5.5

CVSS3.1

CVE-2022-49757 - EDAC/highbank: Fix memory leak in highbank_mc_probe()

In the Linux kernel, the following vulnerability has been resolved: EDAC/highbank: Fix memory leak in highbank_mc_probe() When devres_open_group() fails, it returns -ENOMEM without freeing memory allocated by edac_mc_alloc(). Call edac_mc_free() on the error handling path to avoid a memory leak.…

📅 Published: March 27, 2025, midnight 🔄 Last Modified: Oct. 1, 2025, 6:15 p.m.

7.8

CVSS3.1

CVE-2022-49755 - usb: gadget: f_fs: Prevent race during ffs_ep0_queue_wait

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Prevent race during ffs_ep0_queue_wait While performing fast composition switch, there is a possibility that the process of ffs_ep0_write/ffs_ep0_read get into a race condition due to ep0req being freed up from…

📅 Published: March 27, 2025, midnight 🔄 Last Modified: May 4, 2025, 8:44 a.m.

5.5

CVSS3.1

CVE-2022-49751 - w1: fix WARNING after calling w1_process()

In the Linux kernel, the following vulnerability has been resolved: w1: fix WARNING after calling w1_process() I got the following WARNING message while removing driver(ds2482): ------------[ cut here ]------------ do not call blocking ops when !TASK_RUNNING; state=1 set at [<000000002d50bfb6>] …

📅 Published: March 27, 2025, midnight 🔄 Last Modified: Oct. 1, 2025, 8:17 p.m.

5.5

CVSS3.1

CVE-2022-49749 - i2c: designware: use casting of u64 in clock multiplication to avoid overflow

In the Linux kernel, the following vulnerability has been resolved: i2c: designware: use casting of u64 in clock multiplication to avoid overflow In functions i2c_dw_scl_lcnt() and i2c_dw_scl_hcnt() may have overflow by depending on the values of the given parameters including the ic_clk. For exa…

📅 Published: March 27, 2025, midnight 🔄 Last Modified: Oct. 1, 2025, 6:15 p.m.

5.5

CVSS3.1

CVE-2022-49748 - perf/x86/amd: fix potential integer overflow on shift of a int

In the Linux kernel, the following vulnerability has been resolved: perf/x86/amd: fix potential integer overflow on shift of a int The left shift of int 32 bit integer constant 1 is evaluated using 32 bit arithmetic and then passed as a 64 bit function argument. In the case where i is 32 or more …

📅 Published: March 27, 2025, midnight 🔄 Last Modified: Oct. 1, 2025, 6:15 p.m.

4.3

CVSS3.1

CVE-2025-20230 - Missing Access Control and Incorrect Ownership of Data in App Key Value Store (KVStore) collections…

In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and versions below 3.8.38 and 3.7.23 of the Splunk Secure Gateway app on Splunk Cloud Platform, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles could edit and delete other user data in App Key Value Sto…

📅 Published: March 26, 2025, 10:24 p.m. 🔄 Last Modified: Aug. 1, 2025, 6:01 p.m.

2.5

CVSS3.1

CVE-2025-20233 - Incorrect permissions set by the “chmod“ and “makedirs“ Python functions in Splunk App for Lookup F…

In the Splunk App for Lookup File Editing versions below 4.0.5, a script in the app used the `chmod` and `makedirs` Python functions in a way that resulted in overly broad read and execute permissions. This could lead to improper access control for a low-privileged user.

📅 Published: March 26, 2025, 10:06 p.m. 🔄 Last Modified: Aug. 1, 2025, 6:03 p.m.

5.7

CVSS3.1

CVE-2025-20232 - Risky Command Safeguards Bypass in “/app/search/search“ endpoint through “s“ parameter in Splunk En…

In Splunk Enterprise versions below 9.3.3, 9.2.5, and 9.1.8 and Splunk Cloud Platform versions below 9.3.2408.103, 9.2.2406.108, 9.2.2403.113, 9.1.2312.208 and 9.1.2308.212, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles could run a saved search with a risky command us…

📅 Published: March 26, 2025, 10:06 p.m. 🔄 Last Modified: July 21, 2025, 8:45 p.m.

8

CVSS3.1

CVE-2025-20229 - Remote Code Execution through file upload to “$SPLUNK_HOME/var/run/splunk/apptemp“ directory in Spl…

In Splunk Enterprise versions below 9.3.3, 9.2.5, and 9.1.8, and Splunk Cloud Platform versions below 9.3.2408.104, 9.2.2406.108, 9.2.2403.114, and 9.1.2312.208, a low-privileged user that does not hold the "admin" or "power" Splunk roles could perform a Remote Code Execution (RCE) through a file …

📅 Published: March 26, 2025, 10:05 p.m. 🔄 Last Modified: Feb. 26, 2026, 7:09 p.m.

6.5

CVSS3.1

CVE-2025-20228 - Maintenance mode state change of App Key Value Store (KVStore) through a Cross-Site Request Forgery…

In Splunk Enterprise versions below 9.3.3, 9.2.5, and 9.1.8 and Splunk Cloud Platform versions below 9.2.2403.108, and 9.1.2312.204, a low-privileged user that does not hold the "admin" or "power" Splunk roles could change the maintenance mode state of App Key Value Store (KVStore) through a Cross-…

📅 Published: March 26, 2025, 10:04 p.m. 🔄 Last Modified: July 21, 2025, 8:50 p.m.
Total resulsts: 346710
Page 5951 of 34,671
« previous page » next page
Filters