NVD disclosure day

Published threat advisories for June 3, 2025

CVE advisoryCRITICAL

CVE-2025-44148

MailEnable failure.aspx Cross Site Scripting Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical cross-site scripting vulnerability in MailEnable could permit remote code execution by an attacker. This affects the failure.aspx component, and if reachable, could compromise system integrity. Understanding if MailEnable is used is crucial to assess potential risk.

CVE advisoryCRITICAL

CVE-2025-4517

Tarfile Module Arbitrary Filesystem Write via Extraction Filter Bypass

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Python `tarfile` module allows arbitrary filesystem writes outside the extraction directory when processing untrusted archives with specific filter settings. This could enable attackers to overwrite or place files anywhere on the system. This issue is relevant if your environment uses the `tarfil

CVE advisoryKnown Exploit

CVE-2025-21479

Qualcomm Chipsets Vulnerable to Memory Corruption via Unauthorized Command Execution.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A memory corruption vulnerability in Qualcomm chipsets could allow unauthorized command execution in the GPU micronode. This impacts organizations using affected devices and presents a risk of data compromise and system disruption. Applying vendor-provided mitigations is recommended.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2025-27038

Qualcomm Chipsets Vulnerability Allows Data Corruption.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A memory corruption vulnerability impacts Qualcomm chipsets when rendering graphics in Chrome. This could lead to data corruption, affecting system integrity and posing a business risk to organizations utilizing affected hardware. Mitigation guidance is available from Qualcomm.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2025-21480

Qualcomm Chipsets Memory Corruption Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The vulnerability affects Qualcomm chipsets, allowing for memory corruption through unauthorized command execution. This poses a risk of compromised confidentiality, integrity, and availability of data and systems. The vulnerability has been added to the CISA Known Exploited Vulnerabilities catalog.

• CISA KEV