CVE-2025-46397
A flaw was found in xfig. This vulnerability allows possible code execution via local input manipulation via bezier_spline function.
CVSS
7.8
High
EPSS
0.3%
p22
KEV
—
Exploit Today
7
0-100
Published: Apr 23, 2025 · Last modified: Jun 30, 2026 · CWE-120
0.3%EPSS · 30 days0.3%
2026-08-112026-09-07
A flaw was found in xfig. This vulnerability allows possible code execution via local input manipulation via bezier_spline function.
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:0700
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:0704
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:0705
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:0756
- access.redhat.comhttps://access.redhat.com/security/cve/CVE-2025-46397
- bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=2362058
- sourceforge.nethttps://sourceforge.net/p/mcj/tickets/192/
- lists.debian.orghttps://lists.debian.org/debian-lts-announce/2025/04/msg00043.html
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-4475610.0 CRI—
——0A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application.6hCVE-2026-861668.8 HIG39.5%
——12A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect of the component Boa Web Server. Executing a manipulation of the argument if can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.12hCVE-2026-861659.8 CRI48.5%
——15A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin/formURL. Performing a manipulation of the argument Keywd/urlFQDN results in buffer overflow. The attack may be initiated remotely. The exploit has been made public and could be used.11hCVE-2026-754387.5 HIG19.6%
——6Buffer Overflow vulnerability in Open5GS v2.7.7 allows a remote attacker to cause a denial of service via the ogs_sbi_time_parse() function10hCVE-2026-851108.8 HIG39.5%
——12A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formWlanSetup of the file /boaform/formWlanSetup of the component Boa Web Server. The manipulation of the argument ssid leads to buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.5dCVE-2026-851099.8 CRI47.6%
——14A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formLogin of the file /boaform/formLogin of the component Boa Web Server. Executing a manipulation of the argument Username can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.5d