6.5

CVSS3.1

CVE-2025-25774 -

An issue was discovered in Open5GS v2.7.2. When a UE switches between two gNBs and sends a handover request at a specific time, it may cause an exception in the AMF's internal state machine, leading to an AMF crash and resulting in a Denial of Service (DoS).

πŸ“… Published: March 12, 2025, midnight πŸ”„ Last Modified: April 29, 2025, 3:04 p.m.

5.5

CVSS3.1

CVE-2025-21850 - nvmet: Fix crash when a namespace is disabled

In the Linux kernel, the following vulnerability has been resolved: nvmet: Fix crash when a namespace is disabled The namespace percpu counter protects pending I/O, and we can only safely diable the namespace once the counter drop to zero. Otherwise we end up with a crash when running blktests/nv…

πŸ“… Published: March 12, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 8:18 p.m.

5.5

CVSS3.1

CVE-2025-21845 - mtd: spi-nor: sst: Fix SST write failure

In the Linux kernel, the following vulnerability has been resolved: mtd: spi-nor: sst: Fix SST write failure 'commit 18bcb4aa54ea ("mtd: spi-nor: sst: Factor out common write operation to `sst_nor_write_data()`")' introduced a bug where only one byte of data is written, regardless of the number o…

πŸ“… Published: March 12, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 8:18 p.m.

5.6

CVSS3.1

CVE-2025-25683 -

AlekSIS-Core is vulnerable to Incorrect Access Control. Unauthenticated users can access all PDF files. This affects AlekSIS-Core 3.0, 3.1, 3.1.1, 3.1.2, 3.1.3, 3.1.4, 3.1.5, 3.1.6, 3.2.0 and 3.2.1.

πŸ“… Published: March 12, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2025-21856 - s390/ism: add release function for struct device

In the Linux kernel, the following vulnerability has been resolved: s390/ism: add release function for struct device According to device_release() in /drivers/base/core.c, a device without a release function is a broken device and must be fixed. The current code directly frees the device after c…

πŸ“… Published: March 12, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 8:18 p.m.

3.3

CVSS3.1

CVE-2025-21851 - bpf: Fix softlockup in arena_map_free on 64k page kernel

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix softlockup in arena_map_free on 64k page kernel On an aarch64 kernel with CONFIG_PAGE_SIZE_64KB=y, arena_htab tests cause a segmentation fault and soft lockup. The same failure is not observed with 4k pages on aarch64. …

πŸ“… Published: March 12, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 8:18 p.m.

5.5

CVSS3.1

CVE-2025-21857 - net/sched: cls_api: fix error handling causing NULL dereference

In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: fix error handling causing NULL dereference tcf_exts_miss_cookie_base_alloc() calls xa_alloc_cyclic() which can return 1 if the allocation succeeded after wrapping. This was treated as an error, with value 1 r…

πŸ“… Published: March 12, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 8:18 p.m.

5.5

CVSS3.1

CVE-2025-21844 - smb: client: Add check for next_buffer in receive_encrypted_standard()

In the Linux kernel, the following vulnerability has been resolved: smb: client: Add check for next_buffer in receive_encrypted_standard() Add check for the return value of cifs_buf_get() and cifs_small_buf_get() in receive_encrypted_standard() to prevent null pointer dereference.

πŸ“… Published: March 12, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:17 p.m.

8.8

CVSS3.1

CVE-2025-26260 -

Plenti <= 0.7.16 is vulnerable to code execution. Users uploading '.svelte' files with the /postLocal endpoint can define the file name as javascript codes. The server executes the uploaded file name in host, and cause code execution.

πŸ“… Published: March 12, 2025, midnight πŸ”„ Last Modified: Oct. 2, 2025, 3:55 p.m.

5.4

CVSS3.1

CVE-2025-27914 -

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Reflected Cross-Site Scripting (XSS) vulnerability exists in the /h/rest endpoint, allowing authenticated attackers to inject and execute arbitrary JavaScript in a victim's session. Exploitation requires a valid auth tok…

πŸ“… Published: March 12, 2025, midnight πŸ”„ Last Modified: April 2, 2025, 8:38 p.m.
Total resulsts: 347394
Page 6183 of 34,740
Β« previous page Β» next page
Filters