0.0

CVE-2022-50340 - media: vimc: Fix wrong function called when vimc_init() fails

In the Linux kernel, the following vulnerability has been resolved: media: vimc: Fix wrong function called when vimc_init() fails In vimc_init(), when platform_driver_register(&vimc_pdrv) fails, platform_driver_unregister(&vimc_pdrv) is wrongly called rather than platform_device_unregister(&vimc_…

πŸ“… Published: Sept. 16, 2025, 4:11 p.m. πŸ”„ Last Modified: Sept. 16, 2025, 4:11 p.m.

0.0

CVE-2022-50339 - Bluetooth: avoid hci_dev_test_and_set_flag() in mgmt_init_hdev()

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: avoid hci_dev_test_and_set_flag() in mgmt_init_hdev() syzbot is again reporting attempt to cancel uninitialized work at mgmt_index_removed() [1], for setting of HCI_MGMT flag from mgmt_init_hdev() from hci_mgmt_cmd() f…

πŸ“… Published: Sept. 16, 2025, 4:11 p.m. πŸ”„ Last Modified: Sept. 16, 2025, 4:11 p.m.

6.9

CVSS4.0

CVE-2025-43801 -

Unchecked input for loop condition vulnerability in XML-RPC in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers t…

πŸ“… Published: Sept. 16, 2025, 4:09 p.m. πŸ”„ Last Modified: Sept. 16, 2025, 4:09 p.m.

2.1

CVSS4.0

CVE-2025-58749 - WAMR runtime hangs or crashes with large memory.fill addresses in LLVM-JIT mode

WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. In WAMR versions prior to 2.4.2, when running in LLVM-JIT mode, the runtime cannot exit normally when executing WebAssembly programs containing a memory.fill instruction where the first operand (memory address …

πŸ“… Published: Sept. 16, 2025, 3:53 p.m. πŸ”„ Last Modified: Sept. 16, 2025, 3:53 p.m.

10

CVSS3.1

CVE-2025-41243 - Spring Expression Language property modification using Spring Cloud Gateway Server WebFlux

Spring Cloud Gateway Server Webflux may be vulnerable to Spring Environment property modification. An application should be considered vulnerable when all the following are true: * The application is using Spring Cloud Gateway Server Webflux (Spring Cloud Gateway Server WebMVC is not vulnerabl…

πŸ“… Published: Sept. 16, 2025, 2:54 p.m. πŸ”„ Last Modified: Sept. 16, 2025, 2:54 p.m.

7.4

CVSS3.1

CVE-2025-4953 - Podman: build context bind mount

A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman build is not discarded. This issue can lead to files created within the container appearing in the temporary build context directory on the host, leaving the created files access…

πŸ“… Published: Sept. 16, 2025, 2:54 p.m. πŸ”„ Last Modified: Sept. 16, 2025, 2:54 p.m.

2.3

CVSS4.0

CVE-2025-59270 - psPAS does not enforce TLS within Get-PASSAMLResponse

psPAS PowerShell module does not explicitly enforce TLS 1.2 within the 'Get-PASSAMLResponse' function during the SAML authentication process. An unauthenticated attacker in a 'Man-in-the-Middle' position could manipulate the TLS handshake and downgrade TLS to a deprecated protocol. Fixed in 7.0.209.

πŸ“… Published: Sept. 16, 2025, 2:41 p.m. πŸ”„ Last Modified: Sept. 16, 2025, 2:41 p.m.

7.4

CVSS3.1

CVE-2025-36244 - IBM AIX privilege escalation

IBM AIX 7.2, 7.3, IBM VIOS 3.1, and 4.1, when configured to use Kerberos network authentication, could allow a local user to write to files on the system with root privileges due to improper initialization of critical variables.

πŸ“… Published: Sept. 16, 2025, 2:38 p.m. πŸ”„ Last Modified: Sept. 16, 2025, 2:38 p.m.

9.3

CVSS4.0

CVE-2009-20007 - Talkative IRC v0.4.4.16 Response Buffer Overflow

Talkative IRC v0.4.4.16 is vulnerable to a stack-based buffer overflow when processing specially crafted response strings sent to a connected client. An attacker can exploit this flaw by sending an overly long message that overflows a fixed-length buffer, potentially leading to arbitrary code execu…

πŸ“… Published: Sept. 16, 2025, 2:34 p.m. πŸ”„ Last Modified: Sept. 16, 2025, 2:34 p.m.

9.3

CVSS4.0

CVE-2009-20006 - osCommerce <= 2.2 Admin File Manager Arbitrary PHP Code Execution

osCommerce versions up to and including 2.2 RC2a contain a vulnerability in its administrative file manager utility (admin/file_manager.php). The interface allows file uploads and edits without sufficient input validation or access control. An unauthenticated attacker can craft a POST request to up…

πŸ“… Published: Sept. 16, 2025, 2:33 p.m. πŸ”„ Last Modified: Sept. 16, 2025, 2:33 p.m.
Total resulsts: 310194
Page 6 of 31,020
Β« previous page Β» next page
Filters