5.5

CVSS3.1

CVE-2025-38283 - hisi_acc_vfio_pci: bugfix live migration function without VF device driver

In the Linux kernel, the following vulnerability has been resolved: hisi_acc_vfio_pci: bugfix live migration function without VF device driver If the VF device driver is not loaded in the Guest OS and we attempt to perform device data migration, the address of the migrated data will be NULL. The …

πŸ“… Published: July 10, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 9:58 p.m.

5.5

CVSS3.1

CVE-2025-38271 - net: prevent a NULL deref in rtnl_create_link()

In the Linux kernel, the following vulnerability has been resolved: net: prevent a NULL deref in rtnl_create_link() At the time rtnl_create_link() is running, dev->netdev_ops is NULL, we must not use netdev_lock_ops() or risk a NULL deref if CONFIG_NET_SHAPER is defined. Use netif_set_group() in…

πŸ“… Published: July 10, 2025, midnight πŸ”„ Last Modified: Nov. 20, 2025, 4:53 p.m.

5.5

CVSS3.1

CVE-2025-38269 - btrfs: exit after state insertion failure at btrfs_convert_extent_bit()

In the Linux kernel, the following vulnerability has been resolved: btrfs: exit after state insertion failure at btrfs_convert_extent_bit() If insert_state() state failed it returns an error pointer and we call extent_io_tree_panic() which will trigger a BUG() call. However if CONFIG_BUG is disab…

πŸ“… Published: July 10, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 3:30 p.m.

7.8

CVSS3.1

CVE-2025-7425 - Libxslt: heap use-after-free in libxslt caused by atype corruption in xmlattrptr

A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may acce…

πŸ“… Published: July 10, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2025-38343 - wifi: mt76: mt7996: drop fragments with multicast or broadcast RA

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: drop fragments with multicast or broadcast RA IEEE 802.11 fragmentation can only be applied to unicast frames. Therefore, drop fragments with multicast or broadcast RA. This patch addresses vulnerabilities suc…

πŸ“… Published: July 10, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 12:52 p.m.

5.5

CVSS3.1

CVE-2025-38304 - Bluetooth: Fix NULL pointer deference on eir_get_service_data

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix NULL pointer deference on eir_get_service_data The len parameter is considered optional so it can be NULL so it cannot be used for skipping to next entry of EIR_SERVICE_DATA.

πŸ“… Published: July 10, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 5:57 p.m.

7.1

CVSS3.1

CVE-2025-38286 - pinctrl: at91: Fix possible out-of-boundary access

In the Linux kernel, the following vulnerability has been resolved: pinctrl: at91: Fix possible out-of-boundary access at91_gpio_probe() doesn't check that given OF alias is not available or something went wrong when trying to get it. This might have consequences when accessing gpio_chips array w…

πŸ“… Published: July 10, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 4:44 p.m.

5.5

CVSS3.1

CVE-2025-38318 - perf: arm-ni: Fix missing platform_set_drvdata()

In the Linux kernel, the following vulnerability has been resolved: perf: arm-ni: Fix missing platform_set_drvdata() Add missing platform_set_drvdata in arm_ni_probe(), otherwise calling platform_get_drvdata() in remove returns NULL.

πŸ“… Published: July 10, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 12:54 p.m.

6.1

CVSS3.1

CVE-2024-36697 -

A cross-site scripting (XSS) vulnerability in the Admin Login page of Allworx System Software v9.1.9.12 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the SessionID parameter at query.asp.

πŸ“… Published: July 10, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2025-38332 - scsi: lpfc: Use memcpy() for BIOS version

In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Use memcpy() for BIOS version The strlcat() with FORTIFY support is triggering a panic because it thinks the target buffer will overflow although the correct target buffer size is passed in. Anyway, instead of memset…

πŸ“… Published: July 10, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 3:30 p.m.
Total resulsts: 345149
Page 4289 of 34,515
Β« previous page Β» next page
Filters