5.5

CVSS3.1

CVE-2025-22048 - LoongArch: BPF: Don't override subprog's return value

In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Don't override subprog's return value The verifier test `calls: div by 0 in subprog` triggers a panic at the ld.bu instruction. The ld.bu insn is trying to load byte from memory address returned by the subprog. Th…

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: Oct. 31, 2025, 8:20 p.m.

5.5

CVSS3.1

CVE-2025-22046 - uprobes/x86: Harden uretprobe syscall trampoline check

In the Linux kernel, the following vulnerability has been resolved: uprobes/x86: Harden uretprobe syscall trampoline check Jann reported a possible issue when trampoline_check_ip returns address near the bottom of the address space that is allowed to call into the syscall if uretprobes are not se…

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: Oct. 31, 2025, 8:39 p.m.

5.5

CVSS3.1

CVE-2025-22045 - x86/mm: Fix flush_tlb_range() when used for zapping normal PMDs

In the Linux kernel, the following vulnerability has been resolved: x86/mm: Fix flush_tlb_range() when used for zapping normal PMDs On the following path, flush_tlb_range() can be used for zapping normal PMD entries (PMD entries that point to page tables) together with the PTE entries in the poin…

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:17 p.m.

7.8

CVSS3.1

CVE-2025-22035 - tracing: Fix use-after-free in print_graph_function_flags during tracer switching

In the Linux kernel, the following vulnerability has been resolved: tracing: Fix use-after-free in print_graph_function_flags during tracer switching Kairui reported a UAF issue in print_graph_function_flags() during ftrace stress testing [1]. This issue can be reproduced if puting a 'mdelay(10)'…

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:17 p.m.

5.5

CVSS3.1

CVE-2025-22117 - ice: fix using untrusted value of pkt_len in ice_vc_fdir_parse_raw()

In the Linux kernel, the following vulnerability has been resolved: ice: fix using untrusted value of pkt_len in ice_vc_fdir_parse_raw() Fix using the untrusted value of proto->raw.pkt_len in function ice_vc_fdir_parse_raw() by verifying if it does not exceed the VIRTCHNL_MAX_SIZE_RAW_PACKET valu…

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: April 2, 2026, 11:30 a.m.

8.8

CVSS3.1

CVE-2025-22041 - ksmbd: fix use-after-free in ksmbd_sessions_deregister()

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in ksmbd_sessions_deregister() In multichannel mode, UAF issue can occur in session_deregister when the second channel sets up a session through the connection of the first channel. session that is freed…

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: April 2, 2026, 8:39 a.m.

9.8

CVSS3.1

CVE-2025-29708 -

SourceCodester Company Website CMS 1.0 contains a file upload vulnerability via the "Create Services" file /dashboard/Services.

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: April 23, 2025, 4:33 p.m.

6.1

CVSS3.1

CVE-2025-43703 -

An issue was discovered in Ankitects Anki through 25.02. A crafted shared deck can result in attacker-controlled access to the internal API (even though the attacker has no knowledge of an API key) through approaches such as scripts or the SRC attribute of an IMG element. NOTE: this issue exists be…

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: Oct. 9, 2025, 2:56 p.m.

4.7

CVSS3.1

CVE-2025-43704 -

Arctera/Veritas Data Insight before 7.1.2 can send cleartext credentials when configured to use HTTP Basic Authentication to a Dell Isilon OneFS server.

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2025-22070 - fs/9p: fix NULL pointer dereference on mkdir

In the Linux kernel, the following vulnerability has been resolved: fs/9p: fix NULL pointer dereference on mkdir When a 9p tree was mounted with option 'posixacl', parent directory had a default ACL set for its subdirectories, e.g.: setfacl -m default:group:simpsons:rwx parentdir then creatin…

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 5:15 p.m.
Total resulsts: 345788
Page 5457 of 34,579
Β« previous page Β» next page
Filters