7.1

CVSS3.1

CVE-2025-38679 - media: venus: Fix OOB read due to missing payload bound check

In the Linux kernel, the following vulnerability has been resolved: media: venus: Fix OOB read due to missing payload bound check Currently, The event_seq_changed() handler processes a variable number of properties sent by the firmware. The number of properties is indicated by the firmware and us…

πŸ“… Published: Sept. 4, 2025, midnight πŸ”„ Last Modified: Jan. 8, 2026, 10:30 p.m.

5.5

CVSS3.1

CVE-2025-38709 - loop: Avoid updating block size under exclusive owner

In the Linux kernel, the following vulnerability has been resolved: loop: Avoid updating block size under exclusive owner Syzbot came up with a reproducer where a loop device block size is changed underneath a mounted filesystem. This causes a mismatch between the block device block size and the …

πŸ“… Published: Sept. 4, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 3:31 p.m.

7.1

CVSS3.1

CVE-2025-38728 - smb3: fix for slab out of bounds on mount to ksmbd

In the Linux kernel, the following vulnerability has been resolved: smb3: fix for slab out of bounds on mount to ksmbd With KASAN enabled, it is possible to get a slab out of bounds during mount to ksmbd due to missing check in parse_server_interfaces() (see below): BUG: KASAN: slab-out-of-boun…

πŸ“… Published: Sept. 4, 2025, midnight πŸ”„ Last Modified: Jan. 8, 2026, 5:31 p.m.

5.5

CVSS3.1

CVE-2025-38696 - MIPS: Don't crash in stack_top() for tasks without ABI or vDSO

In the Linux kernel, the following vulnerability has been resolved: MIPS: Don't crash in stack_top() for tasks without ABI or vDSO Not all tasks have an ABI associated or vDSO mapped, for example kthreads never do. If such a task ever ends up calling stack_top(), it will derefence the NULL ABI po…

πŸ“… Published: Sept. 4, 2025, midnight πŸ”„ Last Modified: Jan. 9, 2026, 5:04 p.m.

5.5

CVSS3.1

CVE-2025-38686 - userfaultfd: fix a crash in UFFDIO_MOVE when PMD is a migration entry

In the Linux kernel, the following vulnerability has been resolved: userfaultfd: fix a crash in UFFDIO_MOVE when PMD is a migration entry When UFFDIO_MOVE encounters a migration PMD entry, it proceeds with obtaining a folio and accessing it even though the entry is swp_entry_t. Add the missing c…

πŸ“… Published: Sept. 4, 2025, midnight πŸ”„ Last Modified: Nov. 24, 2025, 7:48 p.m.

5.5

CVSS3.1

CVE-2025-38683 - hv_netvsc: Fix panic during namespace deletion with VF

In the Linux kernel, the following vulnerability has been resolved: hv_netvsc: Fix panic during namespace deletion with VF The existing code move the VF NIC to new namespace when NETDEV_REGISTER is received on netvsc NIC. During deletion of the namespace, default_device_exit_batch() >> default_de…

πŸ“… Published: Sept. 4, 2025, midnight πŸ”„ Last Modified: Jan. 8, 2026, 10:32 p.m.

5.4

CVSS3.1

CVE-2025-57576 -

PHPGurukul Online Shopping Portal 2.1 is vulnerable to Cross Site Scripting (XSS) in /admin/updateorder.php.

πŸ“… Published: Sept. 4, 2025, midnight πŸ”„ Last Modified: Sept. 10, 2025, 5:04 p.m.

5.5

CVSS3.1

CVE-2025-38721 - netfilter: ctnetlink: fix refcount leak on table dump

In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: fix refcount leak on table dump There is a reference count leak in ctnetlink_dump_table(): if (res < 0) { nf_conntrack_get(&ct->ct_general); // HERE cb->args[1] = (unsig…

πŸ“… Published: Sept. 4, 2025, midnight πŸ”„ Last Modified: Jan. 9, 2026, 3:57 p.m.

5.5

CVSS3.1

CVE-2025-38691 - pNFS: Fix uninited ptr deref in block/scsi layout

In the Linux kernel, the following vulnerability has been resolved: pNFS: Fix uninited ptr deref in block/scsi layout The error occurs on the third attempt to encode extents. When function ext_tree_prepare_commit() reallocates a larger buffer to retry encoding extents, the "layoutupdate_pages" pa…

πŸ“… Published: Sept. 4, 2025, midnight πŸ”„ Last Modified: Jan. 9, 2026, 6:57 p.m.

7.2

CVSS3.1

CVE-2025-57263 -

An authenticated SQL injection vulnerability in VX Guestbook 1.07 allows attackers with admin access to inject malicious SQL payloads via the "word" POST parameter in the words.php admin panel.

πŸ“… Published: Sept. 4, 2025, midnight πŸ”„ Last Modified: Sept. 18, 2025, 4:51 p.m.
Total resulsts: 349182
Page 4023 of 34,919
Β« previous page Β» next page
Filters