DragonflyDB Dragonfly before 1.27.0 allows authenticated users to cause a denial of service (daemon crash) via a crafted Redis command. The validity of the scan cursor was not checked.
Publication date: Thu, 17 Apr 2025 00:00:00 +0000
Cyber News related to CVE-2025-26268
CVE-2025-26268 - DragonflyDB Dragonfly before 1.27.0 allows authenticated users to cause a denial of service (daemon crash) via a crafted Redis command. The validity of the scan cursor was not checked. ...
3 months ago Dragonfly
CVE-2025-8645 - Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication is not required to exploit this ...
3 days ago
CVE-2020-26268 - In affected versions of TensorFlow the tf.raw_ops.ImmutableConst operation returns a constant tensor created from a memory mapped file which is assumed immutable. However, if the type of the tensor is not an integral type, the operation crashes the ...
4 years ago
CVE-2022-26268 - Xiaohuanxiong v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /app/controller/Books.php. ...
3 years ago
CVE-2023-26268 - Design documents with matching document IDs, from databases on the same cluster, may share a mutable Javascript environment when using these design document functions: ...
2 years ago
CVE-2024-26268 - User enumeration vulnerability in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before update 27, 7.3 before update 8, 7.2 before fix pack 20, and older unsupported versions allows remote attackers to ...
1 year ago