6.1

CVSS3.1

CVE-2025-56313 -

A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the /publix/run endpoint of JATOS 3.7.1 through 3.9.6 (inclusive). This allows remote attackers to execute arbitrary JavaScript in a user's web browser by including a malicious payload in the "code" URL parameter. When an authen…

πŸ“… Published: Oct. 30, 2025, midnight πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

7.5

CVSS3.1

CVE-2025-61498 -

A buffer overflow in the UPnP service of Tenda AC8 Hardware v03.03.10.01 allows attackers to cause a Denial of Service (DoS) via supplying a crafted packet.

πŸ“… Published: Oct. 30, 2025, midnight πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

5.5

CVSS3.1

CVE-2025-40087 - NFSD: Define a proc_layoutcommit for the FlexFiles layout type

In the Linux kernel, the following vulnerability has been resolved: NFSD: Define a proc_layoutcommit for the FlexFiles layout type Avoid a crash if a pNFS client should happen to send a LAYOUTCOMMIT operation on a FlexFiles layout.

πŸ“… Published: Oct. 30, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:03 p.m.

5.5

CVSS3.1

CVE-2025-40099 - cifs: parse_dfs_referrals: prevent oob on malformed input

In the Linux kernel, the following vulnerability has been resolved: cifs: parse_dfs_referrals: prevent oob on malformed input Malicious SMB server can send invalid reply to FSCTL_DFS_GET_REFERRALS - reply smaller than sizeof(struct get_dfs_referral_rsp) - reply with number of referrals smaller t…

πŸ“… Published: Oct. 30, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:03 p.m.

5.5

CVSS3.1

CVE-2025-40088 - hfsplus: fix slab-out-of-bounds read in hfsplus_strcasecmp()

In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix slab-out-of-bounds read in hfsplus_strcasecmp() The hfsplus_strcasecmp() logic can trigger the issue: [ 117.317703][ T9855] ================================================================== [ 117.318353][ T9855] …

πŸ“… Published: Oct. 30, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:03 p.m.

5.5

CVSS3.1

CVE-2025-40086 - drm/xe: Don't allow evicting of BOs in same VM in array of VM binds

In the Linux kernel, the following vulnerability has been resolved: drm/xe: Don't allow evicting of BOs in same VM in array of VM binds An array of VM binds can potentially evict other buffer objects (BOs) within the same VM under certain conditions, which may lead to NULL pointer dereferences la…

πŸ“… Published: Oct. 30, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:03 p.m.

5.5

CVSS3.1

CVE-2025-40100 - btrfs: do not assert we found block group item when creating free space tree

In the Linux kernel, the following vulnerability has been resolved: btrfs: do not assert we found block group item when creating free space tree Currently, when building a free space tree at populate_free_space_tree(), if we are not using the block group tree feature, we always expect to find blo…

πŸ“… Published: Oct. 30, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:03 p.m.

5.5

CVSS3.1

CVE-2025-40105 - vfs: Don't leak disconnected dentries on umount

In the Linux kernel, the following vulnerability has been resolved: vfs: Don't leak disconnected dentries on umount When user calls open_by_handle_at() on some inode that is not cached, we will create disconnected dentry for it. If such dentry is a directory, exportfs_decode_fh_raw() will then tr…

πŸ“… Published: Oct. 30, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:03 p.m.

5.5

CVSS3.1

CVE-2025-40090 - ksmbd: fix recursive locking in RPC handle list access

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix recursive locking in RPC handle list access Since commit 305853cce3794 ("ksmbd: Fix race condition in RPC handle list access"), ksmbd_session_rpc_method() attempts to lock sess->rpc_lock. This causes hung connections …

πŸ“… Published: Oct. 30, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:03 p.m.

5.5

CVSS3.1

CVE-2025-40089 - cxl/features: Add check for no entries in cxl_feature_info

In the Linux kernel, the following vulnerability has been resolved: cxl/features: Add check for no entries in cxl_feature_info cxl EDAC calls cxl_feature_info() to get the feature information and if the hardware has no Features support, cxlfs may be passed in as NULL. [ 51.957498] BUG: kernel …

πŸ“… Published: Oct. 30, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:03 p.m.
Total resulsts: 317582
Page 132 of 31,759
Β« previous page Β» next page
Filters