VYPR

CVEs

112,915 total · page 1066 of 2,259

  • CVE-2023-45840HigDec 5, 2023
    risk 0.53cvss 8.1epss 0.01

    Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.This vulnerability is related…

  • CVE-2023-45839HigDec 5, 2023
    risk 0.53cvss 8.1epss 0.01

    Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.This vulnerability is related…

  • CVE-2023-45838HigDec 5, 2023
    risk 0.53cvss 8.1epss 0.01

    Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.This vulnerability is related…

  • CVE-2023-43608HigDec 5, 2023
    risk 0.53cvss 8.1epss 0.01

    A data integrity vulnerability exists in the BR_NO_CHECK_HASH_FOR functionality of Buildroot 2023.08.1 and dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.

  • CVE-2023-41835HigDec 5, 2023
    risk 0.42cvss 7.5epss 0.06

    When a Multipart request is performed but some of the fields exceed the maxStringLength  limit, the upload files will remain in struts.multipart.saveDir  even if the request has been denied. Users are recommended to upgrade to versions Struts 2.5.32 or 6.1.2.2 or Struts…

  • CVE-2023-5188HigDec 5, 2023
    risk 0.49cvss 7.5epss 0.01

    The MMS Interpreter of WagoAppRTU in versions below 1.4.6.0 which is used by the WAGO Telecontrol Configurator is vulnerable to malformed packets. An remote unauthenticated attacker could send specifically crafted packets that lead to a denial-of-service condition until restart…

  • CVE-2023-43472HigDec 5, 2023
    risk 0.52cvss 7.5epss 0.37

    An issue in MLFlow versions 2.8.1 and before allows a remote attacker to obtain sensitive information via a crafted request to REST API.

  • CVE-2023-44288HigDec 5, 2023
    risk 0.49cvss 7.5epss 0.01

    Dell PowerScale OneFS, 8.2.2.x through 9.6.0.x, contains an improper control of a resource through its lifetime vulnerability. An unauthenticated network attacker could potentially exploit this vulnerability, leading to denial of service.

  • CVE-2023-39248HigDec 5, 2023
    risk 0.49cvss 7.5epss 0.01

    Dell OS10 Networking Switches running 10.5.2.x and above contain an Uncontrolled Resource Consumption (Denial of Service) vulnerability, when switches are configured with VLT and VRRP. A remote unauthenticated user can cause the network to be flooded leading to Denial of…

  • CVE-2023-37572HigDec 5, 2023
    risk 0.49cvss 7.5epss 0.01

    Softing OPC Suite version 5.25 and before has Incorrect Access Control, allows attackers to obtain sensitive information via weak permissions in OSF_discovery service. The service executable could be changed or the service could be deleted.

  • CVE-2022-47531HigDec 5, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Ericsson Evolved Packet Gateway (EPG) versions 3.x before 3.25 and 2.x before 2.16, allows authenticated users to bypass system CLI and execute commands they are authorized to execute directly in the UNIX shell.

  • CVE-2023-47304HigDec 5, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Vonage Box Telephone Adapter VDV23 version VDV21-3.2.11-0.5.1, allows local attackers to bypass UART authentication controls and read/write arbitrary values to the memory of the device.

  • CVE-2023-42581HigDec 5, 2023
    risk 0.49cvss 7.5epss 0.01

    Improper URL validation from InstantPlay deeplink in Galaxy Store prior to version 4.5.64.4 allows attackers to execute JavaScript API to access data.

  • CVE-2023-42580HigDec 5, 2023
    risk 0.49cvss 7.5epss 0.01

    Improper URL validation from MCSLaunch deeplink in Galaxy Store prior to version 4.5.64.4 allows attackers to execute JavaScript API to install APK from Galaxy Store.

  • CVE-2023-42571HigDec 5, 2023
    risk 0.49cvss 7.6epss 0.00

    Abuse of remote unlock in Find My Mobile prior to version 7.3.13.4 allows physical attacker to unlock the device remotely by resetting the Samsung Account password with SMS verification when user lost the device.

  • CVE-2023-42568HigDec 5, 2023
    risk 0.47cvss 7.3epss 0.00

    Improper access control vulnerability in SmartManagerCN prior to SMR Dec-2023 Release 1 allows local attackers to access arbitrary files with system privilege.

  • CVE-2023-42567HigDec 5, 2023
    risk 0.47cvss 7.3epss 0.00

    Improper size check vulnerability in softsimd prior to SMR Dec-2023 Release 1 allows stack-based buffer overflow.

  • CVE-2023-42566HigDec 5, 2023
    risk 0.47cvss 7.3epss 0.00

    Out-of-bound write vulnerability in libsavsvc prior to SMR Dec-2023 Release 1 allows local attackers to execute arbitrary code.

  • CVE-2023-42565HigDec 5, 2023
    risk 0.47cvss 7.3epss 0.00

    Improper input validation vulnerability in Smart Clip prior to SMR Dec-2023 Release 1 allows local attackers with shell privilege to execute arbitrary code.

  • CVE-2023-42561HigDec 5, 2023
    risk 0.46cvss 7.1epss 0.00

    Heap out-of-bounds write vulnerability in bootloader prior to SMR Dec-2023 Release 1 allows a physical attacker to execute arbitrary code.

  • CVE-2023-42560HigDec 5, 2023
    risk 0.48cvss 7.4epss 0.00

    Heap out-of-bounds write vulnerability in dec_mono_audb of libsavsac.so prior to SMR Dec-2023 Release 1 allows an attacker to execute arbitrary code.

  • CVE-2023-33107HigKEVDec 5, 2023
    risk 0.67cvss 8.4epss 0.01

    Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.

  • CVE-2023-33106HigKEVDec 5, 2023
    risk 0.67cvss 8.4epss 0.01

    Memory corruption while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND.

  • CVE-2023-33098HigDec 5, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parsing WPA IES, when it is passed with length more than expected size.

  • CVE-2023-33097HigDec 5, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in WLAN Firmware while processing a FTMR frame.

  • CVE-2023-33092HigDec 5, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption while processing pin reply in Bluetooth, when pin code received from APP layer is greater than expected size.

  • CVE-2023-33089HigDec 5, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS when processing a NULL buffer while parsing WLAN vdev.

  • CVE-2023-33088HigDec 5, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption when processing cmd parameters while parsing vdev.

  • CVE-2023-33087HigDec 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in Core while processing RX intent request.

  • CVE-2023-33081HigDec 5, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while converting TWT (Target Wake Time) frame parameters in the OTA broadcast.

  • CVE-2023-33080HigDec 5, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame.

  • CVE-2023-33079HigDec 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in Audio while running invalid audio recording from ADSP.

  • CVE-2023-33071HigDec 5, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in Automotive OS whenever untrusted apps try to access HAb for graphics functionalities.

  • CVE-2023-33070HigDec 5, 2023
    risk 0.46cvss 7.1epss 0.00

    Transient DOS in Automotive OS due to improper authentication to the secure IO calls.

  • CVE-2023-33063HigKEVDec 5, 2023
    risk 0.63cvss 7.8epss 0.01

    Memory corruption in DSP Services during a remote call from HLOS to DSP.

  • CVE-2023-33053HigDec 5, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in Kernel while parsing metadata.

  • CVE-2023-33044HigDec 5, 2023
    risk 0.49cvss 7.5epss 0.01

    Transient DOS in Data modem while handling TLB control messages from the Network.

  • CVE-2023-33043HigDec 5, 2023
    risk 0.49cvss 7.5epss 0.01

    Transient DOS in Modem when a Beam switch request is made with a non-configured BWP.

  • CVE-2023-33042HigDec 5, 2023
    risk 0.49cvss 7.5epss 0.01

    Transient DOS in Modem after RRC Setup message is received.

  • CVE-2023-33041HigDec 5, 2023
    risk 0.49cvss 7.5epss 0.00

    Under certain scenarios the WLAN Firmware will reach an assertion due to state confusion while looking up peer ids.

  • CVE-2023-33022HigDec 5, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in HLOS while invoking IOCTL calls from user-space.

  • CVE-2023-33018HigDec 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while using the UIM diag command to get the operators name.

  • CVE-2023-33017HigDec 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in Boot while running a ListVars test in UEFI Menu during boot.

  • CVE-2023-28588HigDec 5, 2023
    risk 0.49cvss 7.5epss 0.01

    Transient DOS in Bluetooth Host while rfc slot allocation.

  • CVE-2023-28587HigDec 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in BT controller while parsing debug commands with specific sub-opcodes at HCI interface level.

  • CVE-2023-28585HigDec 5, 2023
    risk 0.53cvss 8.2epss 0.00

    Memory corruption while loading an ELF segment in TEE Kernel.

  • CVE-2023-28551HigDec 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in UTILS when modem processes memory specific Diag commands having arbitrary address values as input arguments.

  • CVE-2023-28550HigDec 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in MPP performance while accessing DSM watermark using external memory address.

  • CVE-2023-28546HigDec 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory Corruption in SPS Application while exporting public key in sorter TA.

  • CVE-2023-48695HigDec 5, 2023
    risk 0.48cvss 7.3epss 0.01

    Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. An attacker can cause remote code execution due to out of bounds write vulnerabilities in Azure RTOS USBX. The affected components include…