Security Vulnerabilities
- CVEs Published In December 2025
Memory Corruption when processing IOCTLs for JPEG data without verification.
Memory corruption while processing MFC channel configuration during music playback.
Memory corruption while copying packets received from unix clients.
Memory corruption while handling IOCTL calls to set mode.
Memory corruption while routing GPR packets between user and root when handling large data packet.
Information disclosure while processing system calls with invalid parameters.
Memory corruption during video playback when video session open fails with time out error.
Information disclosure while exposing internal TA-to-TA communication APIs to HLOS
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML style sanitizer.