Количество 26 125
Количество 26 125
CVE-2025-23140
misc: pci_endpoint_test: Avoid issue of interrupts remaining after request_irq error
CVE-2025-23136
thermal: int340x: Add NULL check for adev
CVE-2025-23135
RISC-V: KVM: Teardown riscv specific bits after kvm_exit
CVE-2025-23133
wifi: ath11k: update channel list in reg notifier instead reg worker
CVE-2025-23132
f2fs: quota: fix to avoid warning in dquot_writeback_dquots()
CVE-2025-23131
dlm: prevent NPD when writing a positive value to event_done
CVE-2025-23130
f2fs: fix to avoid panic once fallocation fails for pinfile
CVE-2025-2312
cifs.upcall makes an upcall to the wrong namespace in containerized environments
CVE-2025-23129
wifi: ath11k: Clear affinity hint before calling ath11k_pcic_free_irq() in error path
CVE-2025-2310
HDF5 Metadata Attribute Decoder H5MM_strndup heap-based overflow
CVE-2025-2309
HDF5 Type Conversion Logic H5T__bit_copy heap-based overflow
CVE-2025-23090
Rejected reason: This CVE record has been withdrawn due to a duplicate entry CVE-2025-23083.
CVE-2025-2308
HDF5 Scale-Offset Filter H5Z__scaleoffset_decompress_one_byte heap-based overflow
CVE-2025-23085
A memory leak could occur when a remote peer abruptly closes the socket without sending a GOAWAY notification. Additionally, if an invalid header was detected by nghttp2, causing the connection to be terminated by the peer, the same leak was triggered. This flaw could lead to increased memory consumption and potential denial of service under certain conditions. This vulnerability affects HTTP/2 Server users on Node.js v18.x, v20.x, v22.x and v23.x.
CVE-2025-23084
A vulnerability has been identified in Node.js, specifically affecting the handling of drive names in the Windows environment. Certain Node.js functions do not treat drive names as special on Windows. As a result, although Node.js assumes a relative path, it actually refers to the root directory. On Windows, a path that does not start with the file separator is treated as relative to the current directory. This vulnerability affects Windows users of `path.join` API.
CVE-2025-23083
With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an instance of them can be fetched, and its constructor can be grabbed and reinstated for malicious usage. This vulnerability affects Permission Model users (--permission) on Node.js v20, v22, and v23.
CVE-2025-23048
Apache HTTP Server: mod_ssl access control bypass with session resumption
CVE-2025-23016
FastCGI fcgi2 (aka fcgi) 2.x through 2.4.4 has an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.
CVE-2025-2296
Un-verified kernel bypass Secure Boot mechanism in direct boot mode
CVE-2025-2295
Potential iSCSI R2T PDU Vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2025-23140 misc: pci_endpoint_test: Avoid issue of interrupts remaining after request_irq error | CVSS3: 5.5 | 0% Низкий | 6 месяцев назад | |
CVE-2025-23136 thermal: int340x: Add NULL check for adev | CVSS3: 5.5 | 0% Низкий | 6 дней назад | |
CVE-2025-23135 RISC-V: KVM: Teardown riscv specific bits after kvm_exit | 0% Низкий | 10 месяцев назад | ||
CVE-2025-23133 wifi: ath11k: update channel list in reg notifier instead reg worker | 0% Низкий | 6 месяцев назад | ||
CVE-2025-23132 f2fs: quota: fix to avoid warning in dquot_writeback_dquots() | 0% Низкий | 12 месяцев назад | ||
CVE-2025-23131 dlm: prevent NPD when writing a positive value to event_done | CVSS3: 5.5 | 0% Низкий | 12 месяцев назад | |
CVE-2025-23130 f2fs: fix to avoid panic once fallocation fails for pinfile | 0% Низкий | 12 месяцев назад | ||
CVE-2025-2312 cifs.upcall makes an upcall to the wrong namespace in containerized environments | CVSS3: 5.9 | 0% Низкий | 6 месяцев назад | |
CVE-2025-23129 wifi: ath11k: Clear affinity hint before calling ath11k_pcic_free_irq() in error path | 0% Низкий | 10 месяцев назад | ||
CVE-2025-2310 HDF5 Metadata Attribute Decoder H5MM_strndup heap-based overflow | CVSS3: 5.3 | 0% Низкий | 12 месяцев назад | |
CVE-2025-2309 HDF5 Type Conversion Logic H5T__bit_copy heap-based overflow | 0% Низкий | 12 месяцев назад | ||
CVE-2025-23090 Rejected reason: This CVE record has been withdrawn due to a duplicate entry CVE-2025-23083. | 6 месяцев назад | |||
CVE-2025-2308 HDF5 Scale-Offset Filter H5Z__scaleoffset_decompress_one_byte heap-based overflow | 0% Низкий | 9 месяцев назад | ||
CVE-2025-23085 A memory leak could occur when a remote peer abruptly closes the socket without sending a GOAWAY notification. Additionally, if an invalid header was detected by nghttp2, causing the connection to be terminated by the peer, the same leak was triggered. This flaw could lead to increased memory consumption and potential denial of service under certain conditions. This vulnerability affects HTTP/2 Server users on Node.js v18.x, v20.x, v22.x and v23.x. | CVSS3: 5.3 | 1% Низкий | 6 месяцев назад | |
CVE-2025-23084 A vulnerability has been identified in Node.js, specifically affecting the handling of drive names in the Windows environment. Certain Node.js functions do not treat drive names as special on Windows. As a result, although Node.js assumes a relative path, it actually refers to the root directory. On Windows, a path that does not start with the file separator is treated as relative to the current directory. This vulnerability affects Windows users of `path.join` API. | 1% Низкий | 12 месяцев назад | ||
CVE-2025-23083 With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an instance of them can be fetched, and its constructor can be grabbed and reinstated for malicious usage. This vulnerability affects Permission Model users (--permission) on Node.js v20, v22, and v23. | CVSS3: 7.7 | 0% Низкий | больше 1 года назад | |
CVE-2025-23048 Apache HTTP Server: mod_ssl access control bypass with session resumption | CVSS3: 9.1 | 1% Низкий | около 1 года назад | |
CVE-2025-23016 FastCGI fcgi2 (aka fcgi) 2.x through 2.4.4 has an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c. | CVSS3: 9.3 | 1% Низкий | больше 1 года назад | |
CVE-2025-2296 Un-verified kernel bypass Secure Boot mechanism in direct boot mode | CVSS3: 8.2 | 1% Низкий | 8 месяцев назад | |
CVE-2025-2295 Potential iSCSI R2T PDU Vulnerability | CVSS3: 3.5 | 0% Низкий | 8 месяцев назад |
Уязвимостей на страницу