7.8

CVSS3.1

CVE-2025-61804 - Animate | Heap-based Buffer Overflow (CWE-122)

Animate versions 23.0.13, 24.0.10 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

πŸ“… Published: Oct. 15, 2025, 12:18 a.m. πŸ”„ Last Modified: Oct. 20, 2025, 1:27 p.m.

7.8

CVSS3.1

CVE-2025-54279 - Animate | Use After Free (CWE-416)

Animate versions 23.0.13, 24.0.10 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

πŸ“… Published: Oct. 15, 2025, 12:18 a.m. πŸ”„ Last Modified: Oct. 20, 2025, 1:27 p.m.

5.5

CVSS3.1

CVE-2025-54269 - Animate | Out-of-bounds Read (CWE-125)

Animate versions 23.0.13, 24.0.10 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a vict…

πŸ“… Published: Oct. 15, 2025, 12:18 a.m. πŸ”„ Last Modified: Oct. 20, 2025, 1:29 p.m.

5.5

CVSS3.1

CVE-2025-54270 - Animate | NULL Pointer Dereference (CWE-476)

Animate versions 23.0.13, 24.0.10 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive memory information. Exploitation of this issue requires user interaction in that a victim mu…

πŸ“… Published: Oct. 15, 2025, 12:18 a.m. πŸ”„ Last Modified: Oct. 20, 2025, 1:29 p.m.

7.0

CVSS3.1

CVE-2025-39999 - blk-mq: fix blk_mq_tags double free while nr_requests grown

In the Linux kernel, the following vulnerability has been resolved: blk-mq: fix blk_mq_tags double free while nr_requests grown In the case user trigger tags grow by queue sysfs attribute nr_requests, hctx->sched_tags will be freed directly and replaced with a new allocated tags, see blk_mq_tag_u…

πŸ“… Published: Oct. 15, 2025, midnight πŸ”„ Last Modified: Oct. 20, 2025, 1:26 p.m.

7.0

CVSS3.1

CVE-2025-39998 - scsi: target: target_core_configfs: Add length check to avoid buffer overflow

In the Linux kernel, the following vulnerability has been resolved: scsi: target: target_core_configfs: Add length check to avoid buffer overflow A buffer overflow arises from the usage of snprintf to write into the buffer "buf" in target_lu_gp_members_show function located in /drivers/target/tar…

πŸ“… Published: Oct. 15, 2025, midnight πŸ”„ Last Modified: Oct. 20, 2025, 1:26 p.m.

7.0

CVSS3.1

CVE-2025-39979 - net/mlx5: fs, fix UAF in flow counter release

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: fs, fix UAF in flow counter release Fix a kernel trace [1] caused by releasing an HWS action of a local flow counter in mlx5_cmd_hws_delete_fte(), where the HWS action refcount and mutex were not initialized and the cou…

πŸ“… Published: Oct. 15, 2025, midnight πŸ”„ Last Modified: Oct. 20, 2025, 1:27 p.m.

7.0

CVSS3.1

CVE-2025-39978 - octeontx2-pf: Fix potential use after free in otx2_tc_add_flow()

In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: Fix potential use after free in otx2_tc_add_flow() This code calls kfree_rcu(new_node, rcu) and then dereferences "new_node" and then dereferences it on the next line. Two lines later, we take a mutex so I don't th…

πŸ“… Published: Oct. 15, 2025, midnight πŸ”„ Last Modified: Oct. 20, 2025, 1:27 p.m.

7.0

CVSS3.1

CVE-2025-39976 - futex: Use correct exit on failure from futex_hash_allocate_default()

In the Linux kernel, the following vulnerability has been resolved: futex: Use correct exit on failure from futex_hash_allocate_default() copy_process() uses the wrong error exit path from futex_hash_allocate_default(). After exiting from futex_hash_allocate_default(), neither tasklist_lock nor s…

πŸ“… Published: Oct. 15, 2025, midnight πŸ”„ Last Modified: Oct. 20, 2025, 1:27 p.m.

7.0

CVSS3.1

CVE-2025-39973 - i40e: add validation for ring_len param

In the Linux kernel, the following vulnerability has been resolved: i40e: add validation for ring_len param The `ring_len` parameter provided by the virtual function (VF) is assigned directly to the hardware memory context (HMC) without any validation. To address this, introduce an upper boundar…

πŸ“… Published: Oct. 15, 2025, midnight πŸ”„ Last Modified: Oct. 20, 2025, 1:27 p.m.
Total resulsts: 314949
Page 67 of 31,495
Β« previous page Β» next page
Filters