Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-11522 | VisiCut 2.1 allows stack consumption via an XML document with nested set elements, as demonstrated by a java.util.HashMap StackOverflowError when reference='../../../set/set[2]' is used, aka an "insecure deserialization" issue. |
Wed, 24 Sep 2025 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Visicut
Visicut visicut |
|
| CPEs | cpe:2.3:a:visicut:visicut:2.1:*:*:*:*:*:*:* | |
| Vendors & Products |
Visicut
Visicut visicut |
Thu, 17 Apr 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 17 Apr 2025 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-674 | |
| Metrics |
cvssV3_1
|
Thu, 17 Apr 2025 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | VisiCut 2.1 allows stack consumption via an XML document with nested set elements, as demonstrated by a java.util.HashMap StackOverflowError when reference='../../../set/set[2]' is used, aka an "insecure deserialization" issue. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-17T19:22:56.942Z
Reserved: 2025-04-17T00:00:00.000Z
Link: CVE-2025-43708
Updated: 2025-04-17T19:22:50.779Z
Status : Analyzed
Published: 2025-04-17T01:15:46.707
Modified: 2025-09-24T00:51:03.900
Link: CVE-2025-43708
No data.
OpenCVE Enrichment
No data.
EUVD