| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-49436 | Cri | 0.64 | 9.8 | 0.02 | Dec 7, 2023 | Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /goform/SetNetControlList. | ||
| CVE-2023-49435 | Cri | 0.64 | 9.8 | 0.02 | Dec 7, 2023 | Tenda AX9 V22.03.01.46 is vulnerable to command injection. | ||
| CVE-2023-49434 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2023 | Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetNetControlList. | ||
| CVE-2023-49433 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2023 | Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetVirtualServerCfg. | ||
| CVE-2023-49432 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2023 | Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'deviceList' parameter at /goform/setMacFilterCfg. | ||
| CVE-2023-49431 | Cri | 0.64 | 9.8 | 0.02 | Dec 7, 2023 | Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName. | ||
| CVE-2023-49430 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2023 | Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetStaticRouteCfg. | ||
| CVE-2023-49429 | Cri | 0.64 | 9.8 | 0.02 | Dec 7, 2023 | Tenda AX9 V22.03.01.46 was discovered to contain a SQL command injection vulnerability in the 'setDeviceInfo' feature through the 'mac' parameter at /goform/setModules. | ||
| CVE-2023-49437 | Cri | 0.64 | 9.8 | 0.02 | Dec 7, 2023 | Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /goform/SetNetControlList. | ||
| CVE-2023-49428 | Cri | 0.64 | 9.8 | 0.03 | Dec 7, 2023 | Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName. | ||
| CVE-2023-49426 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2023 | Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the list parameter at /goform/SetStaticRouteCfg. | ||
| CVE-2023-49425 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2023 | Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the deviceList parameter at /goform/setMacFilterCfg . | ||
| CVE-2023-39169 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2023 | The affected devices use publicly available default credentials with administrative privileges. | ||
| CVE-2023-49424 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2023 | Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg. | ||
| CVE-2023-39172 | Cri | 0.59 | 9.1 | 0.01 | Dec 7, 2023 | The affected devices transmit sensitive information unencrypted allowing a remote unauthenticated attacker to capture and modify network traffic. | ||
| CVE-2023-35039 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2023 | Improper Restriction of Excessive Authentication Attempts vulnerability in Be Devious Web Development Password Reset with Code for WordPress REST API allows Authentication Abuse.This issue affects Password Reset with Code for WordPress REST API: from n/a through 0.0.15. | ||
| CVE-2023-50164 | Cri | 0.63 | 9.8 | 0.81 | Dec 7, 2023 | An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. Users are recommended to upgrade to versions Struts 2.5.33 or Struts 6.3.0.2 or… | ||
| CVE-2023-48860 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2023 | TOTOLINK N300RT version 3.2.4-B20180730.0906 has a post-authentication RCE due to incorrect access control, allows attackers can bypass front-end security restrictions and execute arbitrary code. | ||
| CVE-2023-48823 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2023 | A Blind SQL injection issue in ajax.php in GaatiTrack Courier Management System 1.0 allows an unauthenticated attacker to inject a payload via the email parameter during login. | ||
| CVE-2023-41913 | Cri | 0.64 | 9.8 | 0.02 | Dec 7, 2023 | strongSwan before 5.9.12 has a buffer overflow and possible unauthenticated remote code execution via a DH public value that exceeds the internal buffer in charon-tkm's DH proxy. The earliest affected version is 5.3.0. An attack can occur via a crafted IKE_SA_INIT message. | ||
| CVE-2023-5761 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2023 | The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'url' parameter in versions 1.4.0 to 1.4.6.1 (free) and versions 1.4.0 to 1.5.0 (pro) due to insufficient escaping on the user supplied parameter and… | ||
| CVE-2023-46353 | Cri | 0.64 | 9.8 | 0.01 | Dec 6, 2023 | In the module "Product Tag Icons Pro" (ticons) before 1.8.4 from MyPresta.eu for PrestaShop, a guest can perform SQL injection. The method TiconProduct::getTiconByProductAndTicon() has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL… | ||
| CVE-2023-36655 | Cri | 0.64 | 9.8 | 0.01 | Dec 6, 2023 | The login REST API in ProLion CryptoSpike 3.0.15P2 (when LDAP or Active Directory is used as the users store) allows a remote blocked user to login and obtain an authentication token by specifying a username with different uppercase/lowercase character combination. | ||
| CVE-2023-46773 | Cri | 0.64 | 9.8 | 0.01 | Dec 6, 2023 | Permission management vulnerability in the PMS module. Successful exploitation of this vulnerability may cause privilege escalation. | ||
| CVE-2023-48849 | Cri | 0.64 | 9.8 | 0.01 | Dec 6, 2023 | Ruijie EG Series Routers version EG_3.0(1)B11P216 and before allows unauthenticated attackers to remotely execute arbitrary code due to incorrect filtering. | ||
| CVE-2023-22524 | Cri | 0.66 | 9.8 | 0.25 | Dec 6, 2023 | Certain versions of the Atlassian Companion App for MacOS were affected by a remote code execution vulnerability. An attacker could utilize WebSockets to bypass Atlassian Companion’s blocklist and MacOS Gatekeeper to allow execution of code. | ||
| CVE-2023-48930 | Cri | 0.64 | 9.8 | 0.01 | Dec 6, 2023 | xinhu xinhuoa 2.2.1 contains a File upload vulnerability. | ||
| CVE-2023-6448 | Cri | 0.76 | 9.8 | 0.02 | KEV | Dec 5, 2023 | Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative password. An unauthenticated attacker with network access can take administrative control of a vulnerable system. | |
| CVE-2023-6269 | Cri | 0.65 | 10.0 | 0.02 | Dec 5, 2023 | An argument injection vulnerability has been identified in the administrative web interface of the Atos Unify OpenScape products "Session Border Controller" (SBC) and "Branch", before version V10 R3.4.0, and OpenScape "BCF" before versions V10R10.12.00 and V10R11.05.02. This… | ||
| CVE-2023-49070 | Cri | 0.74 | 9.8 | 0.95 | Dec 5, 2023 | Pre-auth RCE in Apache Ofbiz 18.12.09. It's due to XML-RPC no longer maintained still present. This issue affects Apache OFBiz: before 18.12.10. Users are recommended to upgrade to version 18.12.10 | ||
| CVE-2023-33083 | Cri | 0.64 | 9.8 | 0.01 | Dec 5, 2023 | Memory corruption in WLAN Host while processing RRM beacon on the AP. | ||
| CVE-2023-33082 | Cri | 0.64 | 9.8 | 0.01 | Dec 5, 2023 | Memory corruption while sending an Assoc Request having BTM Query or BTM Response containing MBO IE. | ||
| CVE-2023-33054 | Cri | 0.59 | 9.1 | 0.00 | Dec 5, 2023 | Cryptographic issue in GPS HLOS Driver while downloading Qualcomm GNSS assistance data. | ||
| CVE-2023-48692 | Cri | 0.59 | 9.0 | 0.03 | Dec 5, 2023 | Azure RTOS NetX Duo is a TCP/IP network stack designed specifically for deeply embedded real-time and IoT applications. An attacker can cause remote code execution due to memory overflow vulnerabilities in Azure RTOS NETX Duo. The affected components include processes/functions… | ||
| CVE-2023-48316 | Cri | 0.64 | 9.8 | 0.04 | Dec 5, 2023 | Azure RTOS NetX Duo is a TCP/IP network stack designed specifically for deeply embedded real-time and IoT applications. An attacker can cause remote code execution due to memory overflow vulnerabilities in Azure RTOS NETX Duo. The affected components include processes/functions… | ||
| CVE-2023-49291 | Cri | 0.54 | 9.3 | 0.01 | Dec 5, 2023 | tj-actions/branch-names is a Github action to retrieve branch or tag names with support for all events. The `tj-actions/branch-names` GitHub Actions improperly references the `github.event.pull_request.head.ref` and `github.head_ref` context variables within a GitHub Actions… | ||
| CVE-2023-40082 | Cri | 0.64 | 9.8 | 0.01 | Dec 4, 2023 | In modify_for_next_stage of fdt.rs, there is a possible way to render KASLR ineffective due to improperly used crypto. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-40078 | Cri | 0.64 | 9.8 | 0.01 | Dec 4, 2023 | In a2dp_vendor_opus_decoder_decode_packet of a2dp_vendor_opus_decoder.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to paired device escalation of privilege with no additional execution privileges needed. User interaction is not… | ||
| CVE-2023-35690 | Cri | 0.64 | 9.8 | 0.00 | Dec 4, 2023 | In RGXDestroyHWRTData of rgxta3d.c, there is a possible arbitrary code execution due to an uncaught exception. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-24052 | Cri | 0.64 | 9.8 | 0.01 | Dec 4, 2023 | An issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain control of the device via the change password functionality as it does not prompt for the current password. | ||
| CVE-2023-24051 | Cri | 0.64 | 9.8 | 0.01 | Dec 4, 2023 | A client side rate limit issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges via brute force style attacks. | ||
| CVE-2023-24049 | Cri | 0.64 | 9.8 | 0.01 | Dec 4, 2023 | An issue was discovered on Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges on the device via poor credential management. | ||
| CVE-2023-21403 | Cri | 0.64 | 9.8 | 0.00 | Dec 4, 2023 | In RGXDestroyZSBufferKM of rgxta3d.c, there is a possible arbitrary code execution due to an uncaught exception. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-21402 | Cri | 0.64 | 9.8 | 0.00 | Dec 4, 2023 | In MMU_UnmapPages of mmu_common.c, there is a possible out of bounds read due to improper input validation. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-21401 | Cri | 0.64 | 9.8 | 0.00 | Dec 4, 2023 | In DevmemIntChangeSparse of devicemem_server.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-21263 | Cri | 0.64 | 9.8 | 0.00 | Dec 4, 2023 | In OSMMapPMRGeneric of pmr_os.c, there is a possible out of bounds write due to an uncaught exception. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-21228 | Cri | 0.64 | 9.8 | 0.00 | Dec 4, 2023 | In PMRChangeSparseMemOSMem of physmem_osmem_linux.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2023-21218 | Cri | 0.64 | 9.8 | 0.00 | Dec 4, 2023 | In PMRChangeSparseMemOSMem of physmem_osmem_linux.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2023-21217 | Cri | 0.64 | 9.8 | 0.00 | Dec 4, 2023 | In PMRWritePMPageList of TBD, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-21216 | Cri | 0.64 | 9.8 | 0.00 | Dec 4, 2023 | In PMRChangeSparseMemOSMem of physmem_osmem_linux.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for… |
- risk 0.64cvss 9.8epss 0.02
Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /goform/SetNetControlList.
- risk 0.64cvss 9.8epss 0.02
Tenda AX9 V22.03.01.46 is vulnerable to command injection.
- risk 0.64cvss 9.8epss 0.01
Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetNetControlList.
- risk 0.64cvss 9.8epss 0.01
Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetVirtualServerCfg.
- risk 0.64cvss 9.8epss 0.01
Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'deviceList' parameter at /goform/setMacFilterCfg.
- risk 0.64cvss 9.8epss 0.02
Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName.
- risk 0.64cvss 9.8epss 0.01
Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetStaticRouteCfg.
- risk 0.64cvss 9.8epss 0.02
Tenda AX9 V22.03.01.46 was discovered to contain a SQL command injection vulnerability in the 'setDeviceInfo' feature through the 'mac' parameter at /goform/setModules.
- risk 0.64cvss 9.8epss 0.02
Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /goform/SetNetControlList.
- risk 0.64cvss 9.8epss 0.03
Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName.
- risk 0.64cvss 9.8epss 0.01
Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the list parameter at /goform/SetStaticRouteCfg.
- risk 0.64cvss 9.8epss 0.01
Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the deviceList parameter at /goform/setMacFilterCfg .
- risk 0.64cvss 9.8epss 0.01
The affected devices use publicly available default credentials with administrative privileges.
- risk 0.64cvss 9.8epss 0.01
Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg.
- risk 0.59cvss 9.1epss 0.01
The affected devices transmit sensitive information unencrypted allowing a remote unauthenticated attacker to capture and modify network traffic.
- risk 0.64cvss 9.8epss 0.01
Improper Restriction of Excessive Authentication Attempts vulnerability in Be Devious Web Development Password Reset with Code for WordPress REST API allows Authentication Abuse.This issue affects Password Reset with Code for WordPress REST API: from n/a through 0.0.15.
- risk 0.63cvss 9.8epss 0.81
An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. Users are recommended to upgrade to versions Struts 2.5.33 or Struts 6.3.0.2 or…
- risk 0.64cvss 9.8epss 0.01
TOTOLINK N300RT version 3.2.4-B20180730.0906 has a post-authentication RCE due to incorrect access control, allows attackers can bypass front-end security restrictions and execute arbitrary code.
- risk 0.64cvss 9.8epss 0.01
A Blind SQL injection issue in ajax.php in GaatiTrack Courier Management System 1.0 allows an unauthenticated attacker to inject a payload via the email parameter during login.
- risk 0.64cvss 9.8epss 0.02
strongSwan before 5.9.12 has a buffer overflow and possible unauthenticated remote code execution via a DH public value that exceeds the internal buffer in charon-tkm's DH proxy. The earliest affected version is 5.3.0. An attack can occur via a crafted IKE_SA_INIT message.
- risk 0.64cvss 9.8epss 0.01
The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'url' parameter in versions 1.4.0 to 1.4.6.1 (free) and versions 1.4.0 to 1.5.0 (pro) due to insufficient escaping on the user supplied parameter and…
- risk 0.64cvss 9.8epss 0.01
In the module "Product Tag Icons Pro" (ticons) before 1.8.4 from MyPresta.eu for PrestaShop, a guest can perform SQL injection. The method TiconProduct::getTiconByProductAndTicon() has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL…
- risk 0.64cvss 9.8epss 0.01
The login REST API in ProLion CryptoSpike 3.0.15P2 (when LDAP or Active Directory is used as the users store) allows a remote blocked user to login and obtain an authentication token by specifying a username with different uppercase/lowercase character combination.
- risk 0.64cvss 9.8epss 0.01
Permission management vulnerability in the PMS module. Successful exploitation of this vulnerability may cause privilege escalation.
- risk 0.64cvss 9.8epss 0.01
Ruijie EG Series Routers version EG_3.0(1)B11P216 and before allows unauthenticated attackers to remotely execute arbitrary code due to incorrect filtering.
- risk 0.66cvss 9.8epss 0.25
Certain versions of the Atlassian Companion App for MacOS were affected by a remote code execution vulnerability. An attacker could utilize WebSockets to bypass Atlassian Companion’s blocklist and MacOS Gatekeeper to allow execution of code.
- risk 0.64cvss 9.8epss 0.01
xinhu xinhuoa 2.2.1 contains a File upload vulnerability.
- risk 0.76cvss 9.8epss 0.02
Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative password. An unauthenticated attacker with network access can take administrative control of a vulnerable system.
- risk 0.65cvss 10.0epss 0.02
An argument injection vulnerability has been identified in the administrative web interface of the Atos Unify OpenScape products "Session Border Controller" (SBC) and "Branch", before version V10 R3.4.0, and OpenScape "BCF" before versions V10R10.12.00 and V10R11.05.02. This…
- risk 0.74cvss 9.8epss 0.95
Pre-auth RCE in Apache Ofbiz 18.12.09. It's due to XML-RPC no longer maintained still present. This issue affects Apache OFBiz: before 18.12.10. Users are recommended to upgrade to version 18.12.10
- risk 0.64cvss 9.8epss 0.01
Memory corruption in WLAN Host while processing RRM beacon on the AP.
- risk 0.64cvss 9.8epss 0.01
Memory corruption while sending an Assoc Request having BTM Query or BTM Response containing MBO IE.
- risk 0.59cvss 9.1epss 0.00
Cryptographic issue in GPS HLOS Driver while downloading Qualcomm GNSS assistance data.
- risk 0.59cvss 9.0epss 0.03
Azure RTOS NetX Duo is a TCP/IP network stack designed specifically for deeply embedded real-time and IoT applications. An attacker can cause remote code execution due to memory overflow vulnerabilities in Azure RTOS NETX Duo. The affected components include processes/functions…
- risk 0.64cvss 9.8epss 0.04
Azure RTOS NetX Duo is a TCP/IP network stack designed specifically for deeply embedded real-time and IoT applications. An attacker can cause remote code execution due to memory overflow vulnerabilities in Azure RTOS NETX Duo. The affected components include processes/functions…
- risk 0.54cvss 9.3epss 0.01
tj-actions/branch-names is a Github action to retrieve branch or tag names with support for all events. The `tj-actions/branch-names` GitHub Actions improperly references the `github.event.pull_request.head.ref` and `github.head_ref` context variables within a GitHub Actions…
- risk 0.64cvss 9.8epss 0.01
In modify_for_next_stage of fdt.rs, there is a possible way to render KASLR ineffective due to improperly used crypto. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.64cvss 9.8epss 0.01
In a2dp_vendor_opus_decoder_decode_packet of a2dp_vendor_opus_decoder.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to paired device escalation of privilege with no additional execution privileges needed. User interaction is not…
- risk 0.64cvss 9.8epss 0.00
In RGXDestroyHWRTData of rgxta3d.c, there is a possible arbitrary code execution due to an uncaught exception. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.64cvss 9.8epss 0.01
An issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain control of the device via the change password functionality as it does not prompt for the current password.
- risk 0.64cvss 9.8epss 0.01
A client side rate limit issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges via brute force style attacks.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered on Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges on the device via poor credential management.
- risk 0.64cvss 9.8epss 0.00
In RGXDestroyZSBufferKM of rgxta3d.c, there is a possible arbitrary code execution due to an uncaught exception. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.64cvss 9.8epss 0.00
In MMU_UnmapPages of mmu_common.c, there is a possible out of bounds read due to improper input validation. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.64cvss 9.8epss 0.00
In DevmemIntChangeSparse of devicemem_server.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.64cvss 9.8epss 0.00
In OSMMapPMRGeneric of pmr_os.c, there is a possible out of bounds write due to an uncaught exception. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.64cvss 9.8epss 0.00
In PMRChangeSparseMemOSMem of physmem_osmem_linux.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for…
- risk 0.64cvss 9.8epss 0.00
In PMRChangeSparseMemOSMem of physmem_osmem_linux.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for…
- risk 0.64cvss 9.8epss 0.00
In PMRWritePMPageList of TBD, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.64cvss 9.8epss 0.00
In PMRChangeSparseMemOSMem of physmem_osmem_linux.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for…