CVE-2025-1220
published 2025-07-13CVE-2025-1220: In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 some functions like fsockopen() lack validation that the…
PriorityP429medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.54%
43.5th percentile
In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 some functions like fsockopen() lack validation that the hostname supplied does not contain null characters. This may lead to other functions like parse_url() treat the hostname in different way, thus opening way to security problems if the user code implements access checks before access using such functions.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | php7.4 | < php7.4 7.4.33-1+deb11u9 (bullseye) | php7.4 7.4.33-1+deb11u9 (bullseye) |
| debian | php8.2 | < php7.4 7.4.33-1+deb11u9 (bullseye) | php7.4 7.4.33-1+deb11u9 (bullseye) |
| debian | php8.4 | < php7.4 7.4.33-1+deb11u9 (bullseye) | php7.4 7.4.33-1+deb11u9 (bullseye) |
| gitlab | gitlab | — | — |
| gitlab | gitlab_ce | — | — |
| gitlab | gitlab_ee | — | — |
| msrc | azl3_php_8.3.23-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_php_8.3.29-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_ceph_16.2.10-4_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_ceph_16.2.10-7_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_php_8.1.32-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_php_8.1.33-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | microsoft_visual_studio_2017_version_15.9 | — | — |
| msrc | microsoft_visual_studio_2019_version_16.11 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.10 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.12 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.13 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.8 | — | — |
| php | php | >= 8.1.0 < 8.1.33 | 8.1.33 |
| php | php | >= 8.2.0 < 8.2.29 | 8.2.29 |
| php | php | >= 8.3.0 < 8.3.23 | 8.3.23 |
| php | php | >= 8.4.0 < 8.4.10 | 8.4.10 |
| php_group | php | >= 8.1.* < 8.1.33 | 8.1.33 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
osv5.3MEDIUM
vendor_redhat9.1CRITICAL
vendor_cisco7.4HIGH
vendor_msrc6.5MEDIUM
vendor_debian3.7LOW
vendor_ubuntu3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
php7.0, php7.2, php7.4 regression
osv·2025-09-04·CVSS 5.3
CVE-2025-1735 [MEDIUM] php7.0, php7.2, php7.4 regression
php7.0, php7.2, php7.4 regression
USN-7648-2 fixed vulnerabilities in PHP. The patch for CVE-2025-1735
caused a regression in php7.0, php7.2 and php7.4. This update fixes
the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that PHP incorrectly handled certain hostnames containing
null characters. A remote attacker could possibly use this issue to bypass
certain hostname validation checks. (CVE-2025-1220)
It was discovered that PHP incorrectly handled the pgsql and pdo_pgsql
escaping functions. A remote attacker could possibly use this issue to
cause PHP to crash, resulting in a denial of service. (CVE-2025-1735)
It was discovered that PHP incorrectly handled parsing certain XML data in
SOAP extensions. A remote attacker could possibly use thi
OSV
php7.0, php7.2, php7.4 vulnerabilities
osv·2025-08-21·CVSS 5.3
CVE-2025-1220 [MEDIUM] php7.0, php7.2, php7.4 vulnerabilities
php7.0, php7.2, php7.4 vulnerabilities
USN-7648-1 fixed several vulnerabilities in PHP. This update
provides the corresponding updates for Ubuntu 16.04 LTS, Ubuntu
18.04 LTS, and Ubuntu 20.04 LTS.
Original advisory details:
It was discovered that PHP incorrectly handled certain hostnames containing
null characters. A remote attacker could possibly use this issue to bypass
certain hostname validation checks. (CVE-2025-1220)
It was discovered that PHP incorrectly handled the pgsql and pdo_pgsql
escaping functions. A remote attacker could possibly use this issue to
cause PHP to crash, resulting in a denial of service. (CVE-2025-1735)
It was discovered that PHP incorrectly handled parsing certain XML data in
SOAP extensions. A remote attacker could possibly use this issue to cause
PHP to
OSV
php8.1, php8.3, php8.4 vulnerabilities
osv·2025-07-17·CVSS 5.3
CVE-2025-1220 [MEDIUM] php8.1, php8.3, php8.4 vulnerabilities
php8.1, php8.3, php8.4 vulnerabilities
It was discovered that PHP incorrectly handled certain hostnames containing
null characters. A remote attacker could possibly use this issue to bypass
certain hostname validation checks. (CVE-2025-1220)
It was discovered that PHP incorrectly handled the pgsql and pdo_pgsql
escaping functions. A remote attacker could possibly use this issue to
cause PHP to crash, resulting in a denial of service. (CVE-2025-1735)
It was discovered that PHP incorrectly handled parsing certain XML data in
SOAP extensions. A remote attacker could possibly use this issue to cause
PHP to crash, resulting in a denial of service. (CVE-2025-6491)
OSV
CVE-2025-1220: In PHP versions:8
osv·2025-07-13·CVSS 5.3
CVE-2025-1220 [MEDIUM] CVE-2025-1220: In PHP versions:8
In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 some functions like fsockopen() lack validation that the hostname supplied does not contain null characters. This may lead to other functions like parse_url() treat the hostname in different way, thus opening way to security problems if the user code implements access checks before access using such functions.
Red Hat
kernel: xen: AMD Zen 2 Processors: Privilege escalation via improper CPU cache isolation
vendor_redhat·2026-05-15·CVSS 7.3
CVE-2025-54518 [HIGH] CWE-1220 kernel: xen: AMD Zen 2 Processors: Privilege escalation via improper CPU cache isolation
kernel: xen: AMD Zen 2 Processors: Privilege escalation via improper CPU cache isolation
Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a different privilege level, potentially resulting in privilege escalation.
A flaw was found in AMD Zen 2-based processors, affecting components such as the kernel and Xen hypervisor. Improper isolation of shared resources within the CPU operation cache could allow an attacker to corrupt instructions executed at a different privilege level. This could potentially result in privilege escalation, granting an attacker higher system access than intended.
Package: kernel (Red Hat Enterprise Linux 10) - Affected
Package: libkrun (Red Hat Enterprise Linu
Red Hat
microcode_ctl: Microcode: Loss of SEV-SNP guest integrity via NBIO register modification
vendor_redhat·2026-05-13·CVSS 5.9
CVE-2025-61971 [MEDIUM] CWE-1220 microcode_ctl: Microcode: Loss of SEV-SNP guest integrity via NBIO register modification
microcode_ctl: Microcode: Loss of SEV-SNP guest integrity via NBIO register modification
Missing lock bit protection for NBIO registers could allow a local admin-privileged attacker to modify MMIO routing configurations, potentially resulting in loss of SEV-SNP guest integrity.
A flaw was found in the microcode that manages NBIO registers. A local attacker with administrative privileges could exploit a missing security control, allowing them to alter critical system configurations. This could compromise the integrity of virtual machines protected by Secure Encrypted Virtualization-Secure Nested Paging (SEV-SNP), potentially leading to unauthorized data tampering or execution within the guest.
Mitigation: Mitigation for this issue is either not available or the currently available option
Red Hat
fastmcp: FastMCP: Improper token issuance due to incorrect resource parameter handling
vendor_redhat·2026-03-16·CVSS 7.4
CVE-2025-69196 [HIGH] CWE-1220 fastmcp: FastMCP: Improper token issuance due to incorrect resource parameter handling
fastmcp: FastMCP: Improper token issuance due to incorrect resource parameter handling
FastMCP is the standard framework for building MCP applications. Prior to version 2.14.2, the server does not properly respect the resource parameter submitted by the client in the authorization and token request. Instead of issuing the token explicitly for the MCP server, the token is issued for the base_url passed to the OAuthProxy during initialization. This issue has been patched 2.14.2.
A flaw was found in FastMCP, a framework for building MCP applications. The server does not correctly process the resource parameter provided by the client during authorization and token requests. This can lead to security tokens being issued for an unintended base URL (Uniform Resource Locator) instead of the spec
Red Hat
Intel (R): From CVEorg collector
vendor_redhat·2026-02-10·CVSS 7.0
CVE-2025-35998 [HIGH] CWE-1220 Intel (R): From CVEorg collector
Intel (R): From CVEorg collector
Missing protection mechanism for alternate hardware interface in the Intel(R) Quick Assist Technology for some Intel(R) Platforms within Ring 0: Kernel may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Missing protection mechanism for alternate hardware interfa
GitLab
CVE-2025-11246: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.4 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could h
vendor_gitlab·2026-01-09·CVSS 5.4
CVE-2025-11246 [MEDIUM] CWE-1220 CVE-2025-11246: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.4 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could h
CVE-2025-11246: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.4 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user with specific permissions to remove all project runners from unrelated projects by manipulating GraphQL runner associations.
Red Hat
Apptainer: Apptainer: Security bypass due to disabling security options
vendor_redhat·2025-12-02·CVSS 4.5
CVE-2025-65105 [MEDIUM] CWE-1220 Apptainer: Apptainer: Security bypass due to disabling security options
Apptainer: Apptainer: Security bypass due to disabling security options
Apptainer is an open source container platform. In Apptainer versions less than 1.4.5, a container can disable two of the forms of the little used --security option, in particular the forms --security=apparmor: and --security=selinux: which otherwise put restrictions on operations that containers can do. The --security option has always been mentioned in Apptainer documentation as being a feature for the root user, although these forms do also work for unprivileged users on systems where the corresponding feature is enabled. Apparmor is enabled by default on Debian-based distributions and SElinux is enabled by default on RHEL-based distributions, but on SUSE it depends on the distribution version. This vulnerability i
Cisco
Cisco Identity Services Engine Reflected Cross-Site Scripting and Information Disclosure Vulnerabilities
vendor_cisco·2025-11-05·CVSS 5.4
CVE-2025-20289 [MEDIUM] CWE-1220 Cisco Identity Services Engine Reflected Cross-Site Scripting and Information Disclosure Vulnerabilities
Cisco Identity Services Engine Reflected Cross-Site Scripting and Information Disclosure Vulnerabilities
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to either disclose sensitive information or conduct a reflected cross-site scripting (XSS) attack.
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multiple-vulns-O9BESWJH
Ubuntu
PHP regression
vendor_ubuntu·2025-09-04·CVSS 3.7
CVE-2025-1735 [LOW] PHP regression
Title: PHP regression
Summary: USN-7648-2 introduced a regression in PHP
USN-7648-2 fixed vulnerabilities in PHP. The patch for CVE-2025-1735
caused a regression in php7.0, php7.2 and php7.4. This update fixes
the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that PHP incorrectly handled certain hostnames containing
null characters. A remote attacker could possibly use this issue to bypass
certain hostname validation checks. (CVE-2025-1220)
It was discovered that PHP incorrectly handled the pgsql and pdo_pgsql
escaping functions. A remote attacker could possibly use this issue to
cause PHP to crash, resulting in a denial of service. (CVE-2025-1735)
It was discovered that PHP incorrectly handled parsing certain XML data in
SOAP extensions.
Ubuntu
PHP vulnerabilities
vendor_ubuntu·2025-08-21·CVSS 3.7
CVE-2025-1220 [LOW] PHP vulnerabilities
Title: PHP vulnerabilities
Summary: Several security issues were fixed in PHP.
USN-7648-1 fixed several vulnerabilities in PHP. This update
provides the corresponding updates for Ubuntu 16.04 LTS, Ubuntu
18.04 LTS, and Ubuntu 20.04 LTS.
Original advisory details:
It was discovered that PHP incorrectly handled certain hostnames containing
null characters. A remote attacker could possibly use this issue to bypass
certain hostname validation checks. (CVE-2025-1220)
It was discovered that PHP incorrectly handled the pgsql and pdo_pgsql
escaping functions. A remote attacker could possibly use this issue to
cause PHP to crash, resulting in a denial of service. (CVE-2025-1735)
It was discovered that PHP incorrectly handled parsing certain XML data in
SOAP extensions. A remote attacker could
GitLab
CVE-2025-2498: An improper access control in Gitlab EE affecting all versions from 12.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that under ce
vendor_gitlab·2025-08-13·CVSS 3.1
CVE-2025-2498 [LOW] CWE-1220 CVE-2025-2498: An improper access control in Gitlab EE affecting all versions from 12.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that under ce
CVE-2025-2498: An improper access control in Gitlab EE affecting all versions from 12.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that under certain conditions could have allowed users to view assigned issues from restricted groups by bypassing IP restrictions.
GitLab
CVE-2025-7001: An issue has been discovered in GitLab CE/EE affecting all versions from 15.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could hav
vendor_gitlab·2025-07-24·CVSS 4.3
CVE-2025-7001 [MEDIUM] CWE-1220 CVE-2025-7001: An issue has been discovered in GitLab CE/EE affecting all versions from 15.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could hav
CVE-2025-7001: An issue has been discovered in GitLab CE/EE affecting all versions from 15.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed priviledged users to access certain resource_group information through the API which should have been unavailable.
Ubuntu
PHP vulnerabilities
vendor_ubuntu·2025-07-17·CVSS 3.7
CVE-2025-1735 [LOW] PHP vulnerabilities
Title: PHP vulnerabilities
Summary: Several security issues were fixed in PHP.
It was discovered that PHP incorrectly handled certain hostnames containing
null characters. A remote attacker could possibly use this issue to bypass
certain hostname validation checks. (CVE-2025-1220)
It was discovered that PHP incorrectly handled the pgsql and pdo_pgsql
escaping functions. A remote attacker could possibly use this issue to
cause PHP to crash, resulting in a denial of service. (CVE-2025-1735)
It was discovered that PHP incorrectly handled parsing certain XML data in
SOAP extensions. A remote attacker could possibly use this issue to cause
PHP to crash, resulting in a denial of service. (CVE-2025-6491)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
php: PHP Hostname Null Character Vulnerability
vendor_redhat·2025-07-13·CVSS 3.7
CVE-2025-1220 [LOW] CWE-918 php: PHP Hostname Null Character Vulnerability
php: PHP Hostname Null Character Vulnerability
In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 some functions like fsockopen() lack validation that the hostname supplied does not contain null characters. This may lead to other functions like parse_url() treat the hostname in different way, thus opening way to security problems if the user code implements access checks before access using such functions.
A flaw was found in PHP. The `fsockopen()` function and related functions fail to validate NULL characters within the provided hostname, potentially leading to unexpected behavior during parsing. This flaw allows a network attacker to supply a specially crafted hostname. This issue can result in a denial of service due to parsing errors.
Microsoft
Null byte termination in hostnames
vendor_msrc·2025-07-08·CVSS 3.7
CVE-2025-1220 [LOW] CWE-918 Null byte termination in hostnames
Null byte termination in hostnames
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
php: php
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azur
GitLab
CVE-2025-5982: An issue has been discovered in GitLab EE affecting all versions from 12.0 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Under certain
vendor_gitlab·2025-06-12·CVSS 3.7
CVE-2025-5982 [LOW] CWE-1220 CVE-2025-5982: An issue has been discovered in GitLab EE affecting all versions from 12.0 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Under certain
CVE-2025-5982: An issue has been discovered in GitLab EE affecting all versions from 12.0 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Under certain conditions users could bypass IP access restrictions and view sensitive information.
GitLab
CVE-2025-4979: An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. An attacker may be a
vendor_gitlab·2025-05-22·CVSS 4.9
CVE-2025-4979 [MEDIUM] CWE-1220 CVE-2025-4979: An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. An attacker may be a
CVE-2025-4979: An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. An attacker may be able to reveal masked or hidden CI variables (that they did not author) in the WebUI, by simply creating their own variable and observing the HTTP response.
GitLab
CVE-2025-1110: An issue has been discovered in GitLab CE/EE affecting all versions from 18.0 before 18.0.1. In certain circumstances, a user with limited permissions
vendor_gitlab·2025-05-22·CVSS 2.7
CVE-2025-1110 [LOW] CWE-1220 CVE-2025-1110: An issue has been discovered in GitLab CE/EE affecting all versions from 18.0 before 18.0.1. In certain circumstances, a user with limited permissions
CVE-2025-1110: An issue has been discovered in GitLab CE/EE affecting all versions from 18.0 before 18.0.1. In certain circumstances, a user with limited permissions could access Job Data via a crafted GraphQL query.
Microsoft
Visual Studio Information Disclosure Vulnerability
vendor_msrc·2025-05-13·CVSS 5.5
CVE-2025-32703 [MEDIUM] CWE-1220 Visual Studio Information Disclosure Vulnerability
Visual Studio Information Disclosure Vulnerability
Description: Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locally.
FAQ: What type of information could be disclosed by this vulnerability?
Exploiting this vulnerability could allow the disclosure of certain memory address within kernel space. Knowing the exact location of kernel memory could be potentially leveraged by an attacker for other malicious activities.
Visual Studio: Visual Studio
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Information Disclosure
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely
Remediation: Release Notes
Reference: http://aka.ms/vs/15/release/latest
Reference: https://do
GitLab
CVE-2025-1278: An issue has been discovered in GitLab CE/EE affecting all versions from 12.0 before 17.9.8, 17.10 before 17.10.6, and 17.11 before 17.11.2. Under cer
vendor_gitlab·2025-05-09·CVSS 5.3
CVE-2025-1278 [MEDIUM] CWE-1220 CVE-2025-1278: An issue has been discovered in GitLab CE/EE affecting all versions from 12.0 before 17.9.8, 17.10 before 17.10.6, and 17.11 before 17.11.2. Under cer
CVE-2025-1278: An issue has been discovered in GitLab CE/EE affecting all versions from 12.0 before 17.9.8, 17.10 before 17.10.6, and 17.11 before 17.11.2. Under certain conditions users could bypass IP access restrictions and view sensitive information.
Red Hat
thunderbird: Leak of hashed Window credentials via crafted attachment URL
vendor_redhat·2025-04-15·CVSS 6.3
CVE-2025-3522 [MEDIUM] CWE-1220 thunderbird: Leak of hashed Window credentials via crafted attachment URL
thunderbird: Leak of hashed Window credentials via crafted attachment URL
Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally. When an email is opened, Thunderbird accesses the specified URL to determine file size, and navigates to it when the user clicks the attachment. Because the URL is not validated or sanitized, it can reference internal resources like chrome:// or SMB share file:// links, potentially leading to hashed Windows credential leakage and opening the door to more serious security issues. This vulnerability affects Thunderbird < 137.0.2 and Thunderbird < 128.9.2.
A flaw was found in Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue: Thunderbird processes the X-Mozilla-Ex
GitLab
CVE-2025-2408: An issue has been discovered in GitLab CE/EE affecting all versions from 13.12 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under cert
vendor_gitlab·2025-04-10·CVSS 5.3
CVE-2025-2408 [MEDIUM] CWE-1220 CVE-2025-2408: An issue has been discovered in GitLab CE/EE affecting all versions from 13.12 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under cert
CVE-2025-2408: An issue has been discovered in GitLab CE/EE affecting all versions from 13.12 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under certain conditions users could bypass IP access restrictions and view sensitive information.
Cisco
Cisco Nexus 3000 and 9000 Series Switches Health Monitoring Diagnostics Denial of Service Vulnerability
vendor_cisco·2025-02-26·CVSS 7.4
CVE-2025-20111 [HIGH] CWE-1220 Cisco Nexus 3000 and 9000 Series Switches Health Monitoring Diagnostics Denial of Service Vulnerability
Cisco Nexus 3000 and 9000 Series Switches Health Monitoring Diagnostics Denial of Service Vulnerability
A vulnerability in the health monitoring diagnostics of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, adjacent attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.
This vulnerability is due to the incorrect handling of specific Ethernet frames. An attacker could exploit this vulnerability by sending a sustained rate of crafted Ethernet frames to an affected device. A successful exploit could allow the attacker to cause the device to reload.
Cisco has released software updates that address this vulnerability. There are workarounds that address this vulnerab
Debian
CVE-2025-1220: php7.4 - In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8...
vendor_debian·2025·CVSS 3.7
CVE-2025-1220 [LOW] CVE-2025-1220: php7.4 - In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8...
In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 some functions like fsockopen() lack validation that the hostname supplied does not contain null characters. This may lead to other functions like parse_url() treat the hostname in different way, thus opening way to security problems if the user code implements access checks before access using such functions.
Scope: local
bullseye: resolved (fixed in 7.4.33-1+deb11u9)
Microsoft
IBM Spectrum Fusion HCI improper access control
vendor_msrc·2024-05-14·CVSS 6.5
CVE-2023-43040 [MEDIUM] CWE-1220 IBM Spectrum Fusion HCI improper access control
IBM Spectrum Fusion HCI improper access control
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
ibm: ibm
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.c
Cisco
Cisco Identity Services Engine Reflected Cross-Site Scripting and Information Disclosure Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2025-20304 [MEDIUM] Cisco Identity Services Engine Reflected Cross-Site Scripting and Information Disclosure Vulnerabilities
CVE-2025-20304: Cisco Identity Services Engine Reflected Cross-Site Scripting and Information Disclosure Vulnerabilities
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to either disclose sensitive information or conduct a reflected cross-site scripting (XSS) attack. For more information about these vulnerabilities, see the
Severity: medium
CVSS: 3.1
CWE: CWE-1220, CWE-79, CWE-1220, CWE-79
Bug IDs: CSCwo37181, CSCwo37212, CSCwo37216, CSCwo37181, CSCwo37212
Cisco
Cisco Identity Services Engine Reflected Cross-Site Scripting and Information Disclosure Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2025-20305 [MEDIUM] Cisco Identity Services Engine Reflected Cross-Site Scripting and Information Disclosure Vulnerabilities
CVE-2025-20305: Cisco Identity Services Engine Reflected Cross-Site Scripting and Information Disclosure Vulnerabilities
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to either disclose sensitive information or conduct a reflected cross-site scripting (XSS) attack. For more information about these vulnerabilities, see the
Severity: medium
CVSS: 3.1
CWE: CWE-1220, CWE-79, CWE-1220, CWE-79
Bug IDs: CSCwo37181, CSCwo37212, CSCwo37216, CSCwo37181, CSCwo37212
Cisco
Cisco Identity Services Engine Reflected Cross-Site Scripting and Information Disclosure Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2025-20289 [MEDIUM] Cisco Identity Services Engine Reflected Cross-Site Scripting and Information Disclosure Vulnerabilities
CVE-2025-20289: Cisco Identity Services Engine Reflected Cross-Site Scripting and Information Disclosure Vulnerabilities
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to either disclose sensitive information or conduct a reflected cross-site scripting (XSS) attack. For more information about these vulnerabilities, see the
Severity: medium
CVSS: 3.1
CWE: CWE-1220, CWE-79, CWE-1220, CWE-79
Bug IDs: CSCwo37181, CSCwo37212, CSCwo37216, CSCwo37181, CSCwo37212
Cisco
Cisco Identity Services Engine Reflected Cross-Site Scripting and Information Disclosure Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2025-20303 [MEDIUM] Cisco Identity Services Engine Reflected Cross-Site Scripting and Information Disclosure Vulnerabilities
CVE-2025-20303: Cisco Identity Services Engine Reflected Cross-Site Scripting and Information Disclosure Vulnerabilities
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to either disclose sensitive information or conduct a reflected cross-site scripting (XSS) attack. For more information about these vulnerabilities, see the
Severity: medium
CVSS: 3.1
CWE: CWE-1220, CWE-79, CWE-1220, CWE-79
Bug IDs: CSCwo37181, CSCwo37212, CSCwo37216, CSCwo37181, CSCwo37212
Cisco
Cisco Nexus 3000 and 9000 Series Switches Health Monitoring Diagnostics Denial of Service Vulnerability
vendor_cisco·CVSS 3.1
CVE-2025-20111 Cisco Nexus 3000 and 9000 Series Switches Health Monitoring Diagnostics Denial of Service Vulnerability
CVE-2025-20111: Cisco Nexus 3000 and 9000 Series Switches Health Monitoring Diagnostics Denial of Service Vulnerability
A vulnerability in the health monitoring diagnostics of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, adjacent attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to the incorrect handling of specific Ethernet frames. An attacker could exploit this vulnerability by sending a sustained rate of crafted Ethernet frames to an affected device. A successful exploit could allow the attacker to cause the device to reload. Cisco has released software updates that address this vulnerability. There are
CVSS: 3.1
CWE: CWE-1220,
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-07-13
Published