50 points luispa 1 hour ago 25 comments
modeless 1 hour ago | parent
thallium205 50 minutes ago | parent
wjholden 45 minutes ago | parent
vdfs 6 minutes ago | parent
slopinthebag 30 minutes ago | parent
one again illustrating the importance of encapsulating unsafe behavior. perhaps c should get a __UNSAFE { } block, where memory access is encapsulated and thus most bugs occurring outside of those blocks do not need to be marked as CVEs.
akersten 25 minutes ago | parent
I think the convention for this is at the filesystem level and most programmers use the `.c` suffix to indicate it
slopinthebag 8 minutes ago | parent
perhaps we could call it a sedimentchest?
seba_dos1 14 minutes ago | parent
DominoTree 46 minutes ago | parent
tetrisgm 31 minutes ago | parent
SchemaLoad 23 minutes ago | parent
sva_ 25 minutes ago | parent
Apparently by late summer this year, there were already more vulnerabilities found than in all of 2025.
imoverclocked 24 minutes ago | parent
crtasm 20 minutes ago | parent
https://security-tracker.debian.org/tracker/source-package/l...
imoverclocked 14 minutes ago | parent
Searching around, the best I have found so far for vanilla kernels is: https://linuxcvetracker.com
It does require a little clicking around to get all the info I want though. Time to pull out curl+awk! :)
embedding-shape 15 minutes ago | parent
Wonder how many of these NSA and others been sitting on, for how long and how many are still there? I guess the silver lining with the aixplosion of CVEs is that software eventually will get more secure.
SchemaLoad 7 minutes ago | parent
Now they just give almost every bug a CVE number.
vdfs 7 minutes ago | parent
jaimex2 12 minutes ago | parent
userbinator 9 minutes ago | parent
Remotely or locally exploitable? This is very lacking on information.
SchemaLoad 6 minutes ago | parent