7.0

CVSS3.1

CVE-2025-37833 - net/niu: Niu requires MSIX ENTRY_DATA fields touch before entry reads

In the Linux kernel, the following vulnerability has been resolved: net/niu: Niu requires MSIX ENTRY_DATA fields touch before entry reads Fix niu_try_msix() to not cause a fatal trap on sparc systems. Set PCI_DEV_FLAGS_MSIX_TOUCH_ENTRY_DATA_FIRST on the struct pci_dev to work around a bug in the…

📅 Published: May 8, 2025, midnight 🔄 Last Modified: May 8, 2025, 2:39 p.m.

7.0

CVSS3.1

CVE-2025-37831 - cpufreq: apple-soc: Fix null-ptr-deref in apple_soc_cpufreq_get_rate()

In the Linux kernel, the following vulnerability has been resolved: cpufreq: apple-soc: Fix null-ptr-deref in apple_soc_cpufreq_get_rate() cpufreq_cpu_get_raw() can return NULL when the target CPU is not present in the policy->cpus mask. apple_soc_cpufreq_get_rate() does not check for this case, …

📅 Published: May 8, 2025, midnight 🔄 Last Modified: May 8, 2025, 2:39 p.m.

5.5

CVSS3.1

CVE-2025-37827 - btrfs: zoned: return EIO on RAID1 block group write pointer mismatch

In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: return EIO on RAID1 block group write pointer mismatch There was a bug report about a NULL pointer dereference in __btrfs_add_free_space_zoned() that ultimately happens because a conversion from the default metadata…

📅 Published: May 8, 2025, midnight 🔄 Last Modified: May 8, 2025, 2:39 p.m.

5.5

CVSS3.1

CVE-2025-37824 - tipc: fix NULL pointer dereference in tipc_mon_reinit_self()

In the Linux kernel, the following vulnerability has been resolved: tipc: fix NULL pointer dereference in tipc_mon_reinit_self() syzbot reported: tipc: Node number set to 1055423674 Oops: general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] SMP KASAN NOPTI K…

📅 Published: May 8, 2025, midnight 🔄 Last Modified: May 8, 2025, 2:39 p.m.

7.0

CVSS3.1

CVE-2025-37814 - tty: Require CAP_SYS_ADMIN for all usages of TIOCL_SELMOUSEREPORT

In the Linux kernel, the following vulnerability has been resolved: tty: Require CAP_SYS_ADMIN for all usages of TIOCL_SELMOUSEREPORT This requirement was overeagerly loosened in commit 2f83e38a095f ("tty: Permit some TIOCL_SETSEL modes without CAP_SYS_ADMIN"), but as it turns out, (1) the log…

📅 Published: May 8, 2025, midnight 🔄 Last Modified: May 8, 2025, 2:39 p.m.

5.5

CVSS3.1

CVE-2025-37806 - fs/ntfs3: Keep write operations atomic

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Keep write operations atomic syzbot reported a NULL pointer dereference in __generic_file_write_iter. [1] Before the write operation is completed, the user executes ioctl[2] to clear the compress flag of the file, whic…

📅 Published: May 8, 2025, midnight 🔄 Last Modified: May 8, 2025, 2:39 p.m.

2

CVSS4.0

CVE-2024-55651 - i-Educar Stored Cross-Site Scripting vulnerability

i-Educar is free, fully online school management software. Version 2.9 of the application fails to properly validate and sanitize user supplied input, leading to a stored cross-site scripting vulnerability that resides within the user type (Tipo de Usuário) input field. Through this attacker vector…

📅 Published: May 7, 2025, 11:49 p.m. 🔄 Last Modified: May 8, 2025, 2:39 p.m.

7.5

CVSS3.1

CVE-2025-46727 - Unbounded-Parameter DoS in Rack::QueryParser

Rack is a modular Ruby web server interface. Prior to versions 2.2.14, 3.0.16, and 3.1.14, `Rack::QueryParser` parses query strings and `application/x-www-form-urlencoded` bodies into Ruby data structures without imposing any limit on the number of parameters, allowing attackers to send requests wi…

📅 Published: May 7, 2025, 11:07 p.m. 🔄 Last Modified: May 8, 2025, 2:39 p.m.

4.2

CVSS3.1

CVE-2025-32441 - Rack session gets restored after deletion

Rack is a modular Ruby web server interface. Prior to version 2.2.14, when using the `Rack::Session::Pool` middleware, simultaneous rack requests can restore a deleted rack session, which allows the unauthenticated user to occupy that session. Rack session middleware prepares the session at the beg…

📅 Published: May 7, 2025, 11:01 p.m. 🔄 Last Modified: May 8, 2025, 2:39 p.m.

6.5

CVSS3.1

CVE-2025-0936 - On affected platforms running Arista EOS with a gNMI transport enabled, running the gNOI File Trans…

On affected platforms running Arista EOS with a gNMI transport enabled, running the gNOI File TransferToRemote RPC with credentials for a remote server may cause these remote-server credentials to be logged or accounted on the local EOS device or possibly on other remote accounting servers (i.e. TA…

📅 Published: May 7, 2025, 10:52 p.m. 🔄 Last Modified: May 8, 2025, 2:39 p.m.
Total resulsts: 293358
Page 26 of 29,336
« previous page » next page
Filters