Latest CVE Feed
-
5.5
MEDIUMCVE-2024-57902
In the Linux kernel, the following vulnerability has been resolved: af_packet: fix vlan_get_tci() vs MSG_PEEK Blamed commit forgot MSG_PEEK case, allowing a crash [1] as found by syzbot. Rework vlan_get_tci() to not touch skb at all, so that it can be ... Read more
Affected Products : linux_kernel- Published: Jan. 15, 2025
- Modified: Jan. 15, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-38152
In the Linux kernel, the following vulnerability has been resolved: remoteproc: core: Clear table_sz when rproc_shutdown There is case as below could trigger kernel dump: Use U-Boot to start remote processor(rproc) with resource table published to a fix... Read more
Affected Products : linux_kernel- Published: Apr. 18, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-37893
In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Fix off-by-one error in build_prologue() Vincent reported that running BPF progs with tailcalls on LoongArch causes kernel hard lockup. Debugging the issues shows that t... Read more
Affected Products : linux_kernel- Published: Apr. 18, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-37805
In the Linux kernel, the following vulnerability has been resolved: sound/virtio: Fix cancel_sync warnings on uninitialized work_structs Betty reported hitting the following warning: [ 8.709131][ T221] WARNING: CPU: 2 PID: 221 at kernel/workqueue.c... Read more
Affected Products : linux_kernel- Published: May. 08, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Misconfiguration
-
5.5
MEDIUMCVE-2025-37800
In the Linux kernel, the following vulnerability has been resolved: driver core: fix potential NULL pointer dereference in dev_uevent() If userspace reads "uevent" device attribute at the same time as another threads unbinds the device from its driver, ... Read more
Affected Products : linux_kernel- Published: May. 08, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-37802
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix WARNING "do not call blocking ops when !TASK_RUNNING" wait_event_timeout() will set the state of the current task to TASK_UNINTERRUPTIBLE, before doing the condition check. T... Read more
Affected Products : linux_kernel- Published: May. 08, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Denial of Service
-
5.5
MEDIUMCVE-2025-37801
In the Linux kernel, the following vulnerability has been resolved: spi: spi-imx: Add check for spi_imx_setupxfer() Add check for the return value of spi_imx_setupxfer(). spi_imx->rx and spi_imx->tx function pointer can be NULL when spi_imx_setupxfer() ... Read more
Affected Products : linux_kernel- Published: May. 08, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-33060
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.... Read more
Affected Products : windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 windows_10_1507 +6 more products- Published: Jun. 10, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-33065
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.... Read more
Affected Products : windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 windows_10_1507 windows_11_23h2 +4 more products- Published: Jun. 10, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-33052
Use of uninitialized resource in Windows DWM Core Library allows an authorized attacker to disclose information locally.... Read more
Affected Products : windows_server_2019 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 windows_11_23h2 windows_server_2022_23h2 windows_server_23h2 windows_11_24h2 +1 more products- Published: Jun. 10, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-32719
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.... Read more
Affected Products : windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 windows_10_1507 windows_11_23h2 +4 more products- Published: Jun. 10, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2022-48391
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.... Read more
- Published: Jun. 06, 2023
- Modified: Jan. 08, 2025
-
5.5
MEDIUMCVE-2025-32720
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.... Read more
Affected Products : windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 windows_10_1507 +6 more products- Published: Jun. 10, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-31727
Jenkins AsakusaSatellite Plugin 0.1.1 and earlier stores AsakusaSatellite API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file ... Read more
Affected Products : asakusasatellite- Published: Apr. 02, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Misconfiguration
-
5.5
MEDIUMCVE-2025-31726
Jenkins Stack Hammer Plugin 1.0.6 and earlier stores Stack Hammer API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.... Read more
Affected Products : stack_hammer- Published: Apr. 02, 2025
- Modified: Apr. 18, 2025
- Vuln Type: Misconfiguration
-
5.5
MEDIUMCVE-2025-31260
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.5. An app may be able to access sensitive user data.... Read more
Affected Products : macos- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2025-31245
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.7.6, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, macOS Ventura 13.7.6. An app may be able to cause unexpected system termination... Read more
- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Denial of Service
-
5.5
MEDIUMCVE-2025-31256
The issue was addressed with improved handling of caches. This issue is fixed in macOS Sequoia 15.5. Hot corner may unexpectedly reveal a user’s deleted notes.... Read more
Affected Products : macos- Published: May. 12, 2025
- Modified: May. 27, 2025
-
5.5
MEDIUMCVE-2025-31261
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access protected user data.... Read more
Affected Products : macos- Published: May. 29, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2025-31251
The issue was addressed with improved input sanitization. This issue is fixed in watchOS 11.5, macOS Sonoma 14.7.6, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, macOS Ventura 13.7.6. Processing a maliciously crafte... Read more
- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Memory Corruption