5.5

CVSS3.1

CVE-2025-38468 - net/sched: Return NULL when htb_lookup_leaf encounters an empty rbtree

In the Linux kernel, the following vulnerability has been resolved: net/sched: Return NULL when htb_lookup_leaf encounters an empty rbtree htb_lookup_leaf has a BUG_ON that can trigger with the following: tc qdisc del dev lo root tc qdisc add dev lo root handle 1: htb default 1 tc class add dev …

πŸ“… Published: July 28, 2025, midnight πŸ”„ Last Modified: Dec. 22, 2025, 7:36 p.m.

7.5

CVSS3.1

CVE-2025-50494 -

Improper session invalidation in the component /doctor/change-password.php of PHPGurukul Car Washing Management System v1.0 allows attackers to execute a session hijacking attack.

πŸ“… Published: July 28, 2025, midnight πŸ”„ Last Modified: July 29, 2025, 9:15 p.m.

5.5

CVSS3.1

CVE-2025-38474 - usb: net: sierra: check for no status endpoint

In the Linux kernel, the following vulnerability has been resolved: usb: net: sierra: check for no status endpoint The driver checks for having three endpoints and having bulk in and out endpoints, but not that the third endpoint is interrupt input. Rectify the omission.

πŸ“… Published: July 28, 2025, midnight πŸ”„ Last Modified: Dec. 22, 2025, 7:29 p.m.

4.1

CVSS3.1

CVE-2023-53158 - gix-transport: gix Command Execution Vulnerability

The gix-transport crate before 0.36.1 for Rust allows command execution via the "gix clone 'ssh://-oProxyCommand=open$IFS" substring. NOTE: this was discovered before CVE-2024-32884, a similar vulnerability (involving a username field) that is more difficult to exploit.

πŸ“… Published: July 28, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.7

CVSS3.1

CVE-2025-8283 - Netavark: podman: netavark may resolve hostnames to unexpected hosts

A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When creating a container with a given name, this name will be used…

πŸ“… Published: July 28, 2025, midnight πŸ”„ Last Modified: Nov. 7, 2025, 10:15 p.m.

7.1

CVSS3.1

CVE-2025-50491 -

Improper session invalidation in the component /banker/change-password.php of PHPGurukul Bank Locker Management System v1 allows attackers to execute a session hijacking attack.

πŸ“… Published: July 28, 2025, midnight πŸ”„ Last Modified: July 29, 2025, 9:17 p.m.

7.8

CVSS3.1

CVE-2025-38494 - HID: core: do not bypass hid_hw_raw_request

In the Linux kernel, the following vulnerability has been resolved: HID: core: do not bypass hid_hw_raw_request hid_hw_raw_request() is actually useful to ensure the provided buffer and length are valid. Directly calling in the low level transport driver function bypassed those checks and allowed…

πŸ“… Published: July 28, 2025, midnight πŸ”„ Last Modified: March 17, 2026, 4 p.m.

5.5

CVSS3.1

CVE-2025-38489 - s390/bpf: Fix bpf_arch_text_poke() with new_addr == NULL again

In the Linux kernel, the following vulnerability has been resolved: s390/bpf: Fix bpf_arch_text_poke() with new_addr == NULL again Commit 7ded842b356d ("s390/bpf: Fix bpf_plt pointer arithmetic") has accidentally removed the critical piece of commit c730fce7c70c ("s390/bpf: Fix bpf_arch_text_poke…

πŸ“… Published: July 28, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 5:45 p.m.

7.8

CVSS3.1

CVE-2025-38485 - iio: accel: fxls8962af: Fix use after free in fxls8962af_fifo_flush

In the Linux kernel, the following vulnerability has been resolved: iio: accel: fxls8962af: Fix use after free in fxls8962af_fifo_flush fxls8962af_fifo_flush() uses indio_dev->active_scan_mask (with iio_for_each_active_channel()) without making sure the indio_dev stays in buffer mode. There is a …

πŸ“… Published: July 28, 2025, midnight πŸ”„ Last Modified: Jan. 7, 2026, 4:25 p.m.

5.5

CVSS3.1

CVE-2025-38478 - comedi: Fix initialization of data for instructions that write to subdevice

In the Linux kernel, the following vulnerability has been resolved: comedi: Fix initialization of data for instructions that write to subdevice Some Comedi subdevice instruction handlers are known to access instruction data elements beyond the first `insn->n` elements in some cases. The `do_insn…

πŸ“… Published: July 28, 2025, midnight πŸ”„ Last Modified: Dec. 23, 2025, 6:27 p.m.
Total resulsts: 346656
Page 4241 of 34,666
Β« previous page Β» next page
Filters