6.6

CVSS3.1

CVE-2025-5915 - Libarchive: heap buffer over read in copy_from_lzss_window() at archive_read_support_format_rar.c

A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may attempt to read beyond the allocated memory buffer, which can…

πŸ“… Published: May 20, 2025, midnight πŸ”„ Last Modified: Jan. 8, 2026, 4:15 a.m.

5.5

CVSS3.1

CVE-2025-37974 - s390/pci: Fix missing check for zpci_create_device() error return

In the Linux kernel, the following vulnerability has been resolved: s390/pci: Fix missing check for zpci_create_device() error return The zpci_create_device() function returns an error pointer that needs to be checked before dereferencing it as a struct zpci_dev pointer. Add the missing check in …

πŸ“… Published: May 20, 2025, midnight πŸ”„ Last Modified: Nov. 14, 2025, 5:01 p.m.

9.8

CVSS3.1

CVE-2025-44888 -

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the stp_conf_name parameter in the web_stp_globalSetting_post function.

πŸ“… Published: May 20, 2025, midnight πŸ”„ Last Modified: May 29, 2025, 3:54 p.m.

9.8

CVSS3.1

CVE-2025-44880 -

A command injection vulnerability in the component /cgi-bin/adm.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input.

πŸ“… Published: May 20, 2025, midnight πŸ”„ Last Modified: May 30, 2025, 1:20 a.m.

5.5

CVSS3.1

CVE-2025-37945 - net: phy: allow MDIO bus PM ops to start/stop state machine for phylink-controlled PHY

In the Linux kernel, the following vulnerability has been resolved: net: phy: allow MDIO bus PM ops to start/stop state machine for phylink-controlled PHY DSA has 2 kinds of drivers: 1. Those who call dsa_switch_suspend() and dsa_switch_resume() from their device PM ops: qca8k-8xxx, bcm_sf2, …

πŸ“… Published: May 20, 2025, midnight πŸ”„ Last Modified: April 20, 2026, 6:15 p.m.

7.8

CVSS3.1

CVE-2025-37991 - parisc: Fix double SIGFPE crash

In the Linux kernel, the following vulnerability has been resolved: parisc: Fix double SIGFPE crash Camm noticed that on parisc a SIGFPE exception will crash an application with a second SIGFPE in the signal handler. Dave analyzed it, and it happens because glibc uses a double-word floating-poin…

πŸ“… Published: May 20, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 3:29 p.m.

5.5

CVSS3.1

CVE-2025-37990 - wifi: brcm80211: fmac: Add error handling for brcmf_usb_dl_writeimage()

In the Linux kernel, the following vulnerability has been resolved: wifi: brcm80211: fmac: Add error handling for brcmf_usb_dl_writeimage() The function brcmf_usb_dl_writeimage() calls the function brcmf_usb_dl_cmd() but dose not check its return value. The 'state.state' and the 'state.bytes' are…

πŸ“… Published: May 20, 2025, midnight πŸ”„ Last Modified: Dec. 16, 2025, 8:19 p.m.

4.7

CVSS3.1

CVE-2025-37988 - fix a couple of races in MNT_TREE_BENEATH handling by do_move_mount()

In the Linux kernel, the following vulnerability has been resolved: fix a couple of races in MNT_TREE_BENEATH handling by do_move_mount() Normally do_lock_mount(path, _) is locking a mountpoint pinned by *path and at the time when matching unlock_mount() unlocks that location it is still pinned b…

πŸ“… Published: May 20, 2025, midnight πŸ”„ Last Modified: Nov. 14, 2025, 4:59 p.m.

5.5

CVSS3.1

CVE-2025-37987 - pds_core: Prevent possible adminq overflow/stuck condition

In the Linux kernel, the following vulnerability has been resolved: pds_core: Prevent possible adminq overflow/stuck condition The pds_core's adminq is protected by the adminq_lock, which prevents more than 1 command to be posted onto it at any one time. This makes it so the client drivers cannot…

πŸ“… Published: May 20, 2025, midnight πŸ”„ Last Modified: Nov. 14, 2025, 4:59 p.m.

5.5

CVSS3.1

CVE-2025-37983 - qibfs: fix _another_ leak

In the Linux kernel, the following vulnerability has been resolved: qibfs: fix _another_ leak failure to allocate inode => leaked dentry... this one had been there since the initial merge; to be fair, if we are that far OOM, the odds of failing at that particular allocation are low...

πŸ“… Published: May 20, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 3:29 p.m.
Total resulsts: 349182
Page 5314 of 34,919
Β« previous page Β» next page
Filters