5.5

CVSS3.1

CVE-2025-68753 - ALSA: firewire-motu: add bounds check in put_user loop for DSP events

In the Linux kernel, the following vulnerability has been resolved: ALSA: firewire-motu: add bounds check in put_user loop for DSP events In the DSP event handling code, a put_user() loop copies event data. When the user buffer size is not aligned to 4 bytes, it could overwrite beyond the buffer …

πŸ“… Published: Jan. 5, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-65328 -

Mega-Fence (webgate-lib.*) 25.1.914 and prior trusts the first value of the X-Forwarded-For (XFF) header as the client IP without validating a trusted proxy chain. An attacker can supply an arbitrary XFF value in a remote request to spoof the client IP, which is then propagated to security-relevant…

πŸ“… Published: Jan. 5, 2026, midnight πŸ”„ Last Modified: Jan. 30, 2026, 1:35 a.m.

7.5

CVSS3.1

CVE-2025-43706 -

An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2400, 1580, 9110, W920, W930, Modem 5123, and Modem 5400. Incorrect handling of RRC packets leads to a Denial of Service.

πŸ“… Published: Jan. 5, 2026, midnight πŸ”„ Last Modified: Jan. 9, 2026, 2:14 p.m.

9.1

CVSS3.1

CVE-2025-27807 -

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 9110, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. The lack of a length check leads to out-of-bounds writes via malformed NAS pack…

πŸ“… Published: Jan. 5, 2026, midnight πŸ”„ Last Modified: Jan. 9, 2026, 2:14 p.m.

7.8

CVSS3.1

CVE-2025-57836 -

An issue was discovered in Samsung Magician 6.3.0 through 8.3.2 on Windows. The installer creates a temporary folder with weak permissions during installation, allowing a non-admin user to perform DLL hijacking and escalate privileges.

πŸ“… Published: Jan. 5, 2026, midnight πŸ”„ Last Modified: Jan. 30, 2026, 1:26 a.m.

7.5

CVSS3.1

CVE-2025-67419 -

A Denial of Service (DoS) vulnerability in evershop 2.1.0 and prior allows unauthenticated attackers to exhaust the application server's resources via the "GET /images" API. The application fails to limit the height of the use-element shadow tree or the dimensions of pattern tiles during the proces…

πŸ“… Published: Jan. 5, 2026, midnight πŸ”„ Last Modified: Jan. 12, 2026, 6:12 p.m.

0.0

CVE-2025-68755 - staging: most: remove broken i2c driver

In the Linux kernel, the following vulnerability has been resolved: staging: most: remove broken i2c driver The MOST I2C driver has been completely broken for five years without anyone noticing so remove the driver from staging. Specifically, commit 723de0f9171e ("staging: most: remove device fr…

πŸ“… Published: Jan. 5, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2025-67315 -

DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

πŸ“… Published: Jan. 5, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 2:16 p.m.

5.1

CVSS3.1

CVE-2025-52515 -

An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500. A race condition in the issimian device driver results in an out-of-bounds access, leading to a denial of service.

πŸ“… Published: Jan. 5, 2026, midnight πŸ”„ Last Modified: Jan. 9, 2026, 1:31 p.m.

7.1

CVSS3.1

CVE-2025-52519 -

An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400, 1580, and 2500. Improper validation of user-space input in the issimian device driver leads to information disclosure and a denial of service.

πŸ“… Published: Jan. 5, 2026, midnight πŸ”„ Last Modified: Jan. 30, 2026, 1:29 a.m.
Total resulsts: 349182
Page 2296 of 34,919
Β« previous page Β» next page
Filters