5.5

CVSS3.1

CVE-2025-40049 - Squashfs: fix uninit-value in squashfs_get_parent

In the Linux kernel, the following vulnerability has been resolved: Squashfs: fix uninit-value in squashfs_get_parent Syzkaller reports a "KMSAN: uninit-value in squashfs_get_parent" bug. This is caused by open_by_handle_at() being called with a file handle containing an invalid parent inode num…

πŸ“… Published: Oct. 28, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:05 p.m.

9.1

CVSS3.1

CVE-2025-61235 -

An issue was discovered in Dataphone A920 v2025.07.161103. A custom packet based on public documentation can be crafted, where some fields can contain arbitrary or trivial data. Normally, such data should cause the device to reject the packet. However, due to a lack of validation, the device accept…

πŸ“… Published: Oct. 28, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:05 p.m.

7.5

CVSS3.1

CVE-2025-61103 - frr: NULL pointer dereference in show_vty_ext_link_lan_adj_sid() in ospf_ext.c

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_lan_adj_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.

πŸ“… Published: Oct. 28, 2025, midnight πŸ”„ Last Modified: Oct. 31, 2025, 6:55 p.m.

7.5

CVSS3.1

CVE-2025-60800 -

Incorrect access control in the /jshERP-boot/user/info interface of jshERP up to commit 90c411a allows attackers to access sensitive information via a crafted GET request.

πŸ“… Published: Oct. 28, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:05 p.m.

5.5

CVSS3.1

CVE-2025-61155 -

Hotta Studio GameDriverX64.sys 7.23.4.7, a signed kernel-mode anti-cheat driver, allows local attackers to cause a denial of service by crashing arbitrary processes via sending crafted IOCTL requests.

πŸ“… Published: Oct. 28, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:05 p.m.

7.5

CVSS3.1

CVE-2025-61107 - frr: NULL pointer dereference in show_vty_ext_pref_pref_sid() in ospf_ext.c

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted LSA Update packet.

πŸ“… Published: Oct. 28, 2025, midnight πŸ”„ Last Modified: Oct. 31, 2025, 6:46 p.m.

9.1

CVSS3.1

CVE-2025-61043 -

An out-of-bounds read vulnerability has been discovered in Monkey's Audio 11.31, specifically in the CAPECharacterHelper::GetUTF16FromUTF8 function. The issue arises from improper handling of the length of the input UTF-8 string, causing the function to read past the memory boundary. This vulnerabi…

πŸ“… Published: Oct. 28, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:05 p.m.

9.1

CVSS3.1

CVE-2025-61128 -

Stack-based buffer overflow vulnerability in WAVLINK QUANTUM D3G/WL-WN530HG3 firmware M30HG3_V240730, and possibly other wavlink models allows attackers to execute arbitrary code via crafted referrer value POST to login.cgi.

πŸ“… Published: Oct. 28, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:05 p.m.

7.5

CVSS3.1

CVE-2025-60349 -

An issue was discovered in Prevx v3.0.5.220 allowing attackers to cause a denial of service via sending IOCTL code 0x22E044 to the pxscan.sys driver. Any processes listed under registry key HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\pxscan\Files will be terminated.

πŸ“… Published: Oct. 28, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:05 p.m.

7.0

CVSS3.1

CVE-2025-40075 - tcp_metrics: use dst_dev_net_rcu()

In the Linux kernel, the following vulnerability has been resolved: tcp_metrics: use dst_dev_net_rcu() Replace three dst_dev() with a lockdep enabled helper.

πŸ“… Published: Oct. 28, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:05 p.m.
Total resulsts: 317018
Page 105 of 31,702
Β« previous page Β» next page
Filters