Vulnerabilities (CVE)

Filtered by CWE-787
Total 6848 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-25698 1 Qualcomm 32 Sd429, Sd429 Firmware, Sd 8 Gen1 5g Firmware and 29 more 2025-04-22 N/A 8.4 HIGH
Memory corruption in SPI buses due to improper input validation while reading address configuration from spi buses in Snapdragon Mobile, Snapdragon Wearables
CVE-2022-25697 1 Qualcomm 32 Sd429, Sd429 Firmware, Sd 8 Gen1 5g Firmware and 29 more 2025-04-22 N/A 8.4 HIGH
Memory corruption in i2c buses due to improper input validation while reading address configuration from i2c driver in Snapdragon Mobile, Snapdragon Wearables
CVE-2022-45693 1 Jettison Project 1 Jettison 2025-04-22 N/A 7.5 HIGH
Jettison before v1.5.2 was discovered to contain a stack overflow via the map parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.
CVE-2022-45689 1 Hutool 1 Hutool 2025-04-22 N/A 7.5 HIGH
hutool-json v5.8.10 was discovered to contain an out of memory error.
CVE-2022-20469 1 Google 1 Android 2025-04-22 N/A 8.8 HIGH
In avct_lcb_msg_asmbl of avct_lcb_act.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-230867224
CVE-2024-49738 1 Google 1 Android 2025-04-22 N/A 7.8 HIGH
In writeInplace of Parcel.cpp, there is a possible out of bounds write. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-43096 1 Google 1 Android 2025-04-22 N/A 8.8 HIGH
In build_read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-49749 1 Google 1 Android 2025-04-22 N/A 8.8 HIGH
In DGifSlurp of dgif_lib.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-49745 1 Google 1 Android 2025-04-22 N/A 7.8 HIGH
In growData of Parcel.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2022-44898 1 Asus 1 Aura Sync 2025-04-22 N/A 7.8 HIGH
The MsIo64.sys component in Asus Aura Sync through v1.07.79 does not properly validate input to IOCTL 0x80102040, 0x80102044, 0x80102050, and 0x80102054, allowing attackers to trigger a memory corruption and cause a Denial of Service (DoS) or escalate privileges via crafted IOCTL requests.
CVE-2025-20632 1 Mediatek 8 Mt7615, Mt7622, Mt7663 and 5 more 2025-04-22 N/A 7.8 HIGH
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00397139; Issue ID: MSV-2188.
CVE-2025-20631 1 Mediatek 8 Mt7615, Mt7622, Mt7663 and 5 more 2025-04-22 N/A 7.8 HIGH
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00397141; Issue ID: MSV-2187.
CVE-2024-20146 4 Google, Linuxfoundation, Mediatek and 1 more 30 Android, Yocto, Mt2737 and 27 more 2025-04-22 N/A 8.1 HIGH
In wlan STA driver, there is a possible out of bounds write due to improper input validation. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00389496 / ALPS09137491; Issue ID: MSV-1835.
CVE-2025-20645 2 Google, Mediatek 15 Android, Mt6765, Mt6768 and 12 more 2025-04-22 N/A 7.8 HIGH
In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09475476; Issue ID: MSV-2599.
CVE-2022-45685 1 Jettison Project 1 Jettison 2025-04-22 N/A 7.5 HIGH
A stack overflow in Jettison before v1.5.2 allows attackers to cause a Denial of Service (DoS) via crafted JSON data.
CVE-2022-45688 2 Hutool, Json-java Project 2 Hutool, Json-java 2025-04-22 N/A 7.5 HIGH
A stack overflow in the XML.toJSONObject component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data.
CVE-2022-44910 1 Quarkslab 1 Binbloom 2025-04-22 N/A 7.8 HIGH
Binbloom 2.0 was discovered to contain a heap buffer overflow via the read_pointer function at /binbloom-master/src/helpers.c.
CVE-2022-42820 1 Apple 3 Ipados, Iphone Os, Macos 2025-04-21 N/A 7.8 HIGH
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 16.1 and iPadOS 16, macOS Ventura 13. An app may cause unexpected app termination or arbitrary code execution.
CVE-2022-32860 1 Apple 3 Ipados, Iphone Os, Macos 2025-04-21 N/A 7.8 HIGH
An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, macOS Big Sur 11.6.8. An app may be able to execute arbitrary code with kernel privileges.
CVE-2022-42840 1 Apple 3 Ipados, Iphone Os, Macos 2025-04-21 N/A 7.8 HIGH
The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2. An app may be able to execute arbitrary code with kernel privileges.