5.5

CVSS3.1

CVE-2025-38246 - bnxt: properly flush XDP redirect lists

In the Linux kernel, the following vulnerability has been resolved: bnxt: properly flush XDP redirect lists We encountered following crash when testing a XDP_REDIRECT feature in production: [56251.579676] list_add corruption. next->prev should be prev (ffff93120dd40f30), but was ffffb301ef3a6740…

πŸ“… Published: July 9, 2025, midnight πŸ”„ Last Modified: Nov. 20, 2025, 8:14 p.m.

4.1

CVSS3.1

CVE-2025-52357 -

Cross-Site Scripting (XSS) vulnerability exists in the ping diagnostic feature of FiberHome FD602GW-DX-R410 router (firmware V2.2.14), allowing an authenticated attacker to execute arbitrary JavaScript code in the context of the router s web interface. The vulnerability is triggered via user-suppli…

πŸ“… Published: July 9, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-49604 -

For Realtek AmebaD devices, a heap-based buffer overflow was discovered in Ameba-AIoT ameba-arduino-d before version 3.1.9 and ameba-rtos-d before commit c2bfd8216a1cbc19ad2ab5f48f372ecea756d67a on 2025/07/03. In the WLAN driver defragment function, lack of validation of the size of fragmented Wi-F…

πŸ“… Published: July 9, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2025-38239 - scsi: megaraid_sas: Fix invalid node index

In the Linux kernel, the following vulnerability has been resolved: scsi: megaraid_sas: Fix invalid node index On a system with DRAM interleave enabled, out-of-bound access is detected: megaraid_sas 0000:3f:00.0: requested/available msix 128/128 poll_queue 0 ------------[ cut here ]------------ …

πŸ“… Published: July 9, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 5:15 p.m.

7.5

CVSS3.1

CVE-2025-53645 -

Zimbra Collaboration (ZCS) before 9.0.0 Patch 46, 10.0.x before 10.0.15, and 10.1.x before 10.1.9 is vulnerable to a denial of service condition due to improper handling of excessive, comma-separated path segments in the Admin Console. An unauthenticated remote attacker can send specially crafted G…

πŸ“… Published: July 9, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-52364 -

Insecure Permissions vulnerability in Tenda CP3 Pro Firmware V22.5.4.93 allows the telnet service (telnetd) by default at boot via the initialization script /etc/init.d/eth.sh. This allows remote attackers to connect to the device s shell over the network, potentially without authentication if defa…

πŸ“… Published: July 9, 2025, midnight πŸ”„ Last Modified: Aug. 7, 2025, 6:02 p.m.

5.5

CVSS3.1

CVE-2025-38264 - nvme-tcp: sanitize request list handling

In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: sanitize request list handling Validate the request in nvme_tcp_handle_r2t() to ensure it's not part of any list, otherwise a malicious R2T PDU might inject a loop in request list processing.

πŸ“… Published: July 9, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 6:22 p.m.

5.5

CVSS3.1

CVE-2025-38256 - io_uring/rsrc: fix folio unpinning

In the Linux kernel, the following vulnerability has been resolved: io_uring/rsrc: fix folio unpinning syzbot complains about an unmapping failure: [ 108.070381][ T14] kernel BUG at mm/gup.c:71! [ 108.070502][ T14] Internal error: Oops - BUG: 00000000f2000800 [#1] SMP [ 108.123672][ T1…

πŸ“… Published: July 9, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 8:58 p.m.

5.5

CVSS3.1

CVE-2025-38254 - drm/amd/display: Add sanity checks for drm_edid_raw()

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Add sanity checks for drm_edid_raw() When EDID is retrieved via drm_edid_raw(), it doesn't guarantee to return proper EDID bytes the caller wants: it may be either NULL (that leads to an Oops) or with too long by…

πŸ“… Published: July 9, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 9 p.m.

5.5

CVSS3.1

CVE-2025-38253 - HID: wacom: fix crash in wacom_aes_battery_handler()

In the Linux kernel, the following vulnerability has been resolved: HID: wacom: fix crash in wacom_aes_battery_handler() Commit fd2a9b29dc9c ("HID: wacom: Remove AES power_supply after extended inactivity") introduced wacom_aes_battery_handler() which is scheduled as a delayed work (aes_battery_w…

πŸ“… Published: July 9, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 9 p.m.
Total resulsts: 349182
Page 4711 of 34,919
Β« previous page Β» next page
Filters