Total
12110 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2023-4232 | 2024-04-18 | N/A | 8.1 HIGH | ||
A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_status_report() function during the SMS decoding. It is assumed that the attack scenario is accessible from a compromised modem, a malicious base station, or just SMS. There is a bound check for this memcpy length in decode_submit(), but it was forgotten in decode_status_report(). | |||||
CVE-2023-4235 | 2024-04-18 | N/A | 8.1 HIGH | ||
A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_deliver_report() function during the SMS decoding. It is assumed that the attack scenario is accessible from a compromised modem, a malicious base station, or just SMS. There is a bound check for this memcpy length in decode_submit(), but it was forgotten in decode_deliver_report(). | |||||
CVE-2024-26599 | 1 Linux | 1 Linux Kernel | 2024-04-17 | N/A | 7.8 HIGH |
In the Linux kernel, the following vulnerability has been resolved: pwm: Fix out-of-bounds access in of_pwm_single_xlate() With args->args_count == 2 args->args[2] is not defined. Actually the flags are contained in args->args[1]. | |||||
CVE-2024-30253 | 2024-04-17 | N/A | 7.5 HIGH | ||
@solana/web3.js is the Solana JavaScript SDK. Using particular inputs with `@solana/web3.js` will result in memory exhaustion (OOM). If you have a server, client, mobile, or desktop product that accepts untrusted input for use with `@solana/web3.js`, your application/service may crash, resulting in a loss of availability. This vulnerability is fixed in 1.0.1, 1.10.2, 1.11.1, 1.12.1, 1.1.2, 1.13.1, 1.14.1, 1.15.1, 1.16.2, 1.17.1, 1.18.1, 1.19.1, 1.20.3, 1.21.1, 1.22.1, 1.23.1, 1.24.3, 1.25.1, 1.26.1, 1.27.1, 1.28.1, 1.2.8, 1.29.4, 1.30.3, 1.31.1, 1.3.1, 1.32.3, 1.33.1, 1.34.1, 1.35.2, 1.36.1, 1.37.3, 1.38.1, 1.39.2, 1.40.2, 1.41.11, 1.4.1, 1.42.1, 1.43.7, 1.44.4, 1.45.1, 1.46.1, 1.47.5, 1.48.1, 1.49.1, 1.50.2, 1.51.1, 1.5.1, 1.52.1, 1.53.1, 1.54.2, 1.55.1, 1.56.3, 1.57.1, 1.58.1, 1.59.2, 1.60.1, 1.61.2, 1.6.1, 1.62.2, 1.63.2, 1.64.1, 1.65.1, 1.66.6, 1.67.3, 1.68.2, 1.69.1, 1.70.4, 1.71.1, 1.72.1, 1.7.2, 1.73.5, 1.74.1, 1.75.1, 1.76.1, 1.77.4, 1.78.8, 1.79.1, 1.80.1, 1.81.1, 1.8.1, 1.82.1, 1.83.1, 1.84.1, 1.85.1, 1.86.1, 1.87.7, 1.88.1, 1.89.2, 1.90.2, 1.9.2, and 1.91.3. | |||||
CVE-2023-28581 | 1 Qualcomm | 52 Fastconnect 6800, Fastconnect 6800 Firmware, Fastconnect 6900 and 49 more | 2024-04-12 | N/A | 9.8 CRITICAL |
Memory corruption in WLAN Firmware while parsing receieved GTK Keys in GTK KDE. | |||||
CVE-2023-28549 | 1 Qualcomm | 450 315 5g Iot Modem, 315 5g Iot Modem Firmware, Aqt1000 and 447 more | 2024-04-12 | N/A | 7.8 HIGH |
Memory corruption in WLAN HAL while parsing Rx buffer in processing TLV payload. | |||||
CVE-2023-28545 | 1 Qualcomm | 408 315 5g Iot Modem, 315 5g Iot Modem Firmware, 9205 Lte Modem and 405 more | 2024-04-12 | N/A | 7.8 HIGH |
Memory corruption in TZ Secure OS while loading an app ELF. | |||||
CVE-2023-21663 | 1 Qualcomm | 76 Aqt1000, Aqt1000 Firmware, Qca6420 and 73 more | 2024-04-12 | N/A | 7.8 HIGH |
Memory Corruption while accessing metadata in Display. | |||||
CVE-2023-21654 | 1 Qualcomm | 112 Apq8096au, Apq8096au Firmware, Aqt1000 and 109 more | 2024-04-12 | N/A | 7.8 HIGH |
Memory corruption in Audio during playback session with audio effects enabled. | |||||
CVE-2023-21637 | 1 Qualcomm | 110 Aqt1000, Aqt1000 Firmware, Fastconnect 6200 and 107 more | 2024-04-12 | N/A | 7.8 HIGH |
Memory corruption in Linux while calling system configuration APIs. | |||||
CVE-2023-21633 | 1 Qualcomm | 194 Apq8064au, Apq8064au Firmware, Aqt1000 and 191 more | 2024-04-12 | N/A | 7.8 HIGH |
Memory Corruption in Linux while processing QcRilRequestImsRegisterMultiIdentityMessage request. | |||||
CVE-2023-21628 | 1 Qualcomm | 566 Apq8017, Apq8017 Firmware, Apq8064au and 563 more | 2024-04-12 | N/A | 7.8 HIGH |
Memory corruption in WLAN HAL while processing WMI-UTF command or FTM TLV1 command. | |||||
CVE-2022-40533 | 1 Qualcomm | 220 Csra6620, Csra6620 Firmware, Csra6640 and 217 more | 2024-04-12 | N/A | 5.5 MEDIUM |
Transient DOS due to untrusted Pointer Dereference in core while sending USB QMI request. | |||||
CVE-2022-33267 | 1 Qualcomm | 106 Aqt1000, Aqt1000 Firmware, Qca6390 and 103 more | 2024-04-12 | N/A | 7.8 HIGH |
Memory corruption in Linux while sending DRM request. | |||||
CVE-2022-25713 | 1 Qualcomm | 110 Ar8035, Ar8035 Firmware, Qam8295p and 107 more | 2024-04-12 | N/A | 7.8 HIGH |
Memory corruption in Automotive due to Improper Restriction of Operations within the Bounds of a Memory Buffer while exporting a shared key. | |||||
CVE-2022-25709 | 1 Qualcomm | 136 Ar8035, Ar8035 Firmware, Qca6174a and 133 more | 2024-04-12 | N/A | 7.8 HIGH |
Memory corruption in modem due to use of out of range pointer offset while processing qmi msg | |||||
CVE-2022-25694 | 1 Qualcomm | 416 Apq8009, Apq8009 Firmware, Apq8009w and 413 more | 2024-04-12 | N/A | 7.8 HIGH |
Memory corruption in Modem due to usage of Out-of-range pointer offset in UIM | |||||
CVE-2023-43534 | 1 Qualcomm | 132 Ar8035, Ar8035 Firmware, Fastconnect 6900 and 129 more | 2024-04-12 | N/A | 9.8 CRITICAL |
Memory corruption while validating the TID to Link Mapping action request frame, when a station connects to an access point. | |||||
CVE-2023-33092 | 1 Qualcomm | 190 Aqt1000, Aqt1000 Firmware, Fastconnect 6200 and 187 more | 2024-04-12 | N/A | 7.8 HIGH |
Memory corruption while processing pin reply in Bluetooth, when pin code received from APP layer is greater than expected size. | |||||
CVE-2023-33079 | 1 Qualcomm | 288 Apq5053-aa, Apq5053-aa Firmware, Ar8035 and 285 more | 2024-04-12 | N/A | 7.8 HIGH |
Memory corruption in Audio while running invalid audio recording from ADSP. |