LTSC 2021, Microsoft 365 Apps for Enterprise
Provider severity
HIGH
Conflicts
1

CVE-2025-62556

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC 2021, Office Online Server, Microsoft Office 2019, Microsoft Office LTSC for Mac 2024, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC for Mac 2021, Microsoft Excel 2016, Microsoft Office LTSC 2024
Provider severity
HIGH
Conflicts
1

CVE-2025-62555

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft SharePoint Enterprise Server 2016, Microsoft Office LTSC for Mac 2024, Microsoft Office 2019, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021, Microsoft Word 2016, Microsoft SharePoint Server 2019, Microsoft Office LTSC 2024
Provider severity
HIGH
Conflicts
1

CVE-2025-62554

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office for Android, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC for Mac 2024, Microsoft Office 2016, Microsoft Office 2019
Provider severity
HIGH
Conflicts
1

CVE-2025-62553

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Excel 2016, Microsoft Office LTSC 2024, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2021, Microsoft Office LTSC for Mac 2021, Microsoft Office 2019, Microsoft Office LTSC for Mac 2024
Provider severity
HIGH
Conflicts
1

CVE-2025-62552

Relative path traversal in Microsoft Office Access allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office 2019, Microsoft Office LTSC 2024, Microsoft Access 2016 (32-bit edition), Microsoft Access 2016, Microsoft Office LTSC 2021, Microsoft 365 Apps for Enterprise
Provider severity
HIGH
Conflicts
1

CVE-2025-62550

Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft
Product
Azure Monitor
Provider severity
HIGH
Conflicts
1

CVE-2025-6255

The Dynamic AJAX Product Filters for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 1.3.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
plugincy
Product
Dynamic AJAX Product Filters for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62549

Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012, Windows 11 Version 25H2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows 11 version 22H3, Windows Server 2016, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows 10 Version 22H2, Windows Server 2008 Service Pack 2, Windows Server 2019 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows Server 2025, Windows 10 Version 21H2, Windows 10 Version 1607, Windows Server 2022, Windows 11 Version 24H2, Windows Server 2025 (Server Core installation), Windows 10 Version 1809, Windows Server 2012 R2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2008 R2 Service Pack 1, Windows Server 2016 (Server Core installation), Windows Server 2012 (Server Core installation), Windows 11 Version 23H2, Windows Server 2019
Provider severity
HIGH
Conflicts
1

CVE-2025-6254

The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.8. This is due to the doctreat_process_registration() function not properly restricting the roles that a user can register with. This makes it possible for unauthenticated attackers to register as an administrator user.

PUBLISHED
Vendor
AmentoTech
Product
Doctreat Core
Provider severity
CRITICAL
Conflicts
0

CVE-2025-6253

The UiCore Elements – Free Elementor widgets and templates plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.3.0 via the prepare_template() function due to a missing capability check and insufficient controls on the filename specified. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

PUBLISHED
Vendor
uicore
Product
UiCore Elements – Free widgets and templates for Elementor
Provider severity
HIGH
Conflicts
0

CVE-2025-62528

Taguette is an open source qualitative research tool. An issue has been discovered in Taguette versions prior to 1.5.0. It was possible for a project member to put JavaScript in name or description fields which would run on project load. This issue has been patched in version 1.5.0.

PUBLISHED
Vendor
remram44
Product
taguette
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62527

Taguette is an open source qualitative research tool. An issue has been discovered in Taguette versions prior to 1.5.0. It was possible for an attacker to request password reset email containing a malicious link, allowing the attacker to set the email if clicked by the victim. This issue has been patched in version 1.5.0.

PUBLISHED
Vendor
remram44
Product
taguette
Provider severity
HIGH
Conflicts
0

CVE-2025-62526

OpenWrt Project is a Linux operating system targeting embedded devices. Prior to version 24.10.4, ubusd contains a heap buffer overflow in the event registration parsing code. This allows an attacker to modify the head and potentially execute arbitrary code in the context of the ubus daemon. The affected code is executed before running the ACL checks, all ubus clients are able to send such messages. In addition to the heap corruption, the crafted subscription also results in a bypass of the list

PUBLISHED
Vendor
openwrt
Product
openwrt
Provider severity
HIGH
Conflicts
0

CVE-2025-62525

OpenWrt Project is a Linux operating system targeting embedded devices. Prior to version 24.10.4, local users could read and write arbitrary kernel memory using the ioctls of the ltq-ptm driver which is used to drive the datapath of the DSL line. This only effects the lantiq target supporting xrx200, danube and amazon SoCs from Lantiq/Intel/MaxLinear with the DSL in PTM mode. The DSL driver for the VRX518 is not affected. ATM mode is also not affected. Most VDSL lines use PTM mode and most ADSL

PUBLISHED
Vendor
openwrt
Product
openwrt
Provider severity
HIGH
Conflicts
1

CVE-2025-62524

PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. PILOS before 4.8.0 exposes the PHP version via the X-Powered-By header, enabling attackers to fingerprint the server and assess potential exploits. This information disclosure vulnerability originates from PHP’s base image. Additionally, the PHP version can also be inferred through the PILOS version displayed in the footer and by examining the source code available on GitHub. This information disclosure vulner

PUBLISHED
Vendor
THM-Health
Product
PILOS
Provider severity
MEDIUM
Conflicts
1

CVE-2025-62523

PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. PILOS before 4.8.0 includes a Cross-Origin Resource Sharing (CORS) misconfiguration in its middleware: it reflects the Origin request header back in the Access-Control-Allow-Origin response header without proper validation or a whitelist, while Access-Control-Allow-Credentials is set to true. This behavior could allow a malicious website on a different origin to send requests (including credentials) to the PIL

PUBLISHED
Vendor
THM-Health
Product
PILOS
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62522

Vite is a frontend tooling framework for JavaScript. In versions from 2.9.18 to before 3.0.0, 3.2.9 to before 4.0.0, 4.5.3 to before 5.0.0, 5.2.6 to before 5.4.21, 6.0.0 to before 6.4.1, 7.0.0 to before 7.0.8, and 7.1.0 to before 7.1.11, files denied by server.fs.deny were sent if the URL ended with \ when the dev server is running on Windows. Only apps explicitly exposing the Vite dev server to the network and running the dev server on Windows were affected. This issue has been patched in versi

PUBLISHED
Vendor
vitejs
Product
vite
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62521

ChurchCRM is an open-source church management system. Prior to version 5.21.0, a pre-authentication remote code execution vulnerability in ChurchCRM's setup wizard allows unauthenticated attackers to inject arbitrary PHP code during the initial installation process, leading to complete server compromise. The vulnerability exists in `setup/routes/setup.php` where user input from the setup form is directly concatenated into a PHP configuration template without any validation or sanitization. Any p

PUBLISHED
Vendor
ChurchCRM
Product
CRM
Provider severity
CRITICAL
Conflicts
0

CVE-2025-62520

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.27.1 and below, due to insufficient access-level checks, any non-admin user with access to manage_config_columns_page.php can use the Copy From action to retrieve the columns configuration from a private project they have no access to. This issue is fixed in version 2.27.2.

PUBLISHED
Vendor
mantisbt
Product
mantisbt
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6252

The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 1.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
qodeinteractive
Product
Qi Addons For Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62519

phpMyFAQ is an open source FAQ web application. Prior to version 4.0.14, an authenticated SQL injection vulnerability in the main configuration update functionality of phpMyFAQ allows a privileged user with 'Configuration Edit' permissions to execute arbitrary SQL commands. Successful exploitation can lead to a full compromise of the database, including reading, modifying, or deleting all data, as well as potential remote code execution depending on the database configuration. This issue has bee

PUBLISHED
Vendor
thorsten
Product
phpMyFAQ
Provider severity
HIGH
Conflicts
0

CVE-2025-62518

astral-tokio-tar is a tar archive reading/writing library for async Rust. Versions of astral-tokio-tar prior to 0.5.6 contain a boundary parsing vulnerability that allows attackers to smuggle additional archive entries by exploiting inconsistent PAX/ustar header handling. When processing archives with PAX-extended headers containing size overrides, the parser incorrectly advances stream position based on ustar header size (often zero) instead of the PAX-specified size, causing it to interpret fi

PUBLISHED
Vendor
astral-sh
Product
tokio-tar
Provider severity
HIGH
Conflicts
0

CVE-2025-62517

Rollbar.js offers error tracking and logging from Javascript to Rollbar. In versions before 2.26.5 and from 3.0.0-alpha1 to before 3.0.0-beta5, there is a prototype pollution vulnerability in merge(). If application code calls rollbar.configure() with untrusted input, prototype pollution is possible. This issue has been fixed in versions 2.26.5 and 3.0.0-beta5. A workaround involves ensuring that values passed to rollbar.configure() do not contain untrusted input.

PUBLISHED
Vendor
rollbar
Product
rollbar.js
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62515

pyquokka is a framework for making data lakes work for time series. In versions 0.3.1 and prior, the FlightServer class directly uses pickle.loads() to deserialize action bodies received from Flight clients without any sanitization or validation in the do_action() method. The vulnerable code is located in pyquokka/flight.py at line 283 where arbitrary data from Flight clients is directly passed to pickle.loads(). When FlightServer is configured to listen on 0.0.0.0, this allows attackers across

PUBLISHED
Vendor
marsupialtail
Product
quokka
Provider severity
CRITICAL
Conflicts
0

CVE-2025-62514

Parsec is a cloud-based application for cryptographically secure file sharing. In versions on the 3.x branch prior to 3.6.0, `libparsec_crypto`, a component of the Parsec application, does not check for weak order point of Curve25519 when compiled with its RustCrypto backend. In practice this means an attacker in a man-in-the-middle position would be able to provide weak order points to both parties in the Diffie-Hellman exchange, resulting in a high probability to for both parties to obtain the

PUBLISHED
Vendor
Scille
Product
parsec-cloud
Provider severity
HIGH
Conflicts
1

CVE-2025-62513

OpenBao is an open source identity-based secrets management system. In versions 2.2.0 to 2.4.1, OpenBao's audit log experienced a regression wherein raw HTTP bodies used by few endpoints were not correctly redacted (HMAC'd). This impacts those using the ACME functionality of PKI, resulting in short-lived ACME verification challenge codes being leaked in the audit logs. Additionally, this impacts those using the OIDC issuer functionality of the identity subsystem, auth and token response codes al

PUBLISHED
Vendor
openbao
Product
openbao
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62512

Piwigo is an open source photo gallery application for the web. In version 15.5.0 and likely earlier 15.x releases, the password reset functionality in Piwigo allows an unauthenticated attacker to determine whether a given username or email address exists in the system. The endpoint at password.php?action=lost returns distinct messages for valid vs. invalid accounts, enabling user enumeration. As of time of publication, no known patches are available.

PUBLISHED
Vendor
Piwigo
Product
Piwigo
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62511

yt-grabber-tui is a C++ terminal user interface application for downloading YouTube content. yt-grabber-tui version 1.0 contains a Time-of-Check to Time-of-Use (TOCTOU) race condition (CWE-367) in the creation of the default configuration file config.json. In version 1.0, load_json_settings in Settings.hpp checks for the existence of config.json using boost::filesystem::exists and, if the file is missing, calls create_json_settings which writes the JSON configuration with boost::property_tree::w

PUBLISHED
Vendor
zheny-creator
Product
YtGrabber-TUI
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62510

FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. In version 1.4.0, a regression allowed folder visibility/ownership to be inferred from folder names. Low-privilege users could see or interact with folders matching their username and, in some cases, other users’ content. This issue has been patched in version 1.5.0, where it introduces explicit per-folder ACLs (owners/read/write/share/read_own) and strict server-side checks across list, read,

PUBLISHED
Vendor
error311
Product
FileRise
Provider severity
HIGH
Conflicts
1

CVE-2025-6251

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via $item['field_id'] in all versions up to, and including, 1.7.1036 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
wproyal
Product
Royal Addons for Elementor – Addons and Templates Kit for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62509

FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to version 1.4.0, a business logic flaw in FileRise’s file/folder handling allows low-privilege users to perform unauthorized operations (view/delete/modify) on files created by other users. The root cause was inferring ownership/visibility from folder names (e.g., a folder named after a username) and missing server-side authorization/ownership checks across file operation endpoints. Thi

PUBLISHED
Vendor
error311
Product
FileRise
Provider severity
HIGH
Conflicts
1

CVE-2025-62508

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Citizen from 3.3.0 to 3.9.0 are vulnerable to stored cross-site scripting in the sticky header button message handling. In stickyHeader.js the copyButtonAttributes function assigns innerHTML from a source element’s textContent when copying button labels. This causes escaped HTML in system message content (such as citizen-share, citizen-view-history, citizen-view-edit, and nstab-talk) to be interpreted as HTML in t

PUBLISHED
Vendor
StarCitizenTools
Product
mediawiki-skins-Citizen
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62507

Redis is an open source, in-memory database that persists on disk. In versions 8.2.0 and above, a user can run the XACKDEL command with multiple ID's and trigger a stack buffer overflow, which may potentially lead to remote code execution. This issue is fixed in version 8.2.3. To workaround this issue without patching the redis-server executable is to prevent users from executing XACKDEL operation. This can be done using ACL to restrict XACKDEL command.

PUBLISHED
Vendor
redis
Product
redis
Provider severity
HIGH
Conflicts
1

CVE-2025-62506

MinIO is a high-performance object storage system. In all versions prior to RELEASE.2025-10-15T17-29-55Z, a privilege escalation vulnerability allows service accounts and STS (Security Token Service) accounts with restricted session policies to bypass their inline policy restrictions when performing operations on their own account, specifically when creating new service accounts for the same user. The vulnerability exists in the IAM policy validation logic where the code incorrectly relied on th

PUBLISHED
Vendor
minio
Product
minio
Provider severity
HIGH
Conflicts
0

CVE-2025-62505

LobeChat is an open source chat application platform. The web-crawler package in LobeChat version 1.136.1 allows server-side request forgery (SSRF) in the tools.search.crawlPages tRPC endpoint. A client can supply an arbitrary urls array together with impls containing the value naive. The service passes the user URLs to Crawler.crawl and the naive implementation performs a server-side fetch of each supplied URL without validating or restricting internal network addresses (such as localhost, 127.

PUBLISHED
Vendor
lobehub
Product
lobe-chat
Provider severity
LOW
Conflicts
0

CVE-2025-62504

Envoy is an open source edge and service proxy. Envoy versions earlier than 1.36.2, 1.35.6, 1.34.10, and 1.33.12 contain a use-after-free vulnerability in the Lua filter. When a Lua script executing in the response phase rewrites a response body so that its size exceeds the configured per_connection_buffer_limit_bytes (default 1MB), Envoy generates a local reply whose headers override the original response headers, leaving dangling references and causing a crash. This results in denial of servic

PUBLISHED
Vendor
envoyproxy
Product
envoy
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62503

User with CREATE and no UPDATE privilege for Pools, Connections, Variables could update existing records via bulk create API with overwrite action.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Airflow
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62501

SSH Hostkey misconfiguration vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows attackers to obtain device credentials through a specially crafted man‑in‑the‑middle (MITM) attack. This could enable unauthorized access if captured credentials are reused.This issue affects Archer AX53 v1.0: through 1.3.1 Build 20241120.

PUBLISHED
Vendor
TP-Link Systems Inc.
Product
Archer AX53 v1.0
Provider severity
HIGH
Conflicts
0

CVE-2025-62500

An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

PUBLISHED
Vendor
Canva
Product
Affinity
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6250

Prior to 25.4.270.0, when wmic.exe is elevated with a full admin token the user can stop the Defendpoint service, bypassing anti-tamper protections. Once the service is disabled, the malicious user can add themselves to Administrators group and run any process with elevated permissions.

PUBLISHED
Vendor
BeyondTrust
Product
Privilege Management for Windows
Provider severity
HIGH
Conflicts
0

CVE-2025-62499

Movable Type contains a stored cross-site scripting vulnerability in Edit CategorySet of ContentType page. If crafted input is stored by an attacker with "ContentType Management" privilege, an arbitrary script may be executed on the web browser of the user who accesses Edit CategorySet of ContentType page.

PUBLISHED
Vendor
Six Apart Ltd., Six Apart Ltd., Six Apart Ltd., Six Apart Ltd., Six Apart Ltd., Six Apart Ltd.
Product
Movable Type (Software Edition), Movable Type Advanced (Software Edition), Movable Type (Cloud Edition), Movable Type Premium (Software Edition), Movable Type Premium (Cloud Edition), Movable Type Premium (Advanced Edition) (Software Edition)
Provider severity
MEDIUM
Conflicts
2

CVE-2025-62498

A relative path traversal (ZipSlip) vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an attacker who can tamper with a productivity project to execute arbitrary code on the machine where the project is opened.

PUBLISHED
Vendor
AutomationDirect, AutomationDirect, AutomationDirect, AutomationDirect, AutomationDirect, AutomationDirect, AutomationDirect, AutomationDirect
Product
Productivity 1000 P1-550 CPU, Productivity 2000 P2-550 CPU, Productivity 2000 P2-622 CPU, Productivity 1000 P1-540 CPU, Productivity Suite, Productivity 3000 P3-550E CPU, Productivity 3000 P3-622 CPU, Productivity 3000 P3-530 CPU
Provider severity
HIGH
Conflicts
2

CVE-2025-62497

Cross-site request forgery vulnerability exists in SNC-CX600W versions prior to Ver.2.8.0. If a user accesses a specially crafted webpage while logged in, unintended operations may be performed.

PUBLISHED
Vendor
Sony Corporation
Product
SNC-CX600W
Provider severity
LOW
Conflicts
1

CVE-2025-62496

A vulnerability exists in the QuickJS engine's BigInt string parsing logic (js_bigint_from_string) when attempting to create a BigInt from a string with an excessively large number of digits. The function calculates the necessary number of bits (n_bits) required to store the BigInt using the formula: $$\text{n\_bits} = (\text{n\_digits} \times 27 + 7) / 8 \quad (\text{for radix 10})$$ * For large input strings (e.g., $79,536,432$ digits or more for base 10), the intermediate calculation $(

PUBLISHED
Vendor
QuickJS
Product
QuickJS
Provider severity
HIGH
Conflicts
0

CVE-2025-62495

An integer overflow vulnerability exists in the QuickJS regular expression engine (libregexp) due to an inconsistent representation of the bytecode buffer size. * The regular expression bytecode is stored in a DynBuf structure, which correctly uses a $\text{size}\_\text{t}$ (an unsigned type, typically 64-bit) for its size member. * However, several functions, such as re_emit_op_u32 and other internal parsing routines, incorrectly cast or store this DynBuf $\text{size}\_\text{t}$ value

PUBLISHED
Vendor
QuickJS
Product
QuickJS
Provider severity
HIGH
Conflicts
0

CVE-2025-62494

A type confusion vulnerability exists in the handling of the string addition (+) operation within the QuickJS engine. * The code first checks if the left-hand operand is a string. * It then attempts to convert the right-hand operand to a primitive value using JS_ToPrimitiveFree. This conversion can trigger a callback (e.g., toString or valueOf). * During this callback, an attacker can modify the type of the left-hand operand in memory, changing it from a string to a different type

PUBLISHED
Vendor
QuickJS
Product
QuickJS
Provider severity
HIGH
Conflicts
0

CVE-2025-62493

A vulnerability exists in the QuickJS engine's BigInt string conversion logic (js_bigint_to_string1) due to an incorrect calculation of the required number of digits, which in turn leads to reading memory past the allocated BigInt structure. * The function determines the number of characters (n_digits) needed for the string representation by calculating: $$ \\ \text{n\_digits} = (\text{n\_bits} + \text{log2\_radix} - 1) / \text{log2\_radix}$$ $$$$This formula is off-by-one in certain edge

PUBLISHED
Vendor
QuickJS
Product
QuickJS
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62492

A vulnerability stemming from floating-point arithmetic precision errors exists in the QuickJS engine's implementation of TypedArray.prototype.indexOf() when a negative fromIndex argument is supplied. * The fromIndex argument (read as a double variable, $d$) is used to calculate the starting position for the search. * If d is negative, the index is calculated relative to the end of the array by adding the array's length (len) to d: $$d_{new} = d + \text{len}$$ * Due to the inher

PUBLISHED
Vendor
QuickJS
Product
QuickJS
Provider severity
MEDIUM
Conflicts
0