7.8

CVSS3.1

CVE-2025-39888 - fuse: Block access to folio overlimit

In the Linux kernel, the following vulnerability has been resolved: fuse: Block access to folio overlimit syz reported a slab-out-of-bounds Write in fuse_dev_do_write. When the number of bytes to be retrieved is truncated to the upper limit by fc->max_pages and there is an offset, the oob is tri…

πŸ“… Published: Sept. 23, 2025, midnight πŸ”„ Last Modified: Jan. 14, 2026, 8:16 p.m.

7.5

CVSS3.1

CVE-2025-57638 -

Buffer overflow vulnerability in Tenda AC9 1.0 via the user supplied sys.vendor configuration value.

πŸ“… Published: Sept. 23, 2025, midnight πŸ”„ Last Modified: Sept. 25, 2025, 4:09 p.m.

6.5

CVSS3.1

CVE-2025-57636 -

OS Command injection vulnerability in D-Link C1 2020-02-21. The sub_47F028 function in jhttpd contains a command injection vulnerability via the HTTP parameter "time".

πŸ“… Published: Sept. 23, 2025, midnight πŸ”„ Last Modified: Sept. 25, 2025, 4:07 p.m.

5.5

CVSS3.1

CVE-2025-39885 - ocfs2: fix recursive semaphore deadlock in fiemap call

In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix recursive semaphore deadlock in fiemap call syzbot detected a OCFS2 hang due to a recursive semaphore on a FS_IOC_FIEMAP of the extent list on a specially crafted mmap file. context_switch kernel/sched/core.c:5357 [in…

πŸ“… Published: Sept. 23, 2025, midnight πŸ”„ Last Modified: Jan. 16, 2026, 7:29 p.m.

7.8

CVSS3.1

CVE-2025-39868 - erofs: fix runtime warning on truncate_folio_batch_exceptionals()

In the Linux kernel, the following vulnerability has been resolved: erofs: fix runtime warning on truncate_folio_batch_exceptionals() Commit 0e2f80afcfa6("fs/dax: ensure all pages are idle prior to filesystem unmount") introduced the WARN_ON_ONCE to capture whether the filesystem has removed all …

πŸ“… Published: Sept. 23, 2025, midnight πŸ”„ Last Modified: Jan. 14, 2026, 8:16 p.m.

7.8

CVSS3.1

CVE-2025-39881 - kernfs: Fix UAF in polling when open file is released

In the Linux kernel, the following vulnerability has been resolved: kernfs: Fix UAF in polling when open file is released A use-after-free (UAF) vulnerability was identified in the PSI (Pressure Stall Information) monitoring mechanism: BUG: KASAN: slab-use-after-free in psi_trigger_poll+0x3c/0x1…

πŸ“… Published: Sept. 23, 2025, midnight πŸ”„ Last Modified: Jan. 16, 2026, 7:26 p.m.

5.5

CVSS3.1

CVE-2025-39874 - macsec: sync features on RTM_NEWLINK

In the Linux kernel, the following vulnerability has been resolved: macsec: sync features on RTM_NEWLINK Syzkaller managed to lock the lower device via ETHTOOL_SFEATURES: netdev_lock include/linux/netdevice.h:2761 [inline] netdev_lock_ops include/net/netdev_lock.h:42 [inline] netdev_sync_lowe…

πŸ“… Published: Sept. 23, 2025, midnight πŸ”„ Last Modified: Jan. 14, 2026, 8:16 p.m.

6.5

CVSS3.1

CVE-2025-57639 -

OS Command injection vulnerability in Tenda AC9 1.0 was discovered to contain a command injection vulnerability via the usb.samba.guest.user parameter in the formSetSambaConf function of the httpd file.

πŸ“… Published: Sept. 23, 2025, midnight πŸ”„ Last Modified: Sept. 25, 2025, 4:09 p.m.

7.5

CVSS3.1

CVE-2025-57637 -

Buffer overflow vulnerability in D-Link DI-7100G 2020-02-21 in the sub_451754 function of the jhttpd service in the viav4 parameter allowing attackers to cause a denial of service or execute arbitrary code.

πŸ“… Published: Sept. 23, 2025, midnight πŸ”„ Last Modified: Sept. 25, 2025, 4:09 p.m.

6.5

CVSS3.1

CVE-2025-56311 -

In Shenzhen C-Data Technology Co. FD602GW-DX-R410 (firmware v2.2.14), the web management interface contains an authenticated CSRF vulnerability on the reboot endpoint (/boaform/admin/formReboot). An attacker can craft a malicious webpage that, when visited by an authenticated administrator, causes …

πŸ“… Published: Sept. 23, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3714 of 34,919
Β« previous page Β» next page
Filters