Author: Angelo Barbosa

CVE-2025-0696 | Cesanta Frozen up to 1.6 JSON null pointer dereference

A vulnerability was found in Cesanta Frozen up to 1.6. It has been classified as problematic. Affected is an unknown function of the component JSON Handler. The manipulation leads to null pointer dereference. This vulnerability is traded as CVE-2025-0696. It is possible to launch the attack remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2025-0695 | Cesanta Frozen up to 1.6 JSON allocation of resources

A vulnerability was found in Cesanta Frozen up to 1.6 and classified as problematic. This issue affects some unknown processing of the component JSON Handler. The manipulation leads to allocation of resources. The identification of this vulnerability is CVE-2025-0695. The attack may be initiated remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2025-0734 | y_project RuoYi up to 4.8.0 Whitelist getBeanName deserialization

A vulnerability has been found in y_project RuoYi up to 4.8.0 and classified as critical. This vulnerability affects the function getBeanName of the component Whitelist. The manipulation leads to deserialization. This vulnerability was named CVE-2025-0734. The attack can be initiated remotely. Furthermore, there is an exploit available. The vendor was contacted early about this disclosure but did not respond in any way. The vendor was contacted early about this disclosure but did not respond in any...

Read More

CVE-2025-0733 | Postman up to 11.20 on Windows profapi.dll untrusted search path

A vulnerability, which was classified as problematic, was found in Postman up to 11.20 on Windows. This affects an unknown part in the library profapi.dll. The manipulation leads to untrusted search path. This vulnerability is uniquely identified as CVE-2025-0733. An attack has to be approached locally. Furthermore, there is an exploit available. The vendor was contacted early about this disclosure but did not respond in any way. The vendor was contacted early about this disclosure but did not respond in any...

Read More

CVE-2025-0732 | Discord up to 1.0.9177 on Windows profapi.dll untrusted search path

A vulnerability, which was classified as problematic, has been found in Discord up to 1.0.9177 on Windows. Affected by this issue is some unknown functionality in the library profapi.dll. The manipulation leads to untrusted search path. This vulnerability is handled as CVE-2025-0732. The attack needs to be approached locally. Furthermore, there is an exploit available. The vendor was contacted early about this disclosure but did not respond in any way. The vendor was contacted early about this disclosure but did not respond in any...

Read More