8.7

CVSS4.0

CVE-2023-7329 - Tinycontrol LAN Controller v3 (LK3) Remote DoS

Tinycontrol LAN Controller v3 (LK3) firmware versions up to 1.58a (hardware v3.8) contain a missing authentication vulnerability in the stm.cgi endpoint. A remote, unauthenticated attacker can send crafted requests to forcibly reboot the device or restore factory settings, leading to a denial of se…

πŸ“… Published: Nov. 12, 2025, 10:06 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 10:06 p.m.

8.6

CVSS4.0

CVE-2017-20211 - UCanCode E-XD++ Visualization Enterprise Suite Untrusted Pointer Dereference RCE

UCanCode E-XD++ Visualization Enterprise Suite contains an untrusted pointer dereference vulnerability via the TKDRAWCAD.TKDrawCADCtrl.1 ActiveX control. This is because it exposes a RotateShape method that dereferences a user-supplied pointer without sufficient validation. A crafted input may caus…

πŸ“… Published: Nov. 12, 2025, 10:05 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 10:05 p.m.

4

CVSS3.1

CVE-2025-64503 - [BIGSLEEP-434615384] cups-filters 1.x: out of bounds write in pdftoraster

cups-filters contains backends, filters, and other software required to get the cups printing service working on operating systems other than macos. In cups-filters prior to 1.28.18, by crafting a PDF file with a large `MediaBox` value, an attacker can cause CUPS-Filter 1.x’s `pdftoraster` tool to …

πŸ“… Published: Nov. 12, 2025, 10:04 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 10:05 p.m.

0.0

CVE-2025-40208 - media: iris: fix module removal if firmware download failed

In the Linux kernel, the following vulnerability has been resolved: media: iris: fix module removal if firmware download failed Fix remove if firmware failed to load: qcom-iris aa00000.video-codec: Direct firmware load for qcom/vpu/vpu33_p4.mbn failed with error -2 qcom-iris aa00000.video-codec: …

πŸ“… Published: Nov. 12, 2025, 9:56 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 9:56 p.m.

0.0

CVE-2025-40207 - media: v4l2-subdev: Fix alloc failure check in v4l2_subdev_call_state_try()

In the Linux kernel, the following vulnerability has been resolved: media: v4l2-subdev: Fix alloc failure check in v4l2_subdev_call_state_try() v4l2_subdev_call_state_try() macro allocates a subdev state with __v4l2_subdev_state_alloc(), but does not check the returned value. If __v4l2_subdev_sta…

πŸ“… Published: Nov. 12, 2025, 9:56 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 9:56 p.m.

0.0

CVE-2025-40206 - netfilter: nft_objref: validate objref and objrefmap expressions

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_objref: validate objref and objrefmap expressions Referencing a synproxy stateful object from OUTPUT hook causes kernel crash due to infinite recursive calls: BUG: TASK stack guard page was hit at 000000008bda5b8c…

πŸ“… Published: Nov. 12, 2025, 9:56 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 9:56 p.m.

0.0

CVE-2025-40205 - btrfs: avoid potential out-of-bounds in btrfs_encode_fh()

In the Linux kernel, the following vulnerability has been resolved: btrfs: avoid potential out-of-bounds in btrfs_encode_fh() The function btrfs_encode_fh() does not properly account for the three cases it handles. Before writing to the file handle (fh), the function only returns to the user BTR…

πŸ“… Published: Nov. 12, 2025, 9:56 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 9:56 p.m.

0.0

CVE-2025-40204 - sctp: Fix MAC comparison to be constant-time

In the Linux kernel, the following vulnerability has been resolved: sctp: Fix MAC comparison to be constant-time To prevent timing attacks, MACs need to be compared in constant time. Use the appropriate helper function for this.

πŸ“… Published: Nov. 12, 2025, 9:56 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 9:56 p.m.

0.0

CVE-2025-40203 - listmount: don't call path_put() under namespace semaphore

In the Linux kernel, the following vulnerability has been resolved: listmount: don't call path_put() under namespace semaphore Massage listmount() and make sure we don't call path_put() under the namespace semaphore. If we put the last reference we're fscked.

πŸ“… Published: Nov. 12, 2025, 9:56 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 9:56 p.m.

0.0

CVE-2025-40202 - ipmi: Rework user message limit handling

In the Linux kernel, the following vulnerability has been resolved: ipmi: Rework user message limit handling The limit on the number of user messages had a number of issues, improper counting in some cases and a use after free. Restructure how this is all done to handle more in the receive messa…

πŸ“… Published: Nov. 12, 2025, 9:56 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 9:56 p.m.
Total resulsts: 318415
Page 33 of 31,842
Β« previous page Β» next page
Filters