VYPR

CVEs

105,912 total · page 1118 of 2,119

  • CVE-2022-25673HigDec 13, 2022
    risk 0.49cvss 7.5epss 0.00

    Denial of service in MODEM due to reachable assertion while processing configuration from network in Snapdragon Mobile

  • CVE-2022-25672HigDec 13, 2022
    risk 0.49cvss 7.5epss 0.00

    Denial of service in MODEM due to reachable assertion while processing SIB1 with invalid Bandwidth in Snapdragon Mobile

  • CVE-2022-20611HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    In deletePackageVersionedInternal of DeletePackageHelper.java, there is a possible way to bypass carrier restrictions due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20501HigDec 13, 2022
    risk 0.47cvss 7.3epss 0.00

    In onCreate of EnableAccountPreferenceActivity.java, there is a possible way to mislead the user into enabling a malicious phone account due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction…

  • CVE-2022-20495HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    In getEnabledAccessibilityServiceList of AccessibilityManager.java, there is a possible way to hide an accessibility service due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…

  • CVE-2022-20491HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20488HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20487HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20486HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20485HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20484HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20483HigDec 13, 2022
    risk 0.49cvss 7.5epss 0.01

    In several functions that parse avrc response in avrc_pars_ct.cc and related files, there are possible out of bounds reads due to integer overflows. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed…

  • CVE-2022-20480HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20479HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20478HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20477HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    In shouldHideNotification of KeyguardNotificationVisibilityProvider.kt, there is a possible way to show hidden notifications due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…

  • CVE-2022-20475HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    In test of ResetTargetTaskHelper.java, there is a possible hijacking of any app which sets allowTaskReparenting="true" due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20474HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    In readLazyValue of Parcel.java, there is a possible loading of arbitrary code into the System Settings app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20470HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    In bindRemoteViewsService of AppWidgetServiceImpl.java, there is a possible way to bypass background activity launch due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed…

  • CVE-2022-20469HigDec 13, 2022
    risk 0.57cvss 8.8epss 0.00

    In avct_lcb_msg_asmbl of avct_lcb_act.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege over Bluetooth with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20442HigDec 13, 2022
    risk 0.47cvss 7.3epss 0.00

    In onCreate of ReviewPermissionsActivity.java, there is a possible way to grant permissions for a separate app with API level < 23 due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is…

  • CVE-2022-20411HigDec 13, 2022
    risk 0.57cvss 8.8epss 0.02

    In avdt_msg_asmbl of avdt_msg.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-40365HigDec 13, 2022
    risk 0.49cvss 7.5epss 0.01

    Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device.

  • CVE-2021-39660HigDec 13, 2022
    risk 0.46cvss 7.0epss 0.00

    In TBD of TBD, there is a possible way to archive arbitrary code execution in kernel due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-46363HigDec 13, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in Apache CXF before versions 3.5.5 and 3.4.10 allows an attacker to perform a remote directory listing or code exfiltration. The vulnerability only applies when the CXFServlet is configured with both the static-resources-list and redirect-query-check…

  • CVE-2022-45693HigDec 13, 2022
    risk 0.49cvss 7.5epss 0.01

    Jettison before v1.5.2 was discovered to contain a stack overflow via the map parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.

  • CVE-2022-45690HigDec 13, 2022
    risk 0.42cvss 7.5epss 0.01

    A stack overflow in the org.json.JSONTokener.nextValue::JSONTokener.java component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data.

  • CVE-2022-45689HigDec 13, 2022
    risk 0.49cvss 7.5epss 0.01

    hutool-json v5.8.10 was discovered to contain an out of memory error.

  • CVE-2022-45688HigDec 13, 2022
    risk 0.42cvss 7.5epss 0.01

    A stack overflow in the XML.toJSONObject component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data.

  • CVE-2022-45685HigDec 13, 2022
    risk 0.49cvss 7.5epss 0.01

    A stack overflow in Jettison before v1.5.2 allows attackers to cause a Denial of Service (DoS) via crafted JSON data.

  • CVE-2022-29580HigDec 13, 2022
    risk 0.58cvss 8.9epss 0.00

    There exists a path traversal vulnerability in the Android Google Search app. This is caused by the incorrect usage of uri.getLastPathSegment. A symbolic encoded string can bypass the path logic to get access to unintended directories. An attacker can manipulate paths that could…

  • CVE-2021-32415HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    EXEMSI MSI Wrapper Versions prior to 10.0.50 and at least since version 6.0.91 will introduce a local privilege escalation vulnerability in installers it creates.

  • CVE-2022-4098HigDec 13, 2022
    risk 0.52cvss 8.0epss 0.00

    Multiple Wiesemann&Theis products of the ComServer Series are prone to an authentication bypass through IP spoofing. After a user logged in to the WBM of the Com-Server an unauthenticated attacker in the same subnet can obtain the session ID and through IP spoofing change…

  • CVE-2022-41268HigDec 13, 2022
    risk 0.55cvss 8.5epss 0.01

    In some SAP standard roles in SAP Business Planning and Consolidation - versions - SAP_BW 750, 751, 752, 753, 754, 755, 756, 757, DWCORE 200, 300, CPMBPC 810, a transaction code reserved for the customer is used. By implementing such transaction code, a malicious user may…

  • CVE-2022-41266HigDec 13, 2022
    risk 0.52cvss 8.0epss 0.00

    Due to a lack of proper input validation, SAP Commerce Webservices 2.0 (Swagger UI) - versions 1905, 2005, 2105, 2011, 2205, allows malicious inputs from untrusted sources, which can be leveraged by an attacker to execute a DOM Cross-Site Scripting (XSS) attack.  As a result,…

  • CVE-2022-41264HigDec 13, 2022
    risk 0.57cvss 8.8epss 0.01

    Due to the unrestricted scope of the RFC function module, SAP BASIS - versions 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, 791, allows an authenticated non-administrator attacker to access a system class and execute any of its public methods with parameters…

  • CVE-2022-45269HigDec 12, 2022
    risk 0.49cvss 7.5epss 0.03

    A directory traversal vulnerability in the component SCS.Web.Server.SPI/1.0 of Linx Sphere LINX 7.35.ST15 allows attackers to read arbitrary files.

  • CVE-2022-45275HigDec 12, 2022
    risk 0.48cvss 7.2epss 0.15

    An arbitrary file upload vulnerability in /queuing/admin/ajax.php?action=save_settings of Dynamic Transaction Queuing System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-42716HigDec 12, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in the Arm Mali GPU Kernel Driver. There is a use-after-free. A non-privileged user can make improper GPU processing operations to gain access to already freed memory. This affects Valhall r29p0 through r40P0.

  • CVE-2022-3999HigDec 12, 2022
    risk 0.53cvss 8.1epss 0.00

    The DPD Baltic Shipping WordPress plugin before 1.2.57 does not have authorisation and CSRF in an AJAX action, which could allow any authenticated users, such as subscriber to delete arbitrary options from the blog, which could make the blog unavailable.

  • CVE-2022-3989HigDec 12, 2022
    risk 0.57cvss 8.8epss 0.01

    The Motors WordPress plugin before 1.4.4 does not properly validate uploaded files for dangerous file types (such as .php) in an AJAX action, allowing an attacker to sign up on a victim's WordPress instance, upload a malicious PHP file and attempt to launch a brute-force attack…

  • CVE-2022-3981HigDec 12, 2022
    risk 0.57cvss 8.8epss 0.01

    The Icegram Express WordPress plugin before 5.5.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by any authenticated users, such as subscriber

  • CVE-2022-3925HigDec 12, 2022
    risk 0.47cvss 7.2epss 0.01

    The buddybadges WordPress plugin through 1.0.0 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users

  • CVE-2022-3912HigDec 12, 2022
    risk 0.49cvss 7.5epss 0.01

    The User Registration WordPress plugin before 2.2.4.1 does not properly restrict the files to be uploaded via an AJAX action available to both unauthenticated and authenticated users, which could allow unauthenticated users to upload PHP files for example.

  • CVE-2022-3605HigDec 12, 2022
    risk 0.51cvss 7.8epss 0.00

    The WP CSV Exporter WordPress plugin before 1.3.7 does not properly escape the fields when exporting data as CSV, leading to a CSV injection vulnerability.

  • CVE-2022-3359HigDec 12, 2022
    risk 0.57cvss 8.8epss 0.01

    The Shortcodes and extra features for Phlox theme WordPress plugin before 2.10.7 unserializes the content of an imported file, which could lead to PHP object injection when a user imports (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.

  • CVE-2022-45997HigDec 12, 2022
    risk 0.47cvss 7.2epss 0.01

    Tenda W20E V16.01.0.6(3392) is vulnerable to Buffer Overflow.

  • CVE-2022-45996HigDec 12, 2022
    risk 0.47cvss 7.2epss 0.02

    Tenda W20E V16.01.0.6(3392) is vulnerable to Command injection via cmd_get_ping_output.

  • CVE-2022-45980HigDec 12, 2022
    risk 0.58cvss 8.8epss 0.07

    Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via /goform/SysToolRestoreSet .

  • CVE-2022-45979HigDec 12, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AX12 v22.03.01.21_CN was discovered to contain a stack overflow via the ssid parameter at /goform/fast_setting_wifi_set .