5.5

CVSS3.1

CVE-2025-40339 - drm/amdgpu: fix nullptr err of vm_handle_moved

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix nullptr err of vm_handle_moved If a amdgpu_bo_va is fpriv->prt_va, the bo of this one is always NULL. So, such kind of amdgpu_bo_va should be updated separately before amdgpu_vm_handle_moved.

๐Ÿ“… Published: Dec. 9, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-65882 -

An issue was discovered in openmptcprouter thru 0.64 in file common/package/utils/sys-upgrade-helper/src/tools/sysupgrade.c in function create_xor_ipad_opad allowing attackers to potentially write arbitrary files or execute arbitrary commands.

๐Ÿ“… Published: Dec. 9, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 2, 2026, 9:30 p.m.

5.5

CVSS3.1

CVE-2023-53805 - kernel: tty: n_gsm: fix UAF in gsm_cleanup_mux

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

๐Ÿ“… Published: Dec. 9, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 9, 2025, 4:17 p.m.

5.4

CVSS3.1

CVE-2025-65300 -

A stored Cross-Site Scripting (XSS) vulnerability exists in the Coohom SaaS Platform feVersion=1760060603897 (2025-10-28) in the Account Settings module, where unsanitized user input in Address fields (City, State, Country/Region) is rendered back to the page. Attackers can inject arbitrary JavaScrโ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 16, 2025, 7:57 p.m.

6.1

CVSS3.1

CVE-2025-65289 -

A stored Cross site scripting (XSS) vulnerability in the Mercury MR816v2 (081C3114 4.8.7 Build 110427 Rel 36550n) router allows a remote attacker on the LAN to inject JavaScript into the router's management UI by submitting a malicious hostname. The injected script is stored and later executed in tโ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 12, 2025, 2:31 p.m.

4.3

CVSS3.1

CVE-2025-63738 -

An issue was discovered in file index.php in Xinhu Rainrock RockOA 2.7.0 allowing attackers to gain sensitive information via phpinfo via the a parameter to the index.php.

๐Ÿ“… Published: Dec. 9, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 12, 2025, 12:29 p.m.

7.5

CVSS3.1

CVE-2025-61258 -

Outsystems Platform Server 11.18.1.37828 allows attackers to cause a denial of service via a crafted content-length value mismatching the body length. NOTE: the Supplier indicates that they are unable to reproduce this.

๐Ÿ“… Published: Dec. 9, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 24, 2025, 4:15 p.m.

7.0

CVSS3.1

CVE-2023-53820 - loop: loop_set_status_from_info() check before assignment

In the Linux kernel, the following vulnerability has been resolved: loop: loop_set_status_from_info() check before assignment In loop_set_status_from_info(), lo->lo_offset and lo->lo_sizelimit should be checked before reassignment, because if an overflow error occurs, the original correct value wโ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.0

CVSS3.1

CVE-2023-53816 - drm/amdkfd: fix potential kgd_mem UAFs

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: fix potential kgd_mem UAFs kgd_mem pointers returned by kfd_process_device_translate_handle are only guaranteed to be valid while p->mutex is held. As soon as the mutex is unlocked, another thread can free the BO.

๐Ÿ“… Published: Dec. 9, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.0

CVSS3.1

CVE-2023-53791 - md: fix warning for holder mismatch from export_rdev()

In the Linux kernel, the following vulnerability has been resolved: md: fix warning for holder mismatch from export_rdev() Commit a1d767191096 ("md: use mddev->external to select holder in export_rdev()") fix the problem that 'claim_rdev' is used for blkdev_get_by_dev() while 'rdev' is used for bโ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346515
Page 2492 of 34,652
ยซ previous page ยป next page
Filters