CVE-2018-25032
published 2022-03-25CVE-2018-25032: zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
PriorityP357high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
52.06%
98.8th percentile
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
Affected
95 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | >= 10.15 < 10.15.7 | 10.15.7 |
| apple | macos | >= 11.0 < 11.6.6 | 11.6.6 |
| apple | macos | >= 12.0.0 < 12.4 | 12.4 |
| apple | macos_big_sur | — | — |
| apple | macos_monterey | — | — |
| apple | security_update_2022-004_catalina | — | — |
| azul | zulu | — | — |
| azul | zulu | — | — |
| azul | zulu | — | — |
| azul | zulu | — | — |
| azul | zulu | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2018-25032 is triggered during deflate (compression) operations in zlib when the input contains many distant matches, leading to memory corruption. Detection should focus on zlib versions prior to 1.2.12 performing deflate operations. ↗
- →The vulnerability was discovered by Danilo Ramos and specifically involves incorrect memory handling during certain deflating operations, which could lead to crash or arbitrary code execution in affected applications. ↗
- ·The vulnerability is scoped as local exploitation per Debian's tracker, but Oracle's advisories classify it as remotely exploitable via HTTP — detection posture should account for both local and network-facing zlib usage. ↗
- ·Oracle rates this as remotely exploitable (CVSS 7.5) over HTTP in products such as Siebel CRM and Oracle Communications, meaning network-facing services using vulnerable zlib should be prioritized for patching and monitoring. ↗
- ·Debian bullseye remains open/unpatched for this CVE; environments running bullseye with zlib should be flagged as unresolved. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
ghsa7.5HIGH
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2025-0012 Informational Bulletin: OSS CVEs Fixed in PAN-OS
vendor_paloalto·2025-07-09·CVSS 7.5
CVE-2018-6594 [HIGH] PAN-SA-2025-0012 Informational Bulletin: OSS CVEs Fixed in PAN-OS
PAN-SA-2025-0012 Informational Bulletin: OSS CVEs Fixed in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS. While it was not determined that these CVEs have any significant impact on PAN-OS, they have been fixed out of an abundance of caution. CVE Summary CVE-2018-6594 This CVE is fixed in PAN-OS 10.2.17, 11.1.11, 11.2.8, 12.1.2, and all later versions of PAN-OS CVE-2018-25032 This CVE is fixed in PAN-OS 10.1.7, 10.2.2, and all later versions of PAN-OS CVE-2019-5827 This CVE is fixed in PAN-OS 11.1.4, and all later versions of PAN-OS. CVE-2019-13750 This CVE is fixed in PAN-OS 11.1.4, and all later versions of PAN-OS. CVE-2019-13751 This CVE is fixed in PAN-OS 11.1.4, and all later versions
Palo Alto
PAN-SA-2025-0012 Informational Bulletin: OSS CVEs Fixed in PAN-OS
vendor_paloalto·2025-07-09·CVSS 7.5
CVE-2023-38546 [HIGH] PAN-SA-2025-0012 Informational Bulletin: OSS CVEs Fixed in PAN-OS
PAN-SA-2025-0012 Informational Bulletin: OSS CVEs Fixed in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS. While it was not determined that these CVEs have any significant impact on PAN-OS, they have been fixed out of an abundance of caution. CVE Summary CVE-2018-6594 This CVE is fixed in PAN-OS 10.2.17, 11.1.11, 11.2.8, 12.1.2, and all later versions of PAN-OS CVE-2018-25032 This CVE is fixed in PAN-OS 10.1.7, 10.2.2, and all later versions of PAN-OS CVE-2019-5827 This CVE is fixed in PAN-OS 11.1.4, and all later versions of PAN-OS. CVE-2019-13750 This CVE is fixed in PAN-OS 11.1.4, and all later versions of PAN-OS. CVE-2019-13751 This CVE is fixed in PAN-OS 11.1.4, and all later versions
Ubuntu
klibc vulnerabilities
vendor_ubuntu·2024-05-23·CVSS 8.8
CVE-2016-9841 [HIGH] klibc vulnerabilities
Title: klibc vulnerabilities
Summary: Several security issues were fixed in klibc.
USN-6736-1 fixed vulnerabilities in klibc. This update provides the
corresponding updates for Ubuntu 24.04 LTS.
Original advisory details:
It was discovered that zlib, vendored in klibc, incorrectly handled pointer
arithmetic. An attacker could use this issue to cause klibc to crash or to
possibly execute arbitrary code. (CVE-2016-9840, CVE-2016-9841)
Danilo Ramos discovered that zlib, vendored in klibc, incorrectly handled
memory when performing certain deflating operations. An attacker could use
this issue to cause klibc to crash or to possibly execute arbitrary code.
(CVE-2018-25032)
Evgeny Legerov discovered that zlib, vendored in klibc, incorrectly handled
memory when performing certain inflate op
Ubuntu
klibc vulnerabilities
vendor_ubuntu·2024-04-16·CVSS 8.8
CVE-2018-25032 [HIGH] klibc vulnerabilities
Title: klibc vulnerabilities
Summary: Several security issues were fixed in klibc.
It was discovered that zlib, vendored in klibc, incorrectly handled pointer
arithmetic. An attacker could use this issue to cause klibc to crash or to
possibly execute arbitrary code. (CVE-2016-9840, CVE-2016-9841)
Danilo Ramos discovered that zlib, vendored in klibc, incorrectly handled
memory when performing certain deflating operations. An attacker could use
this issue to cause klibc to crash or to possibly execute arbitrary code.
(CVE-2018-25032)
Evgeny Legerov discovered that zlib, vendored in klibc, incorrectly handled
memory when performing certain inflate operations. An attacker could use
this issue to cause klibc to crash or to possibly execute arbitrary code.
(CVE-2022-37434)
Instructions: In
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
Oracle
Oracle Oracle Siebel CRM Risk Matrix: Siebel Core (zlib) — CVE-2018-25032
vendor_oracle·2023-07-15·CVSS 7.5
CVE-2018-25032 [HIGH] Oracle Oracle Siebel CRM Risk Matrix: Siebel Core (zlib) — CVE-2018-25032
Oracle Oracle Siebel CRM Risk Matrix: Siebel Core (zlib) vulnerability
CVE: CVE-2018-25032
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
CISA ICS
Siemens SINAMICS Medium Voltage Products
cisa_ics·2023-06-15·CVSS 7.5
[HIGH] Siemens SINAMICS Medium Voltage Products
ICS Advisory
##
Siemens SINAMICS Medium Voltage Products
Release DateJune 15, 2023
Alert CodeICSA-23-166-12
## As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely / low attack complexity
- Vendor: Siemens
- Equipment: SINAMICS MV (medium voltage) products
- Vulnerabilities: Out-of-bounds Write, Out-of-bounds Read, Use After Free, Improper Authentication, OS Command Injection, Improper Certificate Validation, Improper Res
CISA ICS
Siemens SCALANCE Third-Party
cisa_ics·2023-03-21
Siemens SCALANCE Third-Party
ICS Advisory
##
Siemens SCALANCE Third-Party
Release DateMarch 21, 2023
Alert CodeICSA-23-080-07
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.1
- ATTENTION: Exploitable remotely
- Vendor: Siemens
- Equipment: Various third-party components used in SCALANCE W-700 devices
- Vulnerabilities: Generation of Error Message Containing Sensitive Information, Out-of-bounds Write, NULL Pointer Dereference, Out-of-bounds Read, Improper Input Validation, Release of Inval
CISA ICS
Siemens SCALANCE, RUGGEDCOM Third-Party
cisa_ics·2023-03-16
Siemens SCALANCE, RUGGEDCOM Third-Party
ICS Advisory
##
Siemens SCALANCE, RUGGEDCOM Third-Party
Release DateMarch 16, 2023
Alert CodeICSA-23-075-01
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/Low attack complexity
- Vendor: Siemens
- Equipment: Busybox Applet affecting SCALANCE and RUGGEDCOM products
- Vulnerabilities: Out-of-bounds Write, Exposure of Sensitive Information to an Unauthorized Actor, Improper Locking, Improper Input Validation, NULL Pointer Deref
Oracle
Oracle Oracle Database Server Risk Matrix: Oracle Database (zlib) — CVE-2018-25032
vendor_oracle·2023-01-15·CVSS 4.3
CVE-2018-25032 [HIGH] Oracle Oracle Database Server Risk Matrix: Oracle Database (zlib) — CVE-2018-25032
Oracle Oracle Database Server Risk Matrix: Oracle Database (zlib) vulnerability
CVE: CVE-2018-25032
CVSS: 4.3
Protocol: Oracle Net
Remote exploit: No
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Ubuntu
MariaDB vulnerabilities
vendor_ubuntu·2022-11-23
CVE-2022-27448 MariaDB vulnerabilities
Title: MariaDB vulnerabilities
Summary: Several security issues were fixed in MariaDB.
Several security issues were discovered in MariaDB and this update
includes new upstream MariaDB versions to fix these issues.
MariaDB has been updated to 10.3.37 in Ubuntu 20.04 LTS and to 10.6.11
in Ubuntu 22.04 LTS and Ubuntu 22.10.
In addition to security fixes, the updated packages contain bug fixes,
new features, and possibly incompatible changes.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.
Oracle
Oracle Oracle Communications Risk Matrix: DBTier (zlib) — CVE-2018-25032
vendor_oracle·2022-10-15·CVSS 7.5
CVE-2018-25032 [HIGH] Oracle Oracle Communications Risk Matrix: DBTier (zlib) — CVE-2018-25032
Oracle Oracle Communications Risk Matrix: DBTier (zlib) vulnerability
CVE: CVE-2018-25032
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Oracle
Oracle Oracle Communications Risk Matrix: CNC Console (zlib) — CVE-2018-25032
vendor_oracle·2022-07-15·CVSS 7.5
CVE-2018-25032 [HIGH] Oracle Oracle Communications Risk Matrix: CNC Console (zlib) — CVE-2018-25032
Oracle Oracle Communications Risk Matrix: CNC Console (zlib) vulnerability
CVE: CVE-2018-25032
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Ubuntu
rsync vulnerability
vendor_ubuntu·2022-06-13
CVE-2018-25032 rsync vulnerability
Title: rsync vulnerability
Summary: rsync could be made to crash or run programs if it received
specially crafted network traffic.
USN-5359-1 fixed vulnerabilities in rsync.
This update provides the corresponding updates for Ubuntu 16.04 ESM.
Original advisory details:
Danilo Ramos discovered that rsync incorrectly handled memory when
performing certain zlib deflating operations. An attacker could use this
issue to cause rsync to crash, resulting in a denial of service, or
possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Apple
CVE-2018-25032: macOS Big Sur 11.6.6
vendor_apple·2022-05-16·CVSS 7.5
CVE-2018-25032 [HIGH] CVE-2018-25032: macOS Big Sur 11.6.6
Apple Security Update: About the security content of macOS Big Sur 11.6.6
Product: macOS Big Sur
Version: 11.6.6
CVE: CVE-2018-25032
Component: CVE-2022-0530
Impact: An attacker may be able to cause unexpected application termination or arbitrary code execution
Description: A memory corruption issue was addressed with improved input validation.
Apple
CVE-2018-25032: macOS Monterey 12.4
vendor_apple·2022-05-16·CVSS 7.5
CVE-2018-25032 [HIGH] CVE-2018-25032: macOS Monterey 12.4
Apple Security Update: About the security content of macOS Monterey 12.4
Product: macOS Monterey
Version: 12.4
CVE: CVE-2018-25032
Component: CVE-2022-0530
Impact: An attacker may be able to cause unexpected application termination or arbitrary code execution
Description: A memory corruption issue was addressed with improved input validation.
Apple
CVE-2018-25032: Security Update 2022-004 Catalina
vendor_apple·2022-05-16·CVSS 7.5
CVE-2018-25032 [HIGH] CVE-2018-25032: Security Update 2022-004 Catalina
Apple Security Update: About the security content of Security Update 2022-004 Catalina
Product: Security Update 2022-004 Catalina
CVE: CVE-2018-25032
Component: CVE-2022-0530
Impact: An attacker may be able to cause unexpected application termination or arbitrary code execution
Description: A memory corruption issue was addressed with improved input validation.
BSD
FreeBSD-SA-22:08.zlib: zlib compression out-of-bounds write
bsd_advisories·2022-04-06·CVSS 7.5
CVE-2018-25032 [HIGH] FreeBSD-SA-22:08.zlib: zlib compression out-of-bounds write
FreeBSD-SA-22:08.zlib Security Advisory
The FreeBSD Project
Topic: zlib compression out-of-bounds write
Category: zlib
Module: contrib
Announced: 2022-04-06
Credits: Danilo Ramos of Eideticom
Tavis Ormandy of Google Project Zero
Affects: All supported versions of FreeBSD.
Corrected: 2022-04-04 19:30:33 UTC (stable/13, 13.1-STABLE)
2022-04-04 20:02:42 UTC (releng/13.1, 13.1-RC1-p1)
2022-04-06 03:04:19 UTC (releng/13.0, 13.0-RELEASE-p11)
2022-04-04 01:07:59 UTC (stable/12, 12.3-STABLE)
2022-04-06 03:06:39 UTC (releng/12.3, 12.3-RELEASE-p5)
CVE Name: CVE-2018-25032
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
zlib is a compression library used by numer
Ubuntu
rsync vulnerability
vendor_ubuntu·2022-03-31
CVE-2018-25032 rsync vulnerability
Title: rsync vulnerability
Summary: rsync could be made to crash or run programs if it received specially
crafted network traffic.
Danilo Ramos discovered that rsync incorrectly handled memory when
performing certain zlib deflating operations. An attacker could use this
issue to cause rsync to crash, resulting in a denial of service, or
possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
zlib vulnerability
vendor_ubuntu·2022-03-30
CVE-2018-25032 zlib vulnerability
Title: zlib vulnerability
Summary: zlib could be made to crash or run programs if it received specially
crafted input.
Danilo Ramos discovered that zlib incorrectly handled memory when
performing certain deflating operations. An attacker could use this issue
to cause zlib to crash, resulting in a denial of service, or possibly
execute arbitrary code.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Ubuntu
zlib vulnerability
vendor_ubuntu·2022-03-30
CVE-2018-25032 zlib vulnerability
Title: zlib vulnerability
Summary: zlib could be made to crash or run programs if it received specially
crafted input.
USN-5355-1 fixed a vulnerability in zlib. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
Original advisory details:
Danilo Ramos discovered that zlib incorrectly handled memory when
performing certain deflating operations. An attacker could use this issue
to cause zlib to crash, resulting in a denial of service, or possibly
execute arbitrary code.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Microsoft
zlib before 1.2.12 allows memory corruption when deflating (i.e. when compressing) if the input has many distant matches.
vendor_msrc·2022-03-08·CVSS 7.5
CVE-2018-25032 [HIGH] CWE-787 zlib before 1.2.12 allows memory corruption when deflating (i.e. when compressing) if the input has many distant matches.
zlib before 1.2.12 allows memory corruption when deflating (i.e. when compressing) if the input has many distant matches.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
mitre: mitre
Customer Action Required
Red Hat
zlib: A flaw found in zlib when compressing (not decompressing) certain inputs
vendor_redhat·2018-04-20·CVSS 7.5
CVE-2018-25032 [HIGH] CWE-119 zlib: A flaw found in zlib when compressing (not decompressing) certain inputs
zlib: A flaw found in zlib when compressing (not decompressing) certain inputs
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
An out-of-bounds access flaw was found in zlib, which allows memory corruption when deflating (ex: when compressing) if the input has many distant matches. For some rare inputs with a large number of distant matches (crafted payloads), the buffer into which the compressed or deflated data is written can overwrite the distance symbol table which it overlays. This issue results in corrupted output due to invalid distances, which leads to out-of-bound access, corrupting the memory and potentially crashing the application.
Statement: This bug was introduced in zlib v1.2.2.2 through zlib v1.2.
Debian
CVE-2018-25032: libz-mingw-w64 - zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressi...
vendor_debian·2018·CVSS 7.5
CVE-2018-25032 [HIGH] CVE-2018-25032: libz-mingw-w64 - zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressi...
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
Scope: local
bookworm: resolved (fixed in 1.2.11+dfsg-5)
bullseye: open
forky: resolved (fixed in 1.2.11+dfsg-5)
sid: resolved (fixed in 1.2.11+dfsg-5)
trixie: resolved (fixed in 1.2.11+dfsg-5)
VulDB
Oracle PeopleSoft Enterprise PeopleTools 8.58/8.59 PeopleSoft CDA denial of service (EUVD-2022-1454 / Nessus ID 215308)
vuldb·2026-07-14·CVSS 7.5
CVE-2018-25032 [HIGH] Oracle PeopleSoft Enterprise PeopleTools 8.58/8.59 PeopleSoft CDA denial of service (EUVD-2022-1454 / Nessus ID 215308)
A vulnerability, which was classified as critical, was found in Oracle PeopleSoft Enterprise PeopleTools 8.58/8.59. This issue affects some unknown processing of the component PeopleSoft CDA. Executing a manipulation can lead to denial of service.
This vulnerability is tracked as CVE-2018-25032. The attack can be launched remotely. No exploit exists.
You should upgrade the affected component.
VulDB
Oracle Communications Cloud Native Core Unified Data Repository UDR denial of service (EUVD-2022-1454 / Nessus ID 215308)
vuldb·2026-07-14·CVSS 7.5
CVE-2018-25032 [HIGH] Oracle Communications Cloud Native Core Unified Data Repository UDR denial of service (EUVD-2022-1454 / Nessus ID 215308)
A vulnerability was found in Oracle Communications Cloud Native Core Unified Data Repository 22.2.0. It has been declared as critical. Affected is an unknown function of the component UDR. Executing a manipulation can lead to denial of service.
This vulnerability is registered as CVE-2018-25032. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.
VulDB
Apple macOS up to 12.3 zlib memory corruption (HT213257 / EUVD-2022-1454)
vuldb·2026-07-14·CVSS 7.5
CVE-2018-25032 [HIGH] Apple macOS up to 12.3 zlib memory corruption (HT213257 / EUVD-2022-1454)
A vulnerability categorized as problematic has been discovered in Apple macOS up to 12.3. Impacted is an unknown function of the component zlib. Executing a manipulation can lead to memory corruption.
The identification of this vulnerability is CVE-2018-25032. The attack can only be executed locally. There is no exploit available.
It is advisable to upgrade the affected component.
VulDB
Oracle Communications Session Border Controller 8.4/9.0/9.1 System denial of service (EUVD-2022-1454 / Nessus ID 236737)
vuldb·2026-07-14·CVSS 7.5
CVE-2018-25032 [HIGH] Oracle Communications Session Border Controller 8.4/9.0/9.1 System denial of service (EUVD-2022-1454 / Nessus ID 236737)
A vulnerability classified as critical was found in Oracle Communications Session Border Controller 8.4/9.0/9.1. This vulnerability affects unknown code of the component System. Executing a manipulation can lead to denial of service.
This vulnerability is handled as CVE-2018-25032. The attack can be executed remotely. There is not any exploit available.
VulDB
Oracle Communications Diameter Signaling Router 8.6.0.0 Platform denial of service (EUVD-2022-1454 / Nessus ID 236737)
vuldb·2026-07-14·CVSS 7.5
CVE-2018-25032 [HIGH] Oracle Communications Diameter Signaling Router 8.6.0.0 Platform denial of service (EUVD-2022-1454 / Nessus ID 236737)
A vulnerability was found in Oracle Communications Diameter Signaling Router 8.6.0.0. It has been rated as critical. The impacted element is an unknown function of the component Platform. Performing a manipulation results in denial of service.
This vulnerability is cataloged as CVE-2018-25032. It is possible to initiate the attack remotely. There is no exploit available.
VulDB
Oracle MySQL Server up to 5.7.38/8.0.29 Compiling denial of service (EUVD-2022-1454 / Nessus ID 215308)
vuldb·2026-07-14·CVSS 7.5
CVE-2018-25032 [HIGH] Oracle MySQL Server up to 5.7.38/8.0.29 Compiling denial of service (EUVD-2022-1454 / Nessus ID 215308)
A vulnerability classified as critical was found in Oracle MySQL Server up to 5.7.38/8.0.29. The impacted element is an unknown function of the component Compiling. Executing a manipulation can lead to denial of service.
This vulnerability is tracked as CVE-2018-25032. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.
VulDB
Oracle Communications Cloud Native Core Network Function Cloud Native Environment DBTier denial of service (EUVD-2022-1454 / Nessus ID 215308)
vuldb·2026-07-14·CVSS 7.5
CVE-2018-25032 [HIGH] Oracle Communications Cloud Native Core Network Function Cloud Native Environment DBTier denial of service (EUVD-2022-1454 / Nessus ID 215308)
A vulnerability described as critical has been identified in Oracle Communications Cloud Native Core Network Function Cloud Native Environment 22.1.0/22.2.0. This impacts an unknown function of the component DBTier. The manipulation results in denial of service.
This vulnerability is known as CVE-2018-25032. It is possible to launch the attack remotely. No exploit is available.
VulDB
Oracle Communications Cloud Native Core Network Exposure Function NEF denial of service (EUVD-2022-1454 / Nessus ID 215308)
vuldb·2026-07-14·CVSS 7.5
CVE-2018-25032 [HIGH] Oracle Communications Cloud Native Core Network Exposure Function NEF denial of service (EUVD-2022-1454 / Nessus ID 215308)
A vulnerability was found in Oracle Communications Cloud Native Core Network Exposure Function 22.1.1. It has been declared as critical. The impacted element is an unknown function of the component NEF. Such manipulation leads to denial of service.
This vulnerability is documented as CVE-2018-25032. The attack can be executed remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
VulDB
Oracle Communications Cloud Native Core Console 22.1.2 CNC Console denial of service (EUVD-2022-1454 / Nessus ID 215308)
vuldb·2026-07-14·CVSS 7.5
CVE-2018-25032 [HIGH] Oracle Communications Cloud Native Core Console 22.1.2 CNC Console denial of service (EUVD-2022-1454 / Nessus ID 215308)
A vulnerability was found in Oracle Communications Cloud Native Core Console 22.1.2. It has been classified as critical. The affected element is an unknown function of the component CNC Console. This manipulation causes denial of service.
This vulnerability is registered as CVE-2018-25032. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
VulDB
Oracle Communications Cloud Native Core Security Edge Protection Proxy Installer denial of service (EUVD-2022-1454 / Nessus ID 215308)
vuldb·2026-07-14·CVSS 7.5
CVE-2018-25032 [HIGH] Oracle Communications Cloud Native Core Security Edge Protection Proxy Installer denial of service (EUVD-2022-1454 / Nessus ID 215308)
A vulnerability, which was classified as critical, was found in Oracle Communications Cloud Native Core Security Edge Protection Proxy 22.1.1. This affects an unknown part of the component Installer. Executing a manipulation can lead to denial of service.
The identification of this vulnerability is CVE-2018-25032. The attack may be launched remotely. There is no exploit available.
VulDB
Oracle Outside In Technology 8.5.6 Outside In Filters denial of service (EUVD-2022-1454 / Nessus ID 236737)
vuldb·2026-07-14·CVSS 7.5
CVE-2018-25032 [HIGH] Oracle Outside In Technology 8.5.6 Outside In Filters denial of service (EUVD-2022-1454 / Nessus ID 236737)
A vulnerability was found in Oracle Outside In Technology 8.5.6. It has been declared as critical. Impacted is an unknown function of the component Outside In Filters. Executing a manipulation can lead to denial of service.
This vulnerability is handled as CVE-2018-25032. The attack can be executed remotely. There is not any exploit available.
VulDB
Oracle Communications Cloud Native Core Security Edge Protection Proxy SEPP denial of service (EUVD-2022-1454 / Nessus ID 215308)
vuldb·2026-07-14·CVSS 7.5
CVE-2018-25032 [HIGH] Oracle Communications Cloud Native Core Security Edge Protection Proxy SEPP denial of service (EUVD-2022-1454 / Nessus ID 215308)
A vulnerability, which was classified as critical, has been found in Oracle Communications Cloud Native Core Security Edge Protection Proxy 22.1.1. Impacted is an unknown function of the component SEPP. The manipulation leads to denial of service.
This vulnerability is referenced as CVE-2018-25032. Remote exploitation of the attack is possible. No exploit is available.
It is advisable to upgrade the affected component.
VulDB
zlib 1.2.11 memory corruption (EUVD-2022-1454 / Nessus ID 215308)
vuldb·2026-07-14·CVSS 7.5
CVE-2018-25032 [HIGH] zlib 1.2.11 memory corruption (EUVD-2022-1454 / Nessus ID 215308)
A vulnerability labeled as critical has been found in zlib 1.2.11. Impacted is an unknown function. Executing a manipulation can lead to memory corruption.
This vulnerability is tracked as CVE-2018-25032. The attack is only possible within the local network. No exploit exists.
It is advisable to implement a patch to correct this issue.
OSV
klibc vulnerabilities
osv·2024-05-23·CVSS 8.8
CVE-2016-9840 [HIGH] klibc vulnerabilities
klibc vulnerabilities
USN-6736-1 fixed vulnerabilities in klibc. This update provides the
corresponding updates for Ubuntu 24.04 LTS.
Original advisory details:
It was discovered that zlib, vendored in klibc, incorrectly handled pointer
arithmetic. An attacker could use this issue to cause klibc to crash or to
possibly execute arbitrary code. (CVE-2016-9840, CVE-2016-9841)
Danilo Ramos discovered that zlib, vendored in klibc, incorrectly handled
memory when performing certain deflating operations. An attacker could use
this issue to cause klibc to crash or to possibly execute arbitrary code.
(CVE-2018-25032)
Evgeny Legerov discovered that zlib, vendored in klibc, incorrectly handled
memory when performing certain inflate operations. An attacker could use
this issue to cause klibc to c
OSV
klibc vulnerabilities
osv·2024-04-16·CVSS 8.8
CVE-2016-9840 [HIGH] klibc vulnerabilities
klibc vulnerabilities
It was discovered that zlib, vendored in klibc, incorrectly handled pointer
arithmetic. An attacker could use this issue to cause klibc to crash or to
possibly execute arbitrary code. (CVE-2016-9840, CVE-2016-9841)
Danilo Ramos discovered that zlib, vendored in klibc, incorrectly handled
memory when performing certain deflating operations. An attacker could use
this issue to cause klibc to crash or to possibly execute arbitrary code.
(CVE-2018-25032)
Evgeny Legerov discovered that zlib, vendored in klibc, incorrectly handled
memory when performing certain inflate operations. An attacker could use
this issue to cause klibc to crash or to possibly execute arbitrary code.
(CVE-2022-37434)
GHSA
Persistent Cross-site Scripting vulnerability in PrivateBin
ghsa·2022-04-12
CVE-2022-24833 [HIGH] CWE-79 Persistent Cross-site Scripting vulnerability in PrivateBin
Persistent Cross-site Scripting vulnerability in PrivateBin
In PrivateBin
alert(document.domain);
```
2. Upload it as an attachment to a PrivateBin instance that has attachments enabled and hasn't set the recommended content security policy (in particular, one that has either no content security policy set or that allows `*` or `blob:` as a `script-src`).
3. Open the paste. (In a real attack scenario this would be done by the victim.)
4. The SVG is rendered safely as a preview, and script isn't yet executed.
5. Now (depending on your device) right-click or long tap on the image and open it in a new tab.
6. Now a `blob:` URI opens in a new tab with the image and the modal is shown, therefore the script got executed.
## Impact
We tried to reproduce the vulnerability and in our asses
OSV
Persistent Cross-site Scripting vulnerability in PrivateBin
osv·2022-04-12
CVE-2022-24833 [HIGH] Persistent Cross-site Scripting vulnerability in PrivateBin
Persistent Cross-site Scripting vulnerability in PrivateBin
In PrivateBin
alert(document.domain);
```
2. Upload it as an attachment to a PrivateBin instance that has attachments enabled and hasn't set the recommended content security policy (in particular, one that has either no content security policy set or that allows `*` or `blob:` as a `script-src`).
3. Open the paste. (In a real attack scenario this would be done by the victim.)
4. The SVG is rendered safely as a preview, and script isn't yet executed.
5. Now (depending on your device) right-click or long tap on the image and open it in a new tab.
6. Now a `blob:` URI opens in a new tab with the image and the modal is shown, therefore the script got executed.
## Impact
We tried to reproduce the vulnerability and in our asses
GHSA
Out-of-bounds Write in zlib affects Nokogiri
ghsa·2022-04-11·CVSS 7.5
CVE-2018-25032 [HIGH] CWE-787 Out-of-bounds Write in zlib affects Nokogiri
Out-of-bounds Write in zlib affects Nokogiri
## Summary
Nokogiri v1.13.4 updates the vendored zlib from 1.2.11 to 1.2.12, which addresses [CVE-2018-25032](https://nvd.nist.gov/vuln/detail/CVE-2018-25032). That CVE is scored as CVSS 7.4 "High" on the NVD record as of 2022-04-05.
Please note that this advisory only applies to the CRuby implementation of Nokogiri `= v1.13.4`.
## Impact
### [CVE-2018-25032](https://nvd.nist.gov/vuln/detail/CVE-2018-25032) in zlib
- **Severity**: High
- **Type**: [CWE-787](https://cwe.mitre.org/data/definitions/787.html) Out of bounds write
- **Description**: zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
OSV
Out-of-bounds Write in zlib affects Nokogiri
osv·2022-04-11·CVSS 7.5
CVE-2018-25032 [HIGH] Out-of-bounds Write in zlib affects Nokogiri
Out-of-bounds Write in zlib affects Nokogiri
## Summary
Nokogiri v1.13.4 updates the vendored zlib from 1.2.11 to 1.2.12, which addresses [CVE-2018-25032](https://nvd.nist.gov/vuln/detail/CVE-2018-25032). That CVE is scored as CVSS 7.4 "High" on the NVD record as of 2022-04-05.
Please note that this advisory only applies to the CRuby implementation of Nokogiri `= v1.13.4`.
## Impact
### [CVE-2018-25032](https://nvd.nist.gov/vuln/detail/CVE-2018-25032) in zlib
- **Severity**: High
- **Type**: [CWE-787](https://cwe.mitre.org/data/definitions/787.html) Out of bounds write
- **Description**: zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
OSV
Nokogiri affected by zlib's Out-of-bounds Write vulnerability
osv·2022-03-26
CVE-2018-25032 [HIGH] Nokogiri affected by zlib's Out-of-bounds Write vulnerability
Nokogiri affected by zlib's Out-of-bounds Write vulnerability
zlib 1.2.11 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
GHSA
Nokogiri affected by zlib's Out-of-bounds Write vulnerability
ghsa·2022-03-26
CVE-2018-25032 [HIGH] CWE-787 Nokogiri affected by zlib's Out-of-bounds Write vulnerability
Nokogiri affected by zlib's Out-of-bounds Write vulnerability
zlib 1.2.11 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
OSV
CVE-2018-25032: zlib before 1
osv·2022-03-25·CVSS 7.5
CVE-2018-25032 [HIGH] CVE-2018-25032: zlib before 1
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
No detection rules found.
No public exploits indexed.
arXiv
Cascade: Composing Software-Hardware Attack Gadgets for Adversarial Threat Amplification in Compound AI Systems
arxiv_fulltext·2026-03-12
Cascade: Composing Software-Hardware Attack Gadgets for Adversarial Threat Amplification in Compound AI Systems
Cascade: Composing Software-Hardware Attack Gadgets for Adversarial Threat Amplification in Compound AI Systems
Sarbartha Banerjee126,\;
Prateek Sahu12,\;
Anjo Vahldiek-Oberwagner3,\;
Jose Sanchez Vicarte5,\;
Mohit Tiwari24 0.3em
2The University of Texas at Austin \;\; 3Intel Labs \;\; 4Symmetry Systems \;\; 5Microsoft \;\; 6Georgia Tech
plain
1
Sarbartha Banerjee and Prateek Sahu are equal contributors.NoHyper
0.3in
## Abstract
Rapid progress in generative AI has given rise to Compound AI systems - pipelines comprised of multiple large language models (LLM), software tools and database systems.
Compound AI systems are constructed on a layered traditional software stack running on a distributed hardware infrastructure.
Many of the diverse software components are vulnerable to tradit
arXiv
SandCell: Sandboxing Rust Beyond Unsafe Code
arxiv_fulltext·2026-01-18
SandCell: Sandboxing Rust Beyond Unsafe Code
: Sandboxing Rust Beyond Unsafe Code
printacmref=false
[1]
plain
Jialun Zhang
Pennsylvania State University
University Park
USA
[email protected]
Merve Gülmez
Ericsson Security Research
Sweden
[email protected]
Thomas Nyman
Ericsson Product Security
Sweden
[email protected]
Gang Tan
Pennsylvania State University
University Park
USA
[email protected]
Anon. Submission Id: 2275
Author(s)
first review cycle of CCS'26
[First review cycle of CCS'26]November 15-19, 2026The Hague, The Netherlands
none
Zhang et al.
## Abstract
Rust is a modern systems programming language that ensures memory safety by
enforcing ownership and borrowing rules at compile time. While the unsafe
keyword allows programmers to bypass these restrictions, it introduces
significant risks. Vario
http://seclists.org/fulldisclosure/2022/May/33http://seclists.org/fulldisclosure/2022/May/35http://seclists.org/fulldisclosure/2022/May/38http://www.openwall.com/lists/oss-security/2022/03/25/2http://www.openwall.com/lists/oss-security/2022/03/26/1https://cert-portal.siemens.com/productcert/pdf/ssa-333517.pdfhttps://github.com/madler/zlib/commit/5c44459c3b28a9bd3283aaceab7c615f8020c531https://github.com/madler/zlib/compare/v1.2.11...v1.2.12https://github.com/madler/zlib/issues/605https://lists.debian.org/debian-lts-announce/2022/04/msg00000.htmlhttps://lists.debian.org/debian-lts-announce/2022/05/msg00008.htmlhttps://lists.debian.org/debian-lts-announce/2022/09/msg00023.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DCZFIJBJTZ7CL5QXBFKTQ22Q26VINRUF/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DF62MVMH3QUGMBDCB3DY2ERQ6EBHTADB/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JZZPTWRYQULAOL3AW7RZJNVZ2UONXCV4/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NS2D2GFPFGOJUL4WQ3DUAY7HF4VWQ77F/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VOKNP2L734AEL47NRYGVZIKEFOUBQY5Y/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XOKFMSNQ5D5WGMALBNBXU3GE442V74WU/https://security.gentoo.org/glsa/202210-42https://security.netapp.com/advisory/ntap-20220526-0009/https://security.netapp.com/advisory/ntap-20220729-0004/https://support.apple.com/kb/HT213255https://support.apple.com/kb/HT213256https://support.apple.com/kb/HT213257https://www.debian.org/security/2022/dsa-5111https://www.openwall.com/lists/oss-security/2022/03/24/1https://www.openwall.com/lists/oss-security/2022/03/28/1https://www.openwall.com/lists/oss-security/2022/03/28/3https://www.oracle.com/security-alerts/cpujul2022.htmlhttp://seclists.org/fulldisclosure/2022/May/33http://seclists.org/fulldisclosure/2022/May/35http://seclists.org/fulldisclosure/2022/May/38http://www.openwall.com/lists/oss-security/2022/03/25/2http://www.openwall.com/lists/oss-security/2022/03/26/1https://cert-portal.siemens.com/productcert/pdf/ssa-333517.pdfhttps://github.com/madler/zlib/commit/5c44459c3b28a9bd3283aaceab7c615f8020c531https://github.com/madler/zlib/compare/v1.2.11...v1.2.12https://github.com/madler/zlib/issues/605https://lists.debian.org/debian-lts-announce/2022/04/msg00000.htmlhttps://lists.debian.org/debian-lts-announce/2022/05/msg00008.htmlhttps://lists.debian.org/debian-lts-announce/2022/09/msg00023.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DCZFIJBJTZ7CL5QXBFKTQ22Q26VINRUF/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DF62MVMH3QUGMBDCB3DY2ERQ6EBHTADB/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JZZPTWRYQULAOL3AW7RZJNVZ2UONXCV4/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NS2D2GFPFGOJUL4WQ3DUAY7HF4VWQ77F/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VOKNP2L734AEL47NRYGVZIKEFOUBQY5Y/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XOKFMSNQ5D5WGMALBNBXU3GE442V74WU/https://security.gentoo.org/glsa/202210-42https://security.netapp.com/advisory/ntap-20220526-0009/https://security.netapp.com/advisory/ntap-20220729-0004/https://support.apple.com/kb/HT213255https://support.apple.com/kb/HT213256https://support.apple.com/kb/HT213257https://www.debian.org/security/2022/dsa-5111https://www.openwall.com/lists/oss-security/2022/03/24/1https://www.openwall.com/lists/oss-security/2022/03/28/1https://www.openwall.com/lists/oss-security/2022/03/28/3https://www.oracle.com/security-alerts/cpujul2022.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-333517.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-398330.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-419740.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-470355.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-565386.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-942865.html
2022-03-25
Published