3.3

CVSS3.1

CVE-2025-60912 -

phpIPAM v1.7.3 contains a Cross-Site Request Forgery (CSRF) vulnerability in the database export functionality. The generate-mysql.php function, located in the /app/admin/import-export/ endpoint, allows remote attackers to trigger large database dump downloads via crafted HTTP GET requests if an adโ€ฆ

๐Ÿ“… Published: Dec. 8, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 10, 2025, 5:36 p.m.

7.0

CVSS3.1

CVE-2025-40326 - NFSD: Define actions for the new time_deleg FATTR4 attributes

In the Linux kernel, the following vulnerability has been resolved: NFSD: Define actions for the new time_deleg FATTR4 attributes NFSv4 clients won't send legitimate GETATTR requests for these new attributes because they are intended to be used only with CB_GETATTR and SETATTR. But NFSD has to doโ€ฆ

๐Ÿ“… Published: Dec. 8, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 8, 2025, 6:26 p.m.

7.0

CVSS3.1

CVE-2025-40302 - media: videobuf2: forbid remove_bufs when legacy fileio is active

In the Linux kernel, the following vulnerability has been resolved: media: videobuf2: forbid remove_bufs when legacy fileio is active vb2_ioctl_remove_bufs() call manipulates queue internal buffer list, potentially overwriting some pointers used by the legacy fileio access mode. Forbid that ioctlโ€ฆ

๐Ÿ“… Published: Dec. 8, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 8, 2025, 6:26 p.m.

5.5

CVSS3.1

CVE-2025-40298 - gve: Implement settime64 with -EOPNOTSUPP

In the Linux kernel, the following vulnerability has been resolved: gve: Implement settime64 with -EOPNOTSUPP ptp_clock_settime() assumes every ptp_clock has implemented settime64(). Stub it with -EOPNOTSUPP to prevent a NULL dereference.

๐Ÿ“… Published: Dec. 8, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 8, 2025, 6:26 p.m.

7.0

CVSS3.1

CVE-2025-40297 - net: bridge: fix use-after-free due to MST port state bypass

In the Linux kernel, the following vulnerability has been resolved: net: bridge: fix use-after-free due to MST port state bypass syzbot reported[1] a use-after-free when deleting an expired fdb. It is due to a race condition between learning still happening and a port being deleted, after all itsโ€ฆ

๐Ÿ“… Published: Dec. 8, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 8, 2025, 6:26 p.m.

9.1

CVSS3.1

CVE-2025-65548 -

NUT-14 allows cashu tokens to be created with a preimage hash. However, nutshell (cashubtc/nuts) before 0.18.0 do not validate the size of preimage when the token is spent. The preimage is stored by the mint and attacker can exploit this vulnerability to fill the mint's db nd disk with arbitrary daโ€ฆ

๐Ÿ“… Published: Dec. 8, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 15, 2025, 3:56 p.m.

5.5

CVSS3.1

CVE-2023-53769 - virt/coco/sev-guest: Double-buffer messages

In the Linux kernel, the following vulnerability has been resolved: virt/coco/sev-guest: Double-buffer messages The encryption algorithms read and write directly to shared unencrypted memory, which may leak information as well as permit the host to tamper with the message integrity. Instead, copyโ€ฆ

๐Ÿ“… Published: Dec. 8, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 8, 2025, 6:26 p.m.

5.5

CVSS3.1

CVE-2023-53768 - regmap-irq: Fix out-of-bounds access when allocating config buffers

In the Linux kernel, the following vulnerability has been resolved: regmap-irq: Fix out-of-bounds access when allocating config buffers When allocating the 2D array for handling IRQ type registers in regmap_add_irq_chip_fwnode(), the intent is to allocate a matrix with num_config_bases rows and nโ€ฆ

๐Ÿ“… Published: Dec. 8, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 8, 2025, 6:26 p.m.

7.0

CVSS3.1

CVE-2023-53764 - wifi: ath12k: Handle lock during peer_id find

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Handle lock during peer_id find ath12k_peer_find_by_id() requires that the caller hold the ab->base_lock. Currently the WBM error path does not hold the lock and calling that function, leads to the following lockdepโ€ฆ

๐Ÿ“… Published: Dec. 8, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 20, 2025, 8:51 a.m.

7.0

CVSS3.1

CVE-2023-53759 - HID: hidraw: fix data race on device refcount

In the Linux kernel, the following vulnerability has been resolved: HID: hidraw: fix data race on device refcount The hidraw_open() function increments the hidraw device reference counter. The counter has no dedicated synchronization mechanism, resulting in a potential data race when concurrentlyโ€ฆ

๐Ÿ“… Published: Dec. 8, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 8, 2025, 6:26 p.m.
Total resulsts: 343825
Page 2254 of 34,383
ยซ previous page ยป next page
Filters