CVE-2025-6490 - CERT CVE
ID CVE-2025-6490
Sažetak A vulnerability was found in sparklemotion nokogiri up to 1.18.7 and classified as problematic. This issue affects the function hashmap_set_with_hash of the file gumbo-parser/src/hashmap.c. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
Reference
CVSS
Base: 1.7
Impact: 2.9
Exploitability:3.1
Pristup
VektorSloženostAutentikacija
LOCAL LOW SINGLE
Impact
PovjerljivostCjelovitostDostupnost
NONE NONE PARTIAL
CVSS vektor AV:L/AC:L/Au:S/C:N/I:N/A:P
Zadnje važnije ažuriranje 23-06-2025 - 20:16
Objavljeno 22-06-2025 - 19:15