2.9

CVSS3.1

CVE-2025-43718 - poppler: Poppler stack overflow

Poppler 24.06.1 through 25.x before 25.04.0 allows stack consumption and a SIGSEGV via deeply nested structures within the metadata (such as GTS_PDFEVersion) of a PDF document, e.g., a regular expression for a long pdfsubver string. This occurs in Dict::lookup, Catalog::getMetadata, and associated …

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2025-39924 - erofs: fix invalid algorithm for encoded extents

In the Linux kernel, the following vulnerability has been resolved: erofs: fix invalid algorithm for encoded extents The current algorithm sanity checks do not properly apply to new encoded extents. Unify the algorithm check with Z_EROFS_COMPRESSION(_RUNTIME)_MAX and ensure consistency with sbi-…

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: Jan. 14, 2026, 6:16 p.m.

5.5

CVSS3.1

CVE-2025-39902 - mm/slub: avoid accessing metadata when pointer is invalid in object_err()

In the Linux kernel, the following vulnerability has been resolved: mm/slub: avoid accessing metadata when pointer is invalid in object_err() object_err() reports details of an object for further debugging, such as the freelist pointer, redzone, etc. However, if the pointer is invalid, attempting…

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: Jan. 16, 2026, 7:30 p.m.

5.5

CVSS3.1

CVE-2025-39918 - wifi: mt76: fix linked list corruption

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: fix linked list corruption Never leave scheduled wcid entries on the temporary on-stack list

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: Jan. 14, 2026, 6:16 p.m.

5.5

CVSS3.1

CVE-2025-39894 - netfilter: br_netfilter: do not check confirmed bit in br_nf_local_in() after confirm

In the Linux kernel, the following vulnerability has been resolved: netfilter: br_netfilter: do not check confirmed bit in br_nf_local_in() after confirm When send a broadcast packet to a tap device, which was added to a bridge, br_nf_local_in() is called to confirm the conntrack. If another conn…

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: Jan. 16, 2026, 7:30 p.m.

8.8

CVSS3.1

CVE-2025-28357 -

A CRLF injection vulnerability in Neto CMS v6.313.0 through v6.314.0 allows attackers to execute arbitrary code via supplying a crafted HTTP request.

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.2

CVSS3.1

CVE-2025-52039 -

In Frappe ERPNext 15.57.5, the function get_material_requests_based_on_supplier() at erpnext/stock/doctype/material_request/material_request.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by injecting a SQL query into the txt parameter.

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: Oct. 3, 2025, 4:19 p.m.

5.5

CVSS3.1

CVE-2023-53531 - null_blk: fix poll request timeout handling

In the Linux kernel, the following vulnerability has been resolved: null_blk: fix poll request timeout handling When doing io_uring benchmark on /dev/nullb0, it's easy to crash the kernel if poll requests timeout triggered, as reported by David. [1] BUG: kernel NULL pointer dereference, address:…

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: Jan. 23, 2026, 8:41 p.m.

5.5

CVSS3.1

CVE-2023-53528 - RDMA/rxe: Fix unsafe drain work queue code

In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix unsafe drain work queue code If create_qp does not fully succeed it is possible for qp cleanup code to attempt to drain the send or recv work queues before the queues have been created causing a seg fault. This patc…

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: April 6, 2026, 1:24 p.m.

7.8

CVSS3.1

CVE-2023-53515 - virtio-mmio: don't break lifecycle of vm_dev

In the Linux kernel, the following vulnerability has been resolved: virtio-mmio: don't break lifecycle of vm_dev vm_dev has a separate lifecycle because it has a 'struct device' embedded. Thus, having a release callback for it is correct. Allocating the vm_dev struct with devres totally breaks t…

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: April 6, 2026, 1:04 p.m.
Total resulsts: 349182
Page 3610 of 34,919
Β« previous page Β» next page
Filters