Vulnerabilities (CVE)

Filtered by CWE-126
Total 195 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-33014 1 Qualcomm 650 315 5g Iot Modem, 315 5g Iot Modem Firmware, 860 Mobile Platform and 647 more 2024-11-20 N/A 7.5 HIGH
Transient DOS while parsing ESP IE from beacon/probe response frame.
CVE-2024-33015 1 Qualcomm 390 Ar8035, Ar8035 Firmware, Csr8811 and 387 more 2024-11-20 N/A 7.5 HIGH
Transient DOS while parsing SCAN RNR IE when bytes received from AP is such that the size of the last param of IE is less than neighbor report.
CVE-2024-33025 1 Qualcomm 338 Csr8811, Csr8811 Firmware, Fastconnect 6800 and 335 more 2024-11-20 N/A 7.5 HIGH
Transient DOS while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.
CVE-2024-33018 1 Qualcomm 302 Ar8035, Ar8035 Firmware, Csr8811 and 299 more 2024-11-20 N/A 7.5 HIGH
Transient DOS while parsing the received TID-to-link mapping element of the TID-to-link mapping action frame.
CVE-2024-33026 1 Qualcomm 330 Ar8035, Ar8035 Firmware, Csr8811 and 327 more 2024-11-20 N/A 7.5 HIGH
Transient DOS while parsing probe response and assoc response frame when received frame length is less than max size of timestamp.
CVE-2024-33020 1 Qualcomm 196 Ar8035, Ar8035 Firmware, Fastconnect 6700 and 193 more 2024-11-20 N/A 7.5 HIGH
Transient DOS while processing TID-to-link mapping IE elements.
CVE-2024-33019 1 Qualcomm 298 Ar8035, Ar8035 Firmware, Csr8811 and 295 more 2024-11-20 N/A 7.5 HIGH
Transient DOS while parsing the received TID-to-link mapping action frame.
CVE-2024-49031 1 Microsoft 3 365 Apps, Office, Office Long Term Servicing Channel 2024-11-18 N/A 7.8 HIGH
Microsoft Office Graphics Remote Code Execution Vulnerability
CVE-2024-9843 2024-11-13 N/A 5.0 MEDIUM
A buffer over-read in Ivanti Secure Access Client before 22.7R4 allows a local unauthenticated attacker to cause a denial of service.
CVE-2024-31082 2024-11-13 N/A 7.3 HIGH
A heap-based buffer over-read vulnerability was found in the X.org server's ProcAppleDRICreatePixmap() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a client with a different endianness. This vulnerability could be exploited by an attacker to cause the X server to read heap memory values and then transmit them back to the client until encountering an unmapped page, resulting in a crash. Despite the attacker's inability to control the specific memory copied into the replies, the small length values typically stored in a 32-bit integer can result in significant attempted out-of-bounds reads.
CVE-2024-31081 2024-11-12 N/A 7.3 HIGH
A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIPassiveGrabDevice() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a client with a different endianness. This vulnerability could be exploited by an attacker to cause the X server to read heap memory values and then transmit them back to the client until encountering an unmapped page, resulting in a crash. Despite the attacker's inability to control the specific memory copied into the replies, the small length values typically stored in a 32-bit integer can result in significant attempted out-of-bounds reads.
CVE-2024-31080 2024-11-12 N/A 7.3 HIGH
A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIGetSelectedEvents() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a client with a different endianness. This vulnerability could be exploited by an attacker to cause the X server to read heap memory values and then transmit them back to the client until encountering an unmapped page, resulting in a crash. Despite the attacker's inability to control the specific memory copied into the replies, the small length values typically stored in a 32-bit integer can result in significant attempted out-of-bounds reads.
CVE-2024-38403 1 Qualcomm 156 Ar8035, Ar8035 Firmware, Fastconnect 6900 and 153 more 2024-11-07 N/A 6.5 MEDIUM
Transient DOS while parsing BTM ML IE when per STA profile is not included.
CVE-2024-38405 1 Qualcomm 198 Ar8035, Ar8035 Firmware, Fastconnect 6700 and 195 more 2024-11-07 N/A 6.5 MEDIUM
Transient DOS while processing the CU information from RNR IE.
CVE-2024-38265 1 Microsoft 6 Windows Server 2008, Windows Server 2012, Windows Server 2016 and 3 more 2024-10-22 N/A 8.8 HIGH
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2024-38261 1 Microsoft 6 Windows Server 2008, Windows Server 2012, Windows Server 2016 and 3 more 2024-10-22 N/A 7.8 HIGH
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2024-43595 1 Microsoft 1 Edge Chromium 2024-10-18 N/A 8.8 HIGH
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2024-43500 1 Microsoft 4 Windows 11 22h2, Windows 11 23h2, Windows 11 24h2 and 1 more 2024-10-17 N/A 5.5 MEDIUM
Windows Resilient File System (ReFS) Information Disclosure Vulnerability
CVE-2024-33049 1 Qualcomm 262 Csr8811, Csr8811 Firmware, Fastconnect 6700 and 259 more 2024-10-16 N/A 7.5 HIGH
Transient DOS while parsing noninheritance IE of Extension element when length of IE is 2 of beacon frame.
CVE-2024-33064 1 Qualcomm 10 Mdm9628, Mdm9628 Firmware, Qca6564a and 7 more 2024-10-16 N/A 8.2 HIGH
Information disclosure while parsing the multiple MBSSID IEs from the beacon.