5.5

CVSS3.1

CVE-2025-40065 - RISC-V: KVM: Write hgatp register with valid mode bits

In the Linux kernel, the following vulnerability has been resolved: RISC-V: KVM: Write hgatp register with valid mode bits According to the RISC-V Privileged Architecture Spec, when MODE=Bare is selected,software must write zero to the remaining fields of hgatp. We have detected the valid mode s…

πŸ“… Published: Oct. 28, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:05 p.m.

7.5

CVSS3.1

CVE-2025-54604 -

Bitcoin Core through 29.0 allows Uncontrolled Resource Consumption (issue 1 of 2).

πŸ“… Published: Oct. 28, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:05 p.m.

5.5

CVSS3.1

CVE-2025-40062 - crypto: hisilicon/qm - set NULL to qm->debug.qm_diff_regs

In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/qm - set NULL to qm->debug.qm_diff_regs When the initialization of qm->debug.acc_diff_reg fails, the probe process does not exit. However, after qm->debug.qm_diff_regs is freed, it is not set to NULL. This can l…

πŸ“… Published: Oct. 28, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:05 p.m.

5.5

CVSS3.1

CVE-2025-40049 - Squashfs: fix uninit-value in squashfs_get_parent

In the Linux kernel, the following vulnerability has been resolved: Squashfs: fix uninit-value in squashfs_get_parent Syzkaller reports a "KMSAN: uninit-value in squashfs_get_parent" bug. This is caused by open_by_handle_at() being called with a file handle containing an invalid parent inode num…

πŸ“… Published: Oct. 28, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:05 p.m.

9.1

CVSS3.1

CVE-2025-61235 -

An issue was discovered in Dataphone A920 v2025.07.161103. A custom packet based on public documentation can be crafted, where some fields can contain arbitrary or trivial data. Normally, such data should cause the device to reject the packet. However, due to a lack of validation, the device accept…

πŸ“… Published: Oct. 28, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:05 p.m.

7.5

CVSS3.1

CVE-2025-61103 - frr: NULL pointer dereference in show_vty_ext_link_lan_adj_sid() in ospf_ext.c

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_lan_adj_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.

πŸ“… Published: Oct. 28, 2025, midnight πŸ”„ Last Modified: Oct. 31, 2025, 6:55 p.m.

7.5

CVSS3.1

CVE-2025-60800 -

Incorrect access control in the /jshERP-boot/user/info interface of jshERP up to commit 90c411a allows attackers to access sensitive information via a crafted GET request.

πŸ“… Published: Oct. 28, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:05 p.m.

5.5

CVSS3.1

CVE-2025-61155 -

Hotta Studio GameDriverX64.sys 7.23.4.7, a signed kernel-mode anti-cheat driver, allows local attackers to cause a denial of service by crashing arbitrary processes via sending crafted IOCTL requests.

πŸ“… Published: Oct. 28, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:05 p.m.

7.5

CVSS3.1

CVE-2025-61107 - frr: NULL pointer dereference in show_vty_ext_pref_pref_sid() in ospf_ext.c

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted LSA Update packet.

πŸ“… Published: Oct. 28, 2025, midnight πŸ”„ Last Modified: Oct. 31, 2025, 6:46 p.m.

9.1

CVSS3.1

CVE-2025-61043 -

An out-of-bounds read vulnerability has been discovered in Monkey's Audio 11.31, specifically in the CAPECharacterHelper::GetUTF16FromUTF8 function. The issue arises from improper handling of the length of the input UTF-8 string, causing the function to read past the memory boundary. This vulnerabi…

πŸ“… Published: Oct. 28, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:05 p.m.
Total resulsts: 317011
Page 104 of 31,702
Β« previous page Β» next page
Filters