A vulnerability classified as problematic was found in GitLab Enterprise Edition up to 17.11.5/18.0.3/18.1.1. This vulnerability affects unknown code of the component API Request Handler. The manipulation leads to incorrect authorization.
This vulnerability was named CVE-2025-3396. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical has been found in Mitsubishi Electric PV-DR004J and PV-DR004JA. This affects an unknown part. The manipulation leads to hard-coded credentials. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is uniquely identified as CVE-2025-5023. The attack needs to be initiated within the local network. There is no exploit available.
A vulnerability was found in Mitsubishi Electric PV-DR004J and PV-DR004JA. It has been rated as critical. Affected by this issue is some unknown functionality of the component Communication Handler. The manipulation leads to weak password requirements. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is handled as CVE-2025-5022. The attack needs to be done within the local network. There is no exploit available.
A vulnerability was found in Linux Kernel up to 6.16-rc2. It has been declared as problematic. Affected by this vulnerability is the function regs_get_kernel_stack_nth. The manipulation leads to out-of-bounds read.
This vulnerability is known as CVE-2025-38320. It is possible to launch the attack on the physical device. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.15.3. It has been classified as critical. Affected is the function memcpy of the component scsi. The manipulation leads to buffer overflow.
This vulnerability is traded as CVE-2025-38332. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.15.3 and classified as critical. This issue affects the function jffs2_prealloc_raw_node_refs of the component jffs2. The manipulation leads to null pointer dereference.
The identification of this vulnerability is CVE-2025-38328. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in Linux Kernel up to 6.12.34/6.15.3/6.16-rc2/e59796fc80603bcd8569d4d2e10b213c1918edb4 and classified as problematic. This vulnerability affects the function free_transport of the component ksmbd. The manipulation leads to privilege escalation.
This vulnerability was named CVE-2025-38325. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, was found in Linux Kernel up to 6.6.94/6.12.34/6.15.3/6.16-rc2. This affects the function close_all_cached_dirs of the component smb. The manipulation leads to allocation of resources.
This vulnerability is uniquely identified as CVE-2025-38321. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.15.3. Affected by this issue is the function cs_dsp_ctl_cache_init_multiple_offsets of the component firmware. The manipulation leads to allocation of resources.
This vulnerability is handled as CVE-2025-38330. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical was found in Linux Kernel up to 6.15.3. Affected by this vulnerability is the function cs_dsp_mock_wmfw_add_info. The manipulation leads to allocation of resources.
This vulnerability is known as CVE-2025-38329. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical has been found in Linux Kernel up to 6.16-rc2. Affected is the function aoedev_downdev of the component aoe. The manipulation leads to denial of service.
This vulnerability is traded as CVE-2025-38326. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.