
CVE-2025-3360 – Glibc: glib prior to 2.82.5 is vulnerable to integer overflow and buffer under-read when parsing a very long invalid iso 8601 timestamp with g_date_time_new_from_iso8601().
https://notcve.org/view.php?id=CVE-2025-3360
07 Apr 2025 — A flaw was found in GLib. An integer overflow and buffer under-read occur when parsing a long invalid ISO 8601 timestamp with the g_date_time_new_from_iso8601() function. • https://access.redhat.com/security/cve/CVE-2025-3360 • CWE-190: Integer Overflow or Wraparound •

CVE-2025-3359 – Gnuplot: segmentation fault via io_str_init_static_internal function
https://notcve.org/view.php?id=CVE-2025-3359
07 Apr 2025 — A flaw was found in GNUPlot. A segmentation fault via IO_str_init_static_internal may jeopardize the environment. • https://access.redhat.com/security/cve/CVE-2025-3359 • CWE-754: Improper Check for Unusual or Exceptional Conditions •

CVE-2025-32053 – Libsoup: heap buffer overflows in sniff_feed_or_html() and skip_insignificant_space()
https://notcve.org/view.php?id=CVE-2025-32053
03 Apr 2025 — A flaw was found in libsoup. A vulnerability in sniff_feed_or_html() and skip_insignificant_space() functions may lead to a heap buffer over-read. • https://access.redhat.com/security/cve/CVE-2025-32053 • CWE-126: Buffer Over-read •

CVE-2025-32052 – Libsoup: heap buffer overflow in sniff_unknown()
https://notcve.org/view.php?id=CVE-2025-32052
03 Apr 2025 — A flaw was found in libsoup. A vulnerability in the sniff_unknown() function may lead to heap buffer over-read. • https://access.redhat.com/security/cve/CVE-2025-32052 • CWE-126: Buffer Over-read •

CVE-2025-32051 – Libsoup: segmentation fault when parsing malformed data uri
https://notcve.org/view.php?id=CVE-2025-32051
03 Apr 2025 — A flaw was found in libsoup. The libsoup soup_uri_decode_data_uri() function may crash when processing malformed data URI. This flaw allows an attacker to cause a denial of service (DoS). • https://access.redhat.com/security/cve/CVE-2025-32051 • CWE-754: Improper Check for Unusual or Exceptional Conditions •

CVE-2025-32050 – Libsoup: integer overflow in append_param_quoted
https://notcve.org/view.php?id=CVE-2025-32050
03 Apr 2025 — A flaw was found in libsoup. The libsoup append_param_quoted() function may contain an overflow bug resulting in a buffer under-read. • https://access.redhat.com/security/cve/CVE-2025-32050 • CWE-127: Buffer Under-read •

CVE-2025-32049 – Libsoup: denial of service attack to websocket server
https://notcve.org/view.php?id=CVE-2025-32049
03 Apr 2025 — A flaw was found in libsoup. The SoupWebsocketConnection may accept a large WebSocket message, which may cause libsoup to allocate memory and lead to a denial of service (DoS). • https://access.redhat.com/security/cve/CVE-2025-32049 • CWE-770: Allocation of Resources Without Limits or Throttling •

CVE-2025-3155 – Yelp: arbitrary file read
https://notcve.org/view.php?id=CVE-2025-3155
03 Apr 2025 — A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment. • https://access.redhat.com/security/cve/CVE-2025-3155 • CWE-829: Inclusion of Functionality from Untrusted Control Sphere •

CVE-2025-3136 – PyTorch CUDACachingAllocator.cpp torch.cuda.memory.caching_allocator_delete memory corruption
https://notcve.org/view.php?id=CVE-2025-3136
03 Apr 2025 — A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0. This issue affects the function torch.cuda.memory.caching_allocator_delete of the file c10/cuda/CUDACachingAllocator.cpp. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. • https://github.com/pytorch/pytorch/issues/149821 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2025-2784 – Libsoup: heap buffer over-read in `skip_insignificant_space` when sniffing content
https://notcve.org/view.php?id=CVE-2025-2784
03 Apr 2025 — A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_insight_whitespace() function. Libsoup clients may read one byte out-of-bounds in response to a crafted HTTP response by an HTTP server. • https://access.redhat.com/security/cve/CVE-2025-2784 • CWE-125: Out-of-bounds Read •