6.1

CVSS3.1

CVE-2025-66470 - NiceGUI Stored/Reflected XSS in ui.interactive_image via unsanitized SVG content

NiceGUI is a Python-based UI framework. Versions 3.3.1 and below are subject to a XSS vulnerability through the ui.interactive_image component of NiceGUI. The component renders SVG content using Vue's v-html directive without any sanitization. This allows attackers to inject malicious HTML or JavaSโ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, 12:11 a.m. ๐Ÿ”„ Last Modified: Dec. 11, 2025, 6:49 p.m.

7.0

CVSS3.1

CVE-2025-40331 - sctp: Prevent TOCTOU out-of-bounds write

In the Linux kernel, the following vulnerability has been resolved: sctp: Prevent TOCTOU out-of-bounds write For the following path not holding the sock lock, sctp_diag_dump() -> sctp_for_each_endpoint() -> sctp_ep_dump() make sure not to exceed bounds in case the address list has grown betweโ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 9, 2025, 6:36 p.m.

5.5

CVSS3.1

CVE-2023-53852 - nvme-core: fix memory leak in dhchap_secret_store

In the Linux kernel, the following vulnerability has been resolved: nvme-core: fix memory leak in dhchap_secret_store Free dhchap_secret in nvme_ctrl_dhchap_secret_store() before we return fix following kmemleack:- unreferenced object 0xffff8886376ea800 (size 64): comm "check", pid 22048, jiffโ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 9, 2025, 6:37 p.m.

7.0

CVSS3.1

CVE-2023-53850 - iavf: use internal state to free traffic IRQs

In the Linux kernel, the following vulnerability has been resolved: iavf: use internal state to free traffic IRQs If the system tries to close the netdev while iavf_reset_task() is running, __LINK_STATE_START will be cleared and netif_running() will return false in iavf_reinit_interrupt_scheme().โ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 9, 2025, 6:37 p.m.

7.0

CVSS3.1

CVE-2023-53848 - md/raid5-cache: fix a deadlock in r5l_exit_log()

In the Linux kernel, the following vulnerability has been resolved: md/raid5-cache: fix a deadlock in r5l_exit_log() Commit b13015af94cf ("md/raid5-cache: Clear conf->log after finishing work") introduce a new problem: // caller hold reconfig_mutex r5l_exit_log flush_work(&log->disable_writebacโ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 9, 2025, 6:37 p.m.

5.5

CVSS3.1

CVE-2023-53838 - f2fs: synchronize atomic write aborts

In the Linux kernel, the following vulnerability has been resolved: f2fs: synchronize atomic write aborts To fix a race condition between atomic write aborts, I use the inode lock and make COW inode to be re-usable thoroughout the whole atomic file inode lifetime.

๐Ÿ“… Published: Dec. 9, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 9, 2025, 6:37 p.m.

5.5

CVSS3.1

CVE-2023-53826 - ubi: Fix UAF wear-leveling entry in eraseblk_count_seq_show()

In the Linux kernel, the following vulnerability has been resolved: ubi: Fix UAF wear-leveling entry in eraseblk_count_seq_show() Wear-leveling entry could be freed in error path, which may be accessed again in eraseblk_count_seq_show(), for example: __erase_worker eraseblk_count_โ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 9, 2025, 6:37 p.m.

7.0

CVSS3.1

CVE-2023-53832 - md/raid10: fix null-ptr-deref in raid10_sync_request

In the Linux kernel, the following vulnerability has been resolved: md/raid10: fix null-ptr-deref in raid10_sync_request init_resync() inits mempool and sets conf->have_replacemnt at the beginning of sync, close_sync() frees the mempool when sync is completed. After [1] recovery might be skippedโ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 9, 2025, 6:37 p.m.

7.0

CVSS3.1

CVE-2023-53828 - Bluetooth: hci_sync: Avoid use-after-free in dbg for hci_add_adv_monitor()

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: Avoid use-after-free in dbg for hci_add_adv_monitor() KSAN reports use-after-free in hci_add_adv_monitor(). While adding an adv monitor, hci_add_adv_monitor() calls -> msft_add_monitor_pattern() callโ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 9, 2025, 6:37 p.m.

7.0

CVSS3.1

CVE-2023-53806 - drm/amd/display: populate subvp cmd info only for the top pipe

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: populate subvp cmd info only for the top pipe [Why] System restart observed while changing the display resolution to 8k with extended mode. Sytem restart was caused by a page fault. [How] When the driver populatโ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 20, 2025, 8:51 a.m.
Total resulsts: 343968
Page 2229 of 34,397
ยซ previous page ยป next page
Filters