CVE detail
CVE-2025-13601
A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping), the calculation of the length of the escaped string could overflow, leading to a potential write off the end of the newly allocated string.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 18.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 1
- within the 30d window
- Peak daily
- 1
- highest bucket
Evidence
Source links by recency
34 source links · newest first
- Siemens SINEC OSCISA Alerts
Metrics CVSS Version Base Score Base Severity Vector String 3.1 5.5 MEDIUM CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVE-2025-40214 In the Linux kernel, the following vulnerability has been resolved: af_unix: Initialise scc_index in unix_add_edge(). Quang Le reported that the AF_UNIX GC could garbage-collect a receive queue of an alive in-flight soc
governmentwww.cisa.govJul 7, 2026, 12:00 PM - https://cert-portal.siemens.com/productcert/html/ssa-253495.htmlcert-portal.siemens.com
No excerpt available.
Vendor Advisorycert-portal.siemens.comNov 26, 2025, 3:15 PM - https://gitlab.gnome.org/GNOME/glib/-/merge_requests/4914gitlab.gnome.org
No excerpt available.
Exploitgitlab.gnome.orgNov 26, 2025, 3:15 PM - https://gitlab.gnome.org/GNOME/glib/-/issues/3827gitlab.gnome.org
No excerpt available.
Exploitgitlab.gnome.orgNov 26, 2025, 3:15 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2416741bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comNov 26, 2025, 3:15 PM - https://access.redhat.com/security/cve/CVE-2025-13601access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comNov 26, 2025, 3:15 PM - https://access.redhat.com/errata/RHSA-2026:7461access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comNov 26, 2025, 3:15 PM - https://access.redhat.com/errata/RHSA-2026:4419access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comNov 26, 2025, 3:15 PM - https://access.redhat.com/errata/RHSA-2026:3415access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comNov 26, 2025, 3:15 PM - https://access.redhat.com/errata/RHSA-2026:2974access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comNov 26, 2025, 3:15 PM - https://access.redhat.com/errata/RHSA-2026:2671access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comNov 26, 2025, 3:15 PM - https://access.redhat.com/errata/RHSA-2026:2659access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comNov 26, 2025, 3:15 PM - https://access.redhat.com/errata/RHSA-2026:2633access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comNov 26, 2025, 3:15 PM - https://access.redhat.com/errata/RHSA-2026:2563access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comNov 26, 2025, 3:15 PM - https://access.redhat.com/errata/RHSA-2026:2485access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comNov 26, 2025, 3:15 PM - https://access.redhat.com/errata/RHSA-2026:2072access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comNov 26, 2025, 3:15 PM - https://access.redhat.com/errata/RHSA-2026:2064access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comNov 26, 2025, 3:15 PM - https://access.redhat.com/errata/RHSA-2026:18705access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comNov 26, 2025, 3:15 PM - https://access.redhat.com/errata/RHSA-2026:18344access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comNov 26, 2025, 3:15 PM - https://access.redhat.com/errata/RHSA-2026:1736access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comNov 26, 2025, 3:15 PM - https://access.redhat.com/errata/RHSA-2026:1652access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comNov 26, 2025, 3:15 PM - https://access.redhat.com/errata/RHSA-2026:1627access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comNov 26, 2025, 3:15 PM - https://access.redhat.com/errata/RHSA-2026:1626access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comNov 26, 2025, 3:15 PM - https://access.redhat.com/errata/RHSA-2026:1625access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comNov 26, 2025, 3:15 PM - https://access.redhat.com/errata/RHSA-2026:1624access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comNov 26, 2025, 3:15 PM - https://access.redhat.com/errata/RHSA-2026:1608access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comNov 26, 2025, 3:15 PM - https://access.redhat.com/errata/RHSA-2026:1465access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comNov 26, 2025, 3:15 PM - https://access.redhat.com/errata/RHSA-2026:1327access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comNov 26, 2025, 3:15 PM - https://access.redhat.com/errata/RHSA-2026:1326access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comNov 26, 2025, 3:15 PM - https://access.redhat.com/errata/RHSA-2026:1324access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comNov 26, 2025, 3:15 PM - https://access.redhat.com/errata/RHSA-2026:1323access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comNov 26, 2025, 3:15 PM - https://access.redhat.com/errata/RHSA-2026:0991access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comNov 26, 2025, 3:15 PM - https://access.redhat.com/errata/RHSA-2026:0975access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comNov 26, 2025, 3:15 PM - https://access.redhat.com/errata/RHSA-2026:0936access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comNov 26, 2025, 3:15 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2025-3155CVSS 7.4 · High
A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents,…
- CVE-2025-2784CVSS 7.0 · High
A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_insight_whitespace() function. Libsoup clients may read one by…
- CVE-2023-3758CVSS 7.1 · High
A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denyi…
- CVE-2023-5633CVSS 7.8 · High
The reference count changes made as part of the CVE-2023-33951 and CVE-2023-33952 fixes exposed a use-after-free flaw in the way memory objects were handled when they were being u…
- CVE-2024-1488CVSS 8.0 · High
A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process…
- CVE-2024-0193CVSS 7.8 · High
A use-after-free flaw was found in the netfilter subsystem of the Linux kernel. If the catchall element is garbage-collected when the pipapo set is removed, the element can be dea…