4.3

CVSS3.1

CVE-2025-2404 - XSS in Ubit Information Technologies' STOYS

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ubit Information Technologies STOYS allows Cross-Site Scripting (XSS).This issue affects STOYS: from 2 through 20250916.Β  NOTE: The vendor did not inform about the completion of the fixing …

πŸ“… Published: Sept. 16, 2025, 8:33 a.m. πŸ”„ Last Modified: Sept. 16, 2025, 8:33 a.m.

0.0

CVE-2023-53303 - net: microchip: vcap api: Fix possible memory leak for vcap_dup_rule()

In the Linux kernel, the following vulnerability has been resolved: net: microchip: vcap api: Fix possible memory leak for vcap_dup_rule() Inject fault When select CONFIG_VCAP_KUNIT_TEST, the below memory leak occurs. If kzalloc() for duprule succeeds, but the following kmemdup() fails, the dupru…

πŸ“… Published: Sept. 16, 2025, 8:11 a.m. πŸ”„ Last Modified: Sept. 16, 2025, 8:11 a.m.

0.0

CVE-2023-53302 - wifi: iwl4965: Add missing check for create_singlethread_workqueue()

In the Linux kernel, the following vulnerability has been resolved: wifi: iwl4965: Add missing check for create_singlethread_workqueue() Add the check for the return value of the create_singlethread_workqueue() in order to avoid NULL pointer dereference.

πŸ“… Published: Sept. 16, 2025, 8:11 a.m. πŸ”„ Last Modified: Sept. 16, 2025, 8:11 a.m.

0.0

CVE-2023-53301 - f2fs: fix kernel crash due to null io->bio

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix kernel crash due to null io->bio We should return when io->bio is null before doing anything. Otherwise, panic. BUG: kernel NULL pointer dereference, address: 0000000000000010 RIP: 0010:__submit_merged_write_cond+0x164…

πŸ“… Published: Sept. 16, 2025, 8:11 a.m. πŸ”„ Last Modified: Sept. 16, 2025, 8:11 a.m.

0.0

CVE-2023-53300 - media: hi846: Fix memleak in hi846_init_controls()

In the Linux kernel, the following vulnerability has been resolved: media: hi846: Fix memleak in hi846_init_controls() hi846_init_controls doesn't clean the allocated ctrl_hdlr in case there is a failure, which causes memleak. Add v4l2_ctrl_handler_free to free the resource properly.

πŸ“… Published: Sept. 16, 2025, 8:11 a.m. πŸ”„ Last Modified: Sept. 16, 2025, 8:11 a.m.

0.0

CVE-2023-53299 - md/raid10: fix leak of 'r10bio->remaining' for recovery

In the Linux kernel, the following vulnerability has been resolved: md/raid10: fix leak of 'r10bio->remaining' for recovery raid10_sync_request() will add 'r10bio->remaining' for both rdev and replacement rdev. However, if the read io fails, recovery_request_write() returns without issuing the wr…

πŸ“… Published: Sept. 16, 2025, 8:11 a.m. πŸ”„ Last Modified: Sept. 16, 2025, 8:11 a.m.

0.0

CVE-2023-53298 - nfc: fix memory leak of se_io context in nfc_genl_se_io

In the Linux kernel, the following vulnerability has been resolved: nfc: fix memory leak of se_io context in nfc_genl_se_io The callback context for sending/receiving APDUs to/from the selected secure element is allocated inside nfc_genl_se_io and supposed to be eventually freed in se_io_cb callb…

πŸ“… Published: Sept. 16, 2025, 8:11 a.m. πŸ”„ Last Modified: Sept. 16, 2025, 8:11 a.m.

0.0

CVE-2023-53297 - Bluetooth: L2CAP: fix "bad unlock balance" in l2cap_disconnect_rsp

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: fix "bad unlock balance" in l2cap_disconnect_rsp conn->chan_lock isn't acquired before l2cap_get_chan_by_scid, if l2cap_get_chan_by_scid returns NULL, then 'bad unlock balance' is triggered.

πŸ“… Published: Sept. 16, 2025, 8:11 a.m. πŸ”„ Last Modified: Sept. 16, 2025, 8:11 a.m.

0.0

CVE-2023-53296 - sctp: check send stream number after wait_for_sndbuf

In the Linux kernel, the following vulnerability has been resolved: sctp: check send stream number after wait_for_sndbuf This patch fixes a corner case where the asoc out stream count may change after wait_for_sndbuf. When the main thread in the client starts a connection, if its out stream coun…

πŸ“… Published: Sept. 16, 2025, 8:11 a.m. πŸ”„ Last Modified: Sept. 16, 2025, 8:11 a.m.

0.0

CVE-2023-53295 - udf: Do not update file length for failed writes to inline files

In the Linux kernel, the following vulnerability has been resolved: udf: Do not update file length for failed writes to inline files When write to inline file fails (or happens only partly), we still updated length of inline data as if the whole write succeeded. Fix the update of length of inline…

πŸ“… Published: Sept. 16, 2025, 8:11 a.m. πŸ”„ Last Modified: Sept. 16, 2025, 8:11 a.m.
Total resulsts: 310023
Page 8 of 31,003
Β« previous page Β» next page
Filters